#1. Thanks for all the help! Computer is still running pretty great, except no internet access. Here are the logs:
#2
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-12 06:54:12
-----------------------------
06:54:12.312 OS Version: Windows 5.1.2600 Service Pack 3
06:54:12.312 Number of processors: 4 586 0x170A
06:54:12.312 ComputerName: B455DF2A840947D UserName: me
06:54:12.765 Initialize success
06:54:18.171 AVAST engine download error: 0
06:54:21.781 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-10
06:54:21.796 Disk 0 Vendor: ST3250824AS 3.AAE Size: 238475MB BusType: 3
06:54:21.812 Disk 0 MBR read successfully
06:54:21.812 Disk 0 MBR scan
06:54:21.812 Disk 0 Windows XP default MBR code
06:54:21.812 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 238464 MB offset 63
06:54:21.812 Disk 0 scanning sectors +488376000
06:54:21.875 Disk 0 scanning C:\WINDOWS\system32\drivers
06:54:27.343 Service scanning
06:54:42.656 Modules scanning
06:54:54.656 Disk 0 trace - called modules:
06:54:54.671 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
06:54:54.671 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89d88ab8]
06:54:54.703 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\0000006c[0x89d55930]
06:54:54.703 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-10[0x89d8bd98]
06:54:54.703 Scan finished successfully
06:57:41.734 Disk 0 MBR has been saved successfully to "F:\2nd post\MBR.dat"
06:57:41.750 The log file has been saved successfully to "F:\2nd post\aswMBR.txt"
#3
Farbar Service Scanner Version: 01-03-2012
Ran by me (administrator) on 12-04-2012 at 06:59:19
Running from "C:\Documents and Settings\me\Desktop"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Dhcp Service is not running. Checking service configuration:
The start type of Dhcp service is OK.
The ImagePath of Dhcp service is OK.
The ServiceDll of Dhcp service is OK.
NetBt Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open NetBt registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open NetBt registry key. The service key does not exist.
Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error: Google IP is unreachable
Attempt to access Yahoo IP returend error: Yahoo IP is unreachable
Windows Firewall:
=============
Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.
Windows Update:
============
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys
[2008-04-14 08:00] - [2008-04-14 08:00] - 0162816 ____A () D1FB86D58B151D274216C9146003A6E3
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
Extra List:
=======
Gpc(3) IPSec(5) PSched(7) Tcpip(4)
0x0B0000000500000001000000020000000300000004000000080000000B0000000600000007000000090000000A000000
IpSec Tag value is correct.
**** End of log ****
#4
OTL logfile created on: 4/12/2012 7:03:25 AM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\me\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.66 Gb Available Physical Memory | 82.97% Memory free
3.85 Gb Paging File | 3.67 Gb Available in Paging File | 95.44% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 121.90 Gb Free Space | 52.35% Space Free | Partition Type: NTFS
Drive F: | 3.73 Gb Total Space | 1.01 Gb Free Space | 27.10% Space Free | Partition Type: FAT32
Computer Name: B455DF2A840947D | User Name: me | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/04/12 06:50:50 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\me\Desktop\OTL.exe
PRC - [2012/01/28 13:17:10 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- %systemroot%\system32\irsir.dll -- (windowblinds)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\oracleorahomemanagementserver.dll -- (wfxsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\avgcoresvc.dll -- (wacomvhid)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ATIBTXBAR.dll -- (vzcdbsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\BrUsbSer.dll -- (vmnetadapter)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ccflic0.dll -- (VICESYS)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ASDR.dll -- (vaiomediaplatform-mobile-gateway)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\Freedom.dll -- (utscsi)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\DcLps.dll -- (ultra66)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\remoteaccess.dll -- (tvald)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\VAIOMediaPlatform-PhotoServer-UPnP.dll -- (transbaseservice)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\prosync1.dll -- (tifm21)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\netmdsb.dll -- (tfsndrct)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\gtndis5.dll -- (sysaidagent)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\licensemanagersocket.dll -- (SRVLOC)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\igateway.dll -- (SiSRaid)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\webrootadminconsole.dll -- (SE2Dbus)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\pinetmgr.dll -- (SE26mdfl)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\bgsvcgen.dll -- (s3psddr)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\hddsvc.dll -- (rpcapd)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\oracleorahome92tnslistener.dll -- (roxwatch9)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\RVIEG01.dll -- (roxliveshare)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\oracleorahomedatagatherer.dll -- (RioS30)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tpsrv.dll -- (rimmptsk)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\rtl8185.dll -- (retrowdsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ghoststartservice.dll -- (RESMGR)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\RecAgent.dll -- (psdvdisk)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\oracleorahometnslistener.dll -- (pmem)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\slee_81_service.dll -- (pinetmgr)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\TOSHIBASoftModem.dll -- (pepifilter)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\WaveFDE.dll -- (pensup)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\Afc.dll -- (pdlndlpb)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\NetPipeActivator.dll -- (NWSIPX32)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\rapapp.dll -- (ntpr_nic_service2)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\sysmgmthp.dll -- (nm)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\pcx1unic.dll -- (nicconfigsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\NTACCESS.dll -- (mwstick)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\bdpredir.dll -- (mwssched)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\s716bus.dll -- (mvdcodec)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\usbaudio.dll -- (mssql$microsoftbcm)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\avgclean.dll -- (mozyFilter)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\fs_rec.dll -- (mf)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\backupexecjobengine.dll -- (mcupdmgr.exe)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ipfilterdriver.dll -- (mctaskmanager)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\zebrbus.dll -- (mcrdsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\Angel2.dll -- (mcdbus)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\NICSer_WPC300N.dll -- (mcafeeframework)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\rksample.dll -- (livesrv)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tphdexlgsvc.dll -- (LHidUsbK)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\cachemgr.dll -- (klblmain)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ultra66.dll -- (k750mdfl)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\SMNDIS5.dll -- (issvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\EPOWER.dll -- (InterBaseGuardian)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ati2mpaa.dll -- (icepack)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\dlcq_device.dll -- (iAimTV6)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\oracle_load_balancer_60_server-forms6ip9.dll -- (hpzius12)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\secdrv.dll -- (HIDSwvd)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll -- (helpsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\atimpab.dll -- (genregistrar)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\s217bus.dll -- (FETNDIS)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ichaud.dll -- (epson_pm_rpcv2_02)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\STV680m.dll -- (earthlinksafeconnectagent)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\zebrsce.dll -- (ddxgb)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\oracleformsserver-forms60server-oraform.dll -- (CYGF32X)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\DMICall.dll -- (CXAVXBAR)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\PSSdk21.dll -- (cvintdrv)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\s616mdm.dll -- (cmigameport)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\Cinemsup.dll -- (CE3)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\viaudio.dll -- (CDRPDACC)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\SunkFilt39.dll -- (CdaD10BA)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\wwsecsvc.dll -- (caccprovsp)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tmmbd.dll -- (bdss)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\psadd.dll -- (ASDR)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\hsfhwazl.dll -- (AppnBase)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\eeyeevnt.dll -- (APLMp50)
SRV - [2012/02/29 09:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | Boot | Stopped] -- -- (cerc6)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\me\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\me\LOCALS~1\Temp\aswMBR.sys -- (aswMBR)
DRV - [2010/09/07 16:08:58 | 000,100,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2009/08/05 14:16:44 | 000,039,424 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.2.0.7165
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\me\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\me\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/01/28 13:17:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/24 10:24:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/10 17:42:52 | 000,000,000 | ---D | M]
[2010/10/20 17:10:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\me\Application Data\Mozilla\Extensions
[2012/03/28 12:41:07 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\filgc1wm.default\extensions
[2011/11/10 23:02:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\ME\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FILGC1WM.DEFAULT\EXTENSIONS\YVTEUGOSTF@YVTEUGOSTF.ORG.XPI
[2012/03/24 10:24:12 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/11/12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/03/04 11:20:03 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/04 11:20:03 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\17.0.963.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\17.0.963.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U23 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\me\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O3 - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-1220945662-1972579041-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\me\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\me\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/20 15:21:05 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{33510c8e-045f-11e0-8f1f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{33510c8e-045f-11e0-8f1f-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{33510c8e-045f-11e0-8f1f-806d6172696f}\Shell\AutoRun\command - "" = E:\Install.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Install.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
MsConfig - Services: "JavaQuickStarterService"
MsConfig - Services: "gupdatem"
MsConfig - Services: "gupdate"
MsConfig - StartUpReg:
Adobe ARM - hkey= - key= - File not found
MsConfig - StartUpReg:
ctfmon.exe - hkey= - key= - File not found
MsConfig - StartUpReg:
DAEMON Tools-1033 - hkey= - key= - File not found
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg:
LanguageShortcut - hkey= - key= - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
MsConfig - StartUpReg:
NvCplDaemon - hkey= - key= - File not found
MsConfig - StartUpReg:
NvMediaCenter - hkey= - key= - File not found
MsConfig - StartUpReg:
nwiz - hkey= - key= - C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
MsConfig - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
MsConfig - StartUpReg:
RemoteControl - hkey= - key= - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
MsConfig - StartUpReg:
Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - StartUpReg:
SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg:
TkBellExe - hkey= - key= - C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 2
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
SafeBootMin: 94995971.sys - Driver
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: rimmptsk - %systemroot%\system32\tpsrv.dll File not found
NetSvcs: utscsi - %systemroot%\system32\Freedom.dll File not found
NetSvcs: pepifilter - %systemroot%\system32\TOSHIBASoftModem.dll File not found
NetSvcs: mwstick - %systemroot%\system32\NTACCESS.dll File not found
NetSvcs: bdss - %systemroot%\system32\tmmbd.dll File not found
NetSvcs: tvald - %systemroot%\system32\remoteaccess.dll File not found
NetSvcs: mctaskmanager - %systemroot%\system32\ipfilterdriver.dll File not found
NetSvcs: tfsndrct - %systemroot%\system32\netmdsb.dll File not found
NetSvcs: tifm21 - %systemroot%\system32\prosync1.dll File not found
NetSvcs: VICESYS - %systemroot%\system32\ccflic0.dll File not found
NetSvcs: CYGF32X - %systemroot%\system32\oracleformsserver-forms60server-oraform.dll File not found
NetSvcs: mvdcodec - %systemroot%\system32\s716bus.dll File not found
NetSvcs: roxwatch9 - %systemroot%\system32\oracleorahome92tnslistener.dll File not found
NetSvcs: RESMGR - %systemroot%\system32\ghoststartservice.dll File not found
NetSvcs: earthlinksafeconnectagent - %systemroot%\system32\STV680m.dll File not found
NetSvcs: sysaidagent - %systemroot%\system32\gtndis5.dll File not found
NetSvcs: hpzius12 - %systemroot%\system32\oracle_load_balancer_60_server-forms6ip9.dll File not found
NetSvcs: FETNDIS - %systemroot%\system32\s217bus.dll File not found
NetSvcs: mcrdsvc - %systemroot%\system32\zebrbus.dll File not found
NetSvcs: NWSIPX32 - %systemroot%\system32\NetPipeActivator.dll File not found
NetSvcs: windowblinds - %systemroot%\system32\irsir.dll File not found
NetSvcs: caccprovsp - %systemroot%\system32\wwsecsvc.dll File not found
NetSvcs: mwssched - %systemroot%\system32\bdpredir.dll File not found
NetSvcs: vmnetadapter - %systemroot%\system32\BrUsbSer.dll File not found
NetSvcs: mssql$microsoftbcm - %systemroot%\system32\usbaudio.dll File not found
NetSvcs: ASDR - %systemroot%\system32\psadd.dll File not found
NetSvcs: HIDSwvd - %systemroot%\system32\secdrv.dll File not found
NetSvcs: wfxsvc - %systemroot%\system32\oracleorahomemanagementserver.dll File not found
NetSvcs: mozyFilter - %systemroot%\system32\avgclean.dll File not found
NetSvcs: vzcdbsvc - %systemroot%\system32\ATIBTXBAR.dll File not found
NetSvcs: ntpr_nic_service2 - %systemroot%\system32\rapapp.dll File not found
NetSvcs: livesrv - %systemroot%\system32\rksample.dll File not found
NetSvcs: epson_pm_rpcv2_02 - %systemroot%\system32\ichaud.dll File not found
NetSvcs: s3psddr - %systemroot%\system32\bgsvcgen.dll File not found
NetSvcs: icepack - %systemroot%\system32\ati2mpaa.dll File not found
NetSvcs: retrowdsvc - %systemroot%\system32\rtl8185.dll File not found
NetSvcs: mcafeeframework - %systemroot%\system32\NICSer_WPC300N.dll File not found
NetSvcs: cmigameport - %systemroot%\system32\s616mdm.dll File not found
NetSvcs: SE2Dbus - %systemroot%\system32\webrootadminconsole.dll File not found
NetSvcs: pinetmgr - %systemroot%\system32\slee_81_service.dll File not found
NetSvcs: APLMp50 - %systemroot%\system32\eeyeevnt.dll File not found
NetSvcs: CE3 - %systemroot%\system32\Cinemsup.dll File not found
NetSvcs: vaiomediaplatform-mobile-gateway - %systemroot%\system32\ASDR.dll File not found
NetSvcs: iAimTV6 - %systemroot%\system32\dlcq_device.dll File not found
NetSvcs: pmem - %systemroot%\system32\oracleorahometnslistener.dll File not found
NetSvcs: SiSRaid - %systemroot%\system32\igateway.dll File not found
NetSvcs: CDRPDACC - %systemroot%\system32\viaudio.dll File not found
NetSvcs: mf - %systemroot%\system32\fs_rec.dll File not found
NetSvcs: SE26mdfl - %systemroot%\system32\pinetmgr.dll File not found
NetSvcs: CdaD10BA - %systemroot%\system32\SunkFilt39.dll File not found
NetSvcs: nm - %systemroot%\system32\sysmgmthp.dll File not found
NetSvcs: wacomvhid - %systemroot%\system32\avgcoresvc.dll File not found
NetSvcs: LHidUsbK - %systemroot%\system32\tphdexlgsvc.dll File not found
NetSvcs: k750mdfl - %systemroot%\system32\ultra66.dll File not found
NetSvcs: RioS30 - %systemroot%\system32\oracleorahomedatagatherer.dll File not found
NetSvcs: SRVLOC - %systemroot%\system32\licensemanagersocket.dll File not found
NetSvcs: genregistrar - %systemroot%\system32\atimpab.dll File not found
NetSvcs: CXAVXBAR - %systemroot%\system32\DMICall.dll File not found
NetSvcs: InterBaseGuardian - %systemroot%\system32\EPOWER.dll File not found
NetSvcs: issvc - %systemroot%\system32\SMNDIS5.dll File not found
NetSvcs: transbaseservice - %systemroot%\system32\VAIOMediaPlatform-PhotoServer-UPnP.dll File not found
NetSvcs: rpcapd - %systemroot%\system32\hddsvc.dll File not found
NetSvcs: klblmain - %systemroot%\system32\cachemgr.dll File not found
NetSvcs: pdlndlpb - %systemroot%\system32\Afc.dll File not found
NetSvcs: mcdbus - %systemroot%\system32\Angel2.dll File not found
NetSvcs: roxliveshare - %systemroot%\system32\RVIEG01.dll File not found
NetSvcs: psdvdisk - %systemroot%\system32\RecAgent.dll File not found
NetSvcs: pensup - %systemroot%\system32\WaveFDE.dll File not found
NetSvcs: nicconfigsvc - %systemroot%\system32\pcx1unic.dll File not found
NetSvcs: ddxgb - %systemroot%\system32\zebrsce.dll File not found
NetSvcs: ultra66 - %systemroot%\system32\DcLps.dll File not found
NetSvcs: cvintdrv - %systemroot%\system32\PSSdk21.dll File not found
NetSvcs: mcupdmgr.exe - %systemroot%\system32\backupexecjobengine.dll File not found
NetSvcs: AppnBase - %systemroot%\system32\hsfhwazl.dll File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll File not found
========== Files/Folders - Created Within 30 Days ========== [2012/04/12 07:01:39 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\me\Desktop\OTL.exe
[2012/04/12 06:54:10 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\me\Desktop\aswMBR.exe
[2012/04/10 19:57:07 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\me\Desktop\dds.scr
[2012/04/10 17:44:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2012/04/10 17:27:55 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/04/05 00:18:13 | 000,098,992 | ---- | C] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\43528141.sys
[2012/04/02 21:32:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2012/04/02 21:32:35 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2012/03/31 17:57:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\Pics
[2012/03/27 14:58:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/03/27 14:39:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/03/27 14:39:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/03/26 20:21:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Local Settings\Application Data\Threat Expert
[2012/03/26 19:16:15 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2012/03/26 19:12:57 | 000,185,560 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTSD.sys
[2012/03/26 19:12:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012/03/26 19:12:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/03/26 19:12:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Application Data\TestApp
[2012/03/26 19:12:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2012/03/26 19:06:02 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/03/26 13:41:12 | 002,068,016 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\me\Desktop\TDSSKiller.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/04/12 06:50:58 | 000,337,137 | ---- | M] () -- C:\Documents and Settings\me\Desktop\FSS.exe
[2012/04/12 06:50:50 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\me\Desktop\OTL.exe
[2012/04/12 06:44:26 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\me\Desktop\aswMBR.exe
[2012/04/12 06:23:10 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/12 06:18:10 | 000,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1972579041-1801674531-1003UA.job
[2012/04/12 04:18:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1972579041-1801674531-1003Core.job
[2012/04/11 17:59:28 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1220945662-1972579041-1801674531-1003.job
[2012/04/11 17:59:26 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/04/11 17:59:25 | 000,000,874 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/11 17:59:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/04/10 19:57:33 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\me\defogger_reenable
[2012/04/10 18:01:16 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\me\Desktop\gmer.zip
[2012/04/10 17:58:06 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\me\Desktop\dds.scr
[2012/04/10 17:56:40 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\me\Desktop\Defogger.exe
[2012/04/09 21:10:58 | 000,009,728 | ---- | M] () -- C:\Documents and Settings\me\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/07 12:18:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1972579041-1801674531-1003.job
[2012/04/06 00:32:04 | 000,001,418 | ---- | M] () -- C:\Documents and Settings\me\Desktop\sdsetup.exe.lnk
[2012/04/05 21:55:32 | 000,010,662 | ---- | M] () -- C:\Documents and Settings\me\My Documents\cc_20120405_215515.reg
[2012/04/05 00:18:13 | 000,098,992 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\43528141.sys
[2012/04/04 22:44:24 | 000,024,828 | ---- | M] () -- C:\Documents and Settings\me\My Documents\cc_20120404_224415.reg
[2012/04/02 22:23:03 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/03/31 19:22:04 | 033,475,756 | ---- | M] () -- C:\Documents and Settings\me\Desktop\Pics.zip
[2012/03/31 11:22:03 | 000,000,375 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2012/03/30 19:04:19 | 000,433,122 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/30 19:04:19 | 000,067,952 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/28 10:09:58 | 000,000,000 | -HS- | M] () -- C:\WINDOWS\System32\dds_trash_log.cmd
[2012/03/27 15:50:54 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/03/26 23:13:31 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/03/26 19:13:19 | 000,555,294 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/03/26 13:41:12 | 002,068,016 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\me\Desktop\TDSSKiller.exe
[2012/03/24 16:01:40 | 000,095,217 | ---- | M] () -- C:\Documents and Settings\me\Desktop\Charlie.jpg
[2012/03/24 15:10:05 | 000,088,039 | ---- | M] () -- C:\Documents and Settings\me\Desktop\Frog edit.JPG
[2012/03/24 10:23:55 | 000,000,351 | RHS- | M] () -- C:\boot.ini
[2012/03/23 18:15:07 | 000,002,239 | ---- | M] () -- C:\Documents and Settings\me\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/03/23 18:15:05 | 000,002,261 | ---- | M] () -- C:\Documents and Settings\me\Desktop\Google Chrome.lnk
[2012/03/18 11:41:13 | 000,117,360 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/18 11:19:26 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/04/12 06:57:49 | 000,337,137 | ---- | C] () -- C:\Documents and Settings\me\Desktop\FSS.exe
[2012/04/10 19:57:33 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\me\defogger_reenable
[2012/04/10 19:57:09 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\me\Desktop\gmer.zip
[2012/04/10 19:57:05 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\me\Desktop\Defogger.exe
[2012/04/05 21:55:18 | 000,010,662 | ---- | C] () -- C:\Documents and Settings\me\My Documents\cc_20120405_215515.reg
[2012/04/04 22:44:18 | 000,024,828 | ---- | C] () -- C:\Documents and Settings\me\My Documents\cc_20120404_224415.reg
[2012/03/31 19:09:28 | 033,475,756 | ---- | C] () -- C:\Documents and Settings\me\Desktop\Pics.zip
[2012/03/27 14:48:05 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\d3d9caps.dat
[2012/03/27 14:28:29 | 000,000,000 | -HS- | C] () -- C:\WINDOWS\System32\dds_trash_log.cmd
[2012/03/26 19:13:04 | 000,555,294 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/03/26 19:12:28 | 000,001,418 | ---- | C] () -- C:\Documents and Settings\me\Desktop\sdsetup.exe.lnk
[2012/03/24 16:01:40 | 000,095,217 | ---- | C] () -- C:\Documents and Settings\me\Desktop\Charlie.jpg
[2012/03/24 15:08:58 | 000,088,039 | ---- | C] () -- C:\Documents and Settings\me\Desktop\Frog edit.JPG
[2012/03/07 22:25:19 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/16 09:25:34 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/16 09:25:34 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/16 09:25:34 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/16 09:25:34 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/16 09:25:34 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/28 21:33:21 | 000,000,280 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~W4ID0FNNbYCqQS
[2012/01/28 21:33:21 | 000,000,192 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~W4ID0FNNbYCqQSr
[2012/01/28 21:33:17 | 000,000,456 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\W4ID0FNNbYCqQS
[2012/01/26 18:52:10 | 000,000,280 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~zRfpj2rbftmkWu
[2012/01/26 18:52:10 | 000,000,192 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~zRfpj2rbftmkWur
[2012/01/26 18:52:04 | 000,000,456 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\zRfpj2rbftmkWu
[2011/09/27 19:16:34 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\me\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/15 00:13:28 | 000,004,626 | -HS- | C] () -- C:\Documents and Settings\me\Local Settings\Application Data\17e16t76j00yk1muao33at50sr4ruanow2v64g745xuu
[2011/06/15 00:13:28 | 000,004,626 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\17e16t76j00yk1muao33at50sr4ruanow2v64g745xuu
[2011/04/26 16:44:17 | 000,000,192 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\0
[2011/04/05 01:28:42 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011/01/15 16:44:24 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/12/04 12:13:34 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/10/20 17:10:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/10/20 16:21:20 | 000,240,124 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/10/20 16:21:14 | 000,240,124 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/10/20 16:21:14 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/10/20 16:09:55 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2010/10/20 15:36:28 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe
[2010/10/20 15:34:20 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\BCGPOleAcc.dll
[2010/10/20 15:30:09 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/20 15:23:07 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/10/20 15:18:21 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/10/20 11:12:25 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/10/20 11:11:09 | 000,117,360 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/10 05:38:00 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
========== Custom Scans ========== < "%WinDir%\$NtUninstallKB*$." /30 > < C:\Program Files\Common Files\ComObjects\*.* /s > < %systemroot%\*. /mp /s > < %systemroot%\*. /rp /s > < %systemroot%\system32\*.dll /lockedfiles >[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2010/10/20 11:10:08 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010/10/20 11:10:08 | 001,089,536 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010/10/20 11:10:08 | 000,929,792 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >[2012/04/05 00:18:13 | 000,098,992 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\system32\drivers\43528141.sys
[2012/02/24 10:36:44 | 000,185,560 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\drivers\PCTSD.sys
< %SYSTEMDRIVE%\*.exe > < c:\documents and settings\me\application data\microsoft\*.* /s >[2010/12/23 10:48:34 | 000,176,594 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Address Book\me.wab
[2010/12/23 10:48:34 | 000,176,594 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Address Book\me.wab~
[2011/10/16 13:14:59 | 000,153,840 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\00813F57C0CBB9A83349C874FD014078
[2011/10/16 13:20:05 | 000,052,588 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\01F264D2BB689E7123B8E4B92BEB76C7
[2010/12/14 10:35:44 | 000,000,545 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\0270780F846F08BEFE0DD8112D932FEF
[2012/01/24 18:13:55 | 000,036,093 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4
[2012/03/27 16:07:55 | 000,170,683 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\08E382DC40DC2B571439BB7A5449C239
[2010/10/20 16:33:34 | 000,000,727 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\0EBB3788D77094423275558212CCE7B1
[2011/01/14 13:07:39 | 000,035,599 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\12236C41CDDF9E40BA5606CDF086B821
[2011/06/27 11:35:36 | 000,002,280 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\135BD6A358680A7BF1CCEC7C0172393D
[2011/06/02 19:29:34 | 000,430,232 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\1B9435E949F2B3D267BABDE0C8BC19A6
[2011/10/16 13:14:31 | 000,000,794 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\1C4E554353AB278B1DD0E7329C5388D7
[2011/10/16 13:14:27 | 000,000,969 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\1CE9F5C74186E7B86A5CC6A85C21C64C
[2012/02/21 21:09:10 | 000,000,988 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\23B523C9E7746F715D33C6527C18EB9D
[2012/01/10 09:14:07 | 000,000,545 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\2659C1A560AB92C9C29D4B2B25815AE8
[2012/03/27 14:57:44 | 000,000,018 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
[2012/01/28 13:14:36 | 000,000,341 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\303572DF538EDD8B1D606185F1D559B8
[2011/07/25 20:50:11 | 000,000,552 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\3130B1871A126520A8C47861EFE3ED4D
[2010/12/14 10:35:18 | 000,002,155 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\38969BE6CA6647276BD650689DAF359C
[2011/10/16 13:14:44 | 000,000,494 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\3B6E683A7A45CC59BF035C9BA8C7AB9D
[2012/03/27 14:58:26 | 000,000,325 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\451DC5567B190A158F45C268C2C1C989
[2010/12/14 10:35:13 | 000,000,902 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\4859D5BAC918334C46BD5ECFE050190D
[2011/04/12 21:40:19 | 000,264,527 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\486CC6AFD08942336C61FCD401C4A1D1
[2011/06/09 18:13:56 | 000,007,696 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\4DB1DABDF57ED9997FE8DCC77E93C04F
[2010/12/14 10:34:45 | 000,001,518 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\52FE9FFE4780FF24EC690DB2F1D013CE
[2012/01/26 18:40:40 | 000,019,724 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\5495C2E4531B22B3185CE59F8E73C447
[2010/10/20 16:33:34 | 000,000,706 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\5553AF14BD4C3B1DE599145FD14950E0
[2010/12/10 19:26:29 | 000,000,573 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\570FB14ABC805C46708F32F92F10C3B4
[2012/03/27 16:06:01 | 000,000,325 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\57C75A2116202D1B0A43D1BE323F2384
[2012/02/21 21:09:10 | 000,012,949 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\5F74056C561F814B7771CB2993A44DEB
[2012/03/27 16:07:50 | 000,000,898 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
[2012/01/28 13:14:26 | 000,034,620 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6
[2011/04/05 01:28:58 | 000,001,095 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\678F9D319FF4D0257A34339D2BFE3CC5
[2011/10/16 13:14:49 | 000,144,464 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\74547E1981B533FEA41563CC9558DBD0
[2011/04/12 21:40:14 | 000,262,673 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019
[2012/03/27 15:33:26 | 000,000,325 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\75F648433CA0438DDA9EADC3C02F976C
[2012/01/28 14:01:12 | 000,001,280 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\77EDE1350D6A4830F58081495812F0B6
[2012/01/28 13:14:41 | 000,000,413 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\79841F8EF00FBA86D33CC5A47696F165
[2011/11/30 09:27:10 | 000,000,552 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9
[2011/06/27 11:35:39 | 000,001,151 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\87F16F8B405FD697FA6FF88C0E77D946
[2012/01/28 13:14:31 | 000,000,533 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F
[2011/01/14 13:07:34 | 000,000,500 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\8EDCF682921FE94F4A02A43CD1A28E6B
[2012/03/07 21:56:34 | 000,048,509 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
[2011/06/16 21:27:11 | 000,431,549 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\96D7A99548C36B10D2E8035A3E0DCA1A
[2011/10/16 13:19:56 | 000,000,389 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\9CD8982C888AB544945893084BD7523A
[2012/01/02 00:01:50 | 000,002,202 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\A0F226E8ACF8E1672AF808D7CAF4AD47
[2011/06/30 09:18:49 | 000,000,558 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD
[2011/04/12 21:40:28 | 000,096,054 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
[2012/01/02 00:01:55 | 000,001,302 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\A92ECB803776646616CF2949CC6BAC5D
[2011/10/16 13:20:00 | 000,000,429 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\B681B8816EE79EAEAA5CA7DA9EC0DC58
[2010/12/18 01:51:01 | 000,063,478 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\B69D763EB21649DA26F20618312DEE70
[2010/12/14 10:35:47 | 000,004,412 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\BF6AA579955A6C96DA58A0FEFEEA4250
[2011/04/05 01:28:58 | 000,001,310 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7
[2012/01/02 00:01:21 | 000,000,469 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\C8E7EC0C85688F4738F3BE49B104BA67
[2010/12/14 10:35:47 | 000,004,412 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\CCE3E32C68F1446EAE0F7CE249DCAFC6
[2012/01/26 18:40:47 | 000,002,775 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\D0F063B6B88A2B8BFE21C3993A613447
[2012/01/28 13:14:12 | 000,001,550 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\D236B74794790D9923905972356B8BEC
[2012/03/27 16:07:31 | 000,000,325 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\D4986E93688292E6AA43EC2846F35A36
[2011/10/16 13:14:53 | 000,007,639 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\D65457FE84851CE7E17198CC42C0193B
[2012/03/27 16:07:33 | 000,021,523 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\D725F3459E2275E9EA5871B92AD896D0
[2012/01/10 09:14:11 | 000,019,992 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\DEEA0BD81CC3B68E08E92D12B0916963
[2012/01/02 00:01:40 | 000,000,772 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\E2EF7F0FB7284B9ACFD4F65D02218479
[2011/07/25 20:11:41 | 000,000,558 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735
[2011/01/02 16:46:19 | 000,002,249 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5
[2011/06/15 18:24:52 | 000,000,772 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\EC37E616CDD78651CDD48402A28028C1
[2012/01/10 09:13:56 | 000,000,706 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\F063BF7EF604434CBE00FF198F0D9B10
[2012/03/27 14:57:39 | 000,000,325 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\F1CD82CF8CDDF5A0EEF951A329D80A97
[2011/03/03 18:33:32 | 000,005,235 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\F78CAE5D65CB8F387E2E0E15EF7E4AE3
[2012/03/27 16:07:29 | 000,000,955 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\Content\FB788E090BC1F3AA2FBC9E8FB2859601
[2011/10/16 13:14:59 | 000,000,124 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\00813F57C0CBB9A83349C874FD014078
[2011/10/16 13:20:05 | 000,000,098 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\01F264D2BB689E7123B8E4B92BEB76C7
[2010/12/14 10:35:44 | 000,000,146 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\0270780F846F08BEFE0DD8112D932FEF
[2012/01/24 18:13:55 | 000,000,132 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4
[2012/03/27 16:07:55 | 000,000,116 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\08E382DC40DC2B571439BB7A5449C239
[2010/10/20 16:33:34 | 000,000,138 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\0EBB3788D77094423275558212CCE7B1
[2011/01/14 13:07:39 | 000,000,114 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\12236C41CDDF9E40BA5606CDF086B821
[2011/06/27 11:35:36 | 000,000,132 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\135BD6A358680A7BF1CCEC7C0172393D
[2011/06/02 19:29:34 | 000,000,134 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\1B9435E949F2B3D267BABDE0C8BC19A6
[2011/10/16 13:14:31 | 000,000,206 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\1C4E554353AB278B1DD0E7329C5388D7
[2011/10/16 13:14:27 | 000,000,204 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\1CE9F5C74186E7B86A5CC6A85C21C64C
[2012/02/21 21:09:10 | 000,000,112 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\23B523C9E7746F715D33C6527C18EB9D
[2012/01/10 09:14:07 | 000,000,146 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\2659C1A560AB92C9C29D4B2B25815AE8
[2012/03/27 14:57:44 | 000,000,216 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
[2012/01/28 13:14:36 | 000,000,126 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\303572DF538EDD8B1D606185F1D559B8
[2011/07/25 20:50:11 | 000,000,132 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\3130B1871A126520A8C47861EFE3ED4D
[2010/12/14 10:35:18 | 000,000,120 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\38969BE6CA6647276BD650689DAF359C
[2011/10/16 13:14:44 | 000,000,132 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\3B6E683A7A45CC59BF035C9BA8C7AB9D
[2012/03/27 14:58:26 | 000,000,086 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\451DC5567B190A158F45C268C2C1C989
[2010/12/14 10:35:13 | 000,000,096 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\4859D5BAC918334C46BD5ECFE050190D
[2011/04/12 21:40:19 | 000,000,120 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\486CC6AFD08942336C61FCD401C4A1D1
[2011/06/09 18:13:56 | 000,000,098 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\4DB1DABDF57ED9997FE8DCC77E93C04F
[2010/12/14 10:34:45 | 000,000,160 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\52FE9FFE4780FF24EC690DB2F1D013CE
[2012/01/26 18:40:40 | 000,000,122 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\5495C2E4531B22B3185CE59F8E73C447
[2010/10/20 16:33:34 | 000,000,206 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\5553AF14BD4C3B1DE599145FD14950E0
[2010/12/10 19:26:29 | 000,000,174 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\570FB14ABC805C46708F32F92F10C3B4
[2012/03/27 16:06:01 | 000,000,086 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\57C75A2116202D1B0A43D1BE323F2384
[2012/02/21 21:09:10 | 000,000,104 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\5F74056C561F814B7771CB2993A44DEB
[2012/03/27 16:07:50 | 000,000,094 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
[2012/01/28 13:14:26 | 000,000,124 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6
[2011/04/05 01:28:58 | 000,000,120 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\678F9D319FF4D0257A34339D2BFE3CC5
[2011/10/16 13:14:49 | 000,000,154 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\74547E1981B533FEA41563CC9558DBD0
[2011/04/12 21:40:14 | 000,000,124 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\74BFD122C0875EC75DBE5C6DB4C59019
[2012/03/27 15:33:26 | 000,000,086 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\75F648433CA0438DDA9EADC3C02F976C
[2012/01/28 14:01:12 | 000,000,154 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\77EDE1350D6A4830F58081495812F0B6
[2012/01/28 13:14:41 | 000,000,098 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\79841F8EF00FBA86D33CC5A47696F165
[2011/11/30 09:27:10 | 000,000,132 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9
[2011/06/27 11:35:39 | 000,000,120 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\87F16F8B405FD697FA6FF88C0E77D946
[2012/01/28 13:14:31 | 000,000,100 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F
[2011/01/14 13:07:34 | 000,000,100 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\8EDCF682921FE94F4A02A43CD1A28E6B
[2012/03/07 21:56:34 | 000,000,216 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
[2011/06/16 21:27:11 | 000,000,134 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\96D7A99548C36B10D2E8035A3E0DCA1A
[2011/10/16 13:19:56 | 000,000,132 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\9CD8982C888AB544945893084BD7523A
[2012/01/02 00:01:50 | 000,000,194 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\A0F226E8ACF8E1672AF808D7CAF4AD47
[2011/06/30 09:18:49 | 000,000,146 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD
[2011/04/12 21:40:28 | 000,000,124 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
[2012/01/02 00:01:55 | 000,000,126 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\A92ECB803776646616CF2949CC6BAC5D
[2011/10/16 13:20:00 | 000,000,136 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\B681B8816EE79EAEAA5CA7DA9EC0DC58
[2010/12/18 01:51:01 | 000,000,128 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\B69D763EB21649DA26F20618312DEE70
[2010/12/14 10:35:47 | 000,000,106 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\BF6AA579955A6C96DA58A0FEFEEA4250
[2011/04/05 01:28:58 | 000,000,100 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7
[2012/01/02 00:01:21 | 000,000,098 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\C8E7EC0C85688F4738F3BE49B104BA67
[2010/12/14 10:35:47 | 000,000,106 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\CCE3E32C68F1446EAE0F7CE249DCAFC6
[2012/01/26 18:40:47 | 000,000,178 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\D0F063B6B88A2B8BFE21C3993A613447
[2012/01/28 13:14:12 | 000,000,124 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\D236B74794790D9923905972356B8BEC
[2012/03/27 16:07:31 | 000,000,086 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\D4986E93688292E6AA43EC2846F35A36
[2011/10/16 13:14:53 | 000,000,118 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\D65457FE84851CE7E17198CC42C0193B
[2012/03/27 16:07:33 | 000,000,110 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\D725F3459E2275E9EA5871B92AD896D0
[2012/01/10 09:14:11 | 000,000,106 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\DEEA0BD81CC3B68E08E92D12B0916963
[2012/01/02 00:01:40 | 000,000,138 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\E2EF7F0FB7284B9ACFD4F65D02218479
[2011/07/25 20:11:41 | 000,000,144 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735
[2011/01/02 16:46:19 | 000,000,124 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5
[2011/06/15 18:24:52 | 000,000,134 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\EC37E616CDD78651CDD48402A28028C1
[2012/01/10 09:13:56 | 000,000,206 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\F063BF7EF604434CBE00FF198F0D9B10
[2012/03/27 14:57:39 | 000,000,086 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\F1CD82CF8CDDF5A0EEF951A329D80A97
[2011/03/03 18:33:32 | 000,000,238 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\F78CAE5D65CB8F387E2E0E15EF7E4AE3
[2012/03/27 16:07:29 | 000,000,134 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\CryptnetUrlCache\MetaData\FB788E090BC1F3AA2FBC9E8FB2859601
[2010/12/18 01:30:52 | 000,000,043 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\Crypto\RSA\S-1-5-21-1220945662-1972579041-1801674531-1003\34331bd9546cea8ffa1fe74209908d36_773ede37-b37d-46e8-abfe-f1d9424660c2
[2010/10/20 16:38:33 | 000,000,053 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\Crypto\RSA\S-1-5-21-1220945662-1972579041-1801674531-1003\6b29ae44e85efac3c72ff4d1865d73f1_773ede37-b37d-46e8-abfe-f1d9424660c2
[2010/10/20 15:30:08 | 000,000,045 | --S- | M] () -- c:\documents and settings\me\application data\microsoft\Crypto\RSA\S-1-5-21-1220945662-1972579041-1801674531-1003\83aa4cc77f591dfc2374580bbd95f6ba_773ede37-b37d-46e8-abfe-f1d9424660c2
[2011/03/25 13:34:09 | 000,008,634 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\HTML Help\hh.dat
[2010/10/20 15:20:55 | 000,000,141 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\brndlog.bak
[2010/10/20 15:25:23 | 000,010,378 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\brndlog.txt
[2012/03/31 11:43:44 | 000,002,448 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Desktop.htt
[2010/10/20 15:25:23 | 000,000,119 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/03/23 18:15:07 | 000,002,239 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/26 23:25:48 | 000,001,606 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/10/20 16:32:03 | 000,000,815 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/10/20 17:10:03 | 000,001,620 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/28 21:33:20 | 000,000,853 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/07/06 22:57:31 | 000,000,800 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/06/21 23:10:03 | 000,000,154 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Media Player\0E1B7080.wpl
[2012/03/20 08:14:45 | 000,327,680 | ---- | M] (AGEIA Technologies, Inc.) -- c:\documents and settings\me\application data\microsoft\Microsoft\ruamntmv.dll
[2011/08/31 18:25:29 | 000,033,211 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\MMC\dfrg
[2012/02/22 00:07:07 | 000,000,160 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\CREDHIST
[2012/02/22 00:07:07 | 000,000,388 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\4fd9cb2b-592c-44f9-b1e6-87a1bf7e9faf
[2012/02/22 00:07:07 | 000,000,388 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\5cabf787-8549-4625-a9db-9120781c1a2f
[2012/02/22 00:07:07 | 000,000,388 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\767b2173-a312-4f57-94b4-87581d90735d
[2012/04/06 11:18:10 | 000,000,388 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\7a79e079-0b92-4e4b-bfb1-c8eada33b2cb
[2012/02/22 00:07:07 | 000,000,388 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\91cf7a49-86bb-43a5-80e8-d9525c61cf9a
[2012/02/22 00:07:07 | 000,000,388 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\cfe9ffed-86c2-4c57-8d51-2d1d839777cd
[2012/04/06 11:18:10 | 000,000,024 | -HS- | M] () -- c:\documents and settings\me\application data\microsoft\Protect\S-1-5-21-1220945662-1972579041-1801674531-1003\Preferred
[2012/02/16 12:07:50 | 000,005,672 | ---- | M] () -- c:\documents and settings\me\application data\microsoft\Windows\Themes\Custom.theme
< MD5 for: AFD.SYS >[2011/08/17 09:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\dllcache\afd.sys
[2011/08/17 09:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\drivers\afd.sys
[2008/04/14 08:00:00 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\$NtUninstallKB951748$\afd.sys
[2011/02/16 09:22:48 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=355556D9E580915118CD7EF736653A89 -- C:\WINDOWS\$NtUninstallKB2592799$\afd.sys
[2008/10/16 11:07:58 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=38D7B715504DA4741DF35E3594FE2099 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys
[2008/08/14 06:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys
[2008/10/16 10:43:01 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7618D5218F2A614672EC61A80D854A37 -- C:\WINDOWS\$NtUninstallKB2503665$\afd.sys
[2008/08/14 06:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$NtUninstallKB2509553$\afd.sys
[2011/02/16 09:25:05 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=8D499B1276012EB907E7A9E0F4D8FDA4 -- C:\WINDOWS\$hf_mig$\KB2503665\SP3QFE\afd.sys
[2008/06/20 07:48:03 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys
[2008/06/20 07:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\$NtUninstallKB956803$\afd.sys
[2011/08/17 09:41:46 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=F6B7B1ECD7B41736BDB6FF4B092BCB79 -- C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys
< MD5 for: ATAPI.SYS >[2008/04/14 08:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
< MD5 for: EXPLORER.EXE >[2008/04/14 08:00:00 | 001,033,728 | -H-- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 08:00:00 | 001,033,728 | -H-- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: VOLSNAP.SYS >[2008/04/14 08:00:00 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\dllcache\volsnap.sys
[2008/04/14 08:00:00 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\drivers\volsnap.sys
< MD5 for: WINLOGON.EXE >[2008/04/14 08:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/03/24 10:24:10 | 000,834,712 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/03/24 10:24:10 | 000,834,712 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/03/24 10:24:10 | 000,834,712 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/03/24 10:24:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/03/24 10:24:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/03/24 10:24:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --show-icons [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --hide-icons [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/12/16 08:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/12/16 08:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/12/16 08:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/03/24 10:24:10 | 000,834,712 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/03/24 10:24:10 | 000,834,712 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/03/24 10:24:10 | 000,834,712 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/03/24 10:24:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/03/24 10:24:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/03/24 10:24:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --show-icons [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --hide-icons [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Documents and Settings\me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/03/21 08:21:14 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/12/16 08:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/12/16 08:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/12/16 08:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[C:\WINDOWS\$NtUninstallKB57722$] -> Error: Cannot create file handle -> Unknown point type
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
========== Alternate Data Streams ========== @Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
#4 EXTRAS
OTL Extras logfile created on: 4/12/2012 7:03:25 AM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\me\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.66 Gb Available Physical Memory | 82.97% Memory free
3.85 Gb Paging File | 3.67 Gb Available in Paging File | 95.44% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 121.90 Gb Free Space | 52.35% Space Free | Partition Type: NTFS
Drive F: | 3.73 Gb Total Space | 1.01 Gb Free Space | 27.10% Space Free | Partition Type: FAT32
Computer Name: B455DF2A840947D | User Name: me | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-1220945662-1972579041-1801674531-1003\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java 6 Update 23
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{32714287-4234-412A-877B-D33AFABFDE2B}" = EverQuest Titanium
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{6583D00E-0924-4950-8BE9-5D09FE70B333}" = MTX
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.89
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.89
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.36
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.9.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BEFBEDDF-1417-4C8A-92FB-F003C0D41199}" = OpenOffice.org 3.2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C6}" = WinZip 16.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F20C1251-1D0A-4944-B2AE-678581B33B19}" = Neverwinter Nights 2
"BitZipper_is1" = BitZipper 2010
"hon" = Heroes of Newerth
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero 7_is1" = Nero 7.5.9.0A
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"StarCraft II" = StarCraft II
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.4
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1220945662-1972579041-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:25 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:38 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
Error - 4/5/2012 10:19:38 PM | Computer Name = B455DF2A840947D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.
[ System Events ]
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Streamip service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Mhn service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The BrSerIf service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Agrsrvce service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Ldap service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Ndisipo service terminated with the following error: %%2
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Xnacc service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The SE2Emdm service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The Cmuda3 service terminated with the following error: %%126
Error - 4/11/2012 6:00:58 PM | Computer Name = B455DF2A840947D | Source = Service Control Manager | ID = 7023
Description = The C34nb4c5 service terminated with the following error: %%126
< End of report >