OTL logfile created on: 6/16/2010 1:37:37 PM - Run
OTLPE by OldTimer - Version 3.1.39.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
638.00 Mb Total Physical Memory | 328.00 Mb Available Physical Memory | 51.00% Memory free
582.00 Mb Paging File | 369.00 Mb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 192 960 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.38 Gb Total Space | 0.82 Gb Free Space | 4.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 433.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV - File not found [Auto] -- -- (winvnc)
SRV - [2009/12/10 18:31:35 | 002,477,304 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2009/12/10 18:31:35 | 001,864,888 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec AntiVirus\Smc.exe -- (SmcService)
SRV - [2009/12/10 18:31:35 | 000,341,320 | ---- | M] (Symantec Corporation) [Disabled] -- C:\Program Files\Symantec AntiVirus\SNAC.EXE -- (SNAC)
SRV - [2009/12/10 18:31:35 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/12/10 18:31:35 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009/03/20 20:10:15 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2006/05/17 16:38:48 | 000,077,824 | ---- | M] (SEIKO EPSON Corp.) [Auto] -- C:\WINDOWS\System32\EpStsSrv.exe -- (EPSON ESCPOS Status Service)
SRV - [2006/05/12 17:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) [Auto] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - [2010/06/14 17:42:51 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100614.025\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/06/14 17:42:50 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100614.025\NAVENG.SYS -- (NAVENG)
DRV - [2010/06/07 15:22:49 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/05/27 00:15:21 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2009/12/14 15:50:41 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/12/10 18:31:35 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/12/10 18:31:35 | 000,320,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/12/10 18:31:35 | 000,281,648 | ---- | M] (Symantec Corporation) [File_System | System] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/12/10 18:31:35 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/12/10 18:31:34 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2006/05/11 12:51:34 | 000,048,256 | ---- | M] (SEIKO EPSON Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\TMUSBXP.SYS -- (TMUSB)
DRV - [2006/05/11 12:51:32 | 000,095,485 | ---- | M] (MK Systems CO., LTD.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\ESDPDX01.SYS -- (Esdpdx01)
DRV - [2003/01/14 13:37:40 | 000,011,319 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\a302.sys -- ({E6759E0C-470B-44DC-A4A1-627E68BB3A85})
DRV - [2001/08/22 10:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
DRV - [2001/08/17 09:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\administrator.NCU_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\administrator.NCU_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\administrator.NCU_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\ascholp_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\ascholp_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\ascholp_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\ascholp_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;<local>
IE - HKU\ascholp_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=10.1.3.50:3128;https=10.1.3.50:3128;gopher=10.1.3.50:3128;socks=10.1.3.50:3128
IE - HKU\cpetrucci_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\cpetrucci_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\cpetrucci_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\cpetrucci_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;*nada.com;<local>
IE - HKU\cpetrucci_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\etaylor_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\etaylor_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\etaylor_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\jperine_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\jperine_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\jperine_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\jperine_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;*nada.com;<local>
IE - HKU\jperine_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\jsicinski_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\jsicinski_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\jsicinski_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\jsicinski_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;<local>
IE - HKU\jsicinski_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\jwilliamson_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\jwilliamson_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\jwilliamson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\jwilliamson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;<local>
IE - HKU\jwilliamson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=10.1.3.50:3128;https=10.1.3.50:3128;gopher=10.1.3.50:3128;socks=10.1.3.50:3128
IE - HKU\kcreger_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\kcreger_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\kcreger_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\kcreger_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;<local>
IE - HKU\kcreger_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\kwilson_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\kwilson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\kwilson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;<local>
IE - HKU\kwilson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\lrobinson_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\lrobinson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\lrobinson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;<local>
IE - HKU\lrobinson_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\mcastillo_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\mcastillo_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\mcastillo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\mcastillo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;*nada.com;<local>
IE - HKU\mcastillo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\mlalowski_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\mlalowski_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\mlalowski_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\mlalowski_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;<local>
IE - HKU\mlalowski_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=10.1.3.50:3128;https=10.1.3.50:3128;gopher=10.1.3.50:3128;socks=10.1.3.50:3128
IE - HKU\momara_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\momara_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\momara_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\momara_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;<local>
IE - HKU\momara_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\msnoble_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\msnoble_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\msnoble_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\msnoble_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;*nada.com;<local>
IE - HKU\msnoble_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\mviehweg_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\mviehweg_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\mviehweg_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\mviehweg_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;*nada.com;<local>
IE - HKU\mviehweg_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\nmartinez_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\nmartinez_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\nmartinez_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\nmartinez_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;<local>
IE - HKU\nmartinez_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\pfhouse_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\pfhouse_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\pfhouse_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\rjacobo_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\rjacobo_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\rjacobo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\rjacobo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;*.elanfinancialservices.com;*nada.com;<local>
IE - HKU\rjacobo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\rruettiger_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\rruettiger_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\rruettiger_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\rruettiger_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;<local>
IE - HKU\rruettiger_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\sathanasiou_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://intranetIE - HKU\sathanasiou_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetIE - HKU\sathanasiou_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\sathanasiou_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *intranet;*10.1.3.2;*192.168.10.5;192.168.10.2;*e-facts.org;*broker2.images.membersunited.org;*federalreserve.org;170.209.0.2;170.209.0.3;*10.1.3.8;*.docmagic.com;*numarkcu.org;<local>
IE - HKU\sathanasiou_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.1.3.50:3128
IE - HKU\scan_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranet/IE - HKU\scan_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2005/11/01 08:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ESDUSBMon.exe] C:\WINDOWS\system32\ESDUSBMon.exe (SEIKO EPSON Corp.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [WinVNC] C:\Program Files\TightVNC\WinVNC.exe File not found
O4 - HKU\.DEFAULT..\RunOnce: [TSClientAXDisabler] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [TSClientMSIUninstaller] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\nmartinez_ON_C..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Remote Admin Server.lnk = C:\Program Files\Symitar\SFW\RemoteAdminServer.exe (Symitar™, A Jack Henry Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\cpetrucci\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\jperine\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\kcreger\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\mcastillo\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\mviehweg\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\rjacobo\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\administrator.NCU_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\administrator.NCU_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\ascholp_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\cpetrucci_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\etaylor_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\etaylor_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\etaylor_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\jperine_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\jsicinski_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\jwilliamson_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\kcreger_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\kwilson_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\lrobinson_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\mcastillo_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\mlalowski_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\momara_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\msnoble_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\mviehweg_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\nmartinez_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\nmartinez_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\pfhouse_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\pfhouse_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\rjacobo_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\rruettiger_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\sathanasiou_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\scan_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ncu.local
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/11/02 15:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/06/14 18:03:28 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010/06/14 18:02:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Sun
[2010/06/14 17:59:36 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/06/11 16:59:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mviehweg\Application Data\Sun
[2010/06/11 16:00:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/06/11 15:29:09 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/06/11 15:29:09 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/06/11 15:29:09 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/06/11 15:29:08 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/06/11 15:28:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/06/11 15:27:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/06/09 09:12:11 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asycfilt.dll
[2010/06/09 05:22:22 | 000,285,696 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\dllcache\atmfd.dll
[2010/06/03 16:29:21 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/06/03 16:29:21 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/06/03 16:29:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/06/03 16:29:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/05/24 18:07:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mviehweg\Application Data\OpenOffice.org
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/06/16 13:27:05 | 000,262,144 | -H-- | M] () -- C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/06/16 13:27:05 | 000,262,144 | -H-- | M] () -- C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/06/16 13:26:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/16 13:26:46 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/14 18:04:12 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/06/14 18:04:11 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/06/14 18:04:02 | 003,766,762 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/06/14 17:45:32 | 001,835,008 | -H-- | M] () -- C:\Documents and Settings\etaylor\NTUSER.DAT
[2010/06/14 17:45:32 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\etaylor\ntuser.ini
[2010/06/14 17:22:00 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/11 17:04:37 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mviehweg\ntuser.ini
[2010/06/11 17:04:36 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\mviehweg\NTUSER.DAT
[2010/06/11 17:04:25 | 003,771,514 | -H-- | M] () -- C:\Documents and Settings\mviehweg\Local Settings\Application Data\IconCache.db
[2010/06/11 16:19:02 | 000,141,240 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 16:00:54 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/06/11 15:23:58 | 003,706,469 | R--- | M] () -- C:\Documents and Settings\etaylor\Desktop\ComboFix.exe
[2010/06/11 15:23:58 | 003,706,469 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/06/09 17:40:43 | 000,000,112 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/09 17:38:21 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/09 17:25:32 | 000,521,470 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/09 17:25:32 | 000,456,304 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/09 17:25:32 | 000,075,210 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/09 08:32:02 | 001,113,559 | ---- | M] () -- C:\Documents and Settings\etaylor\Desktop\sav_log.csv
[2010/06/03 17:08:36 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\etaylor\Desktop\dds.scr
[2010/06/03 15:52:27 | 000,004,748 | RHS- | M] () -- C:\Documents and Settings\etaylor\ntuser.pol
[2010/06/02 19:45:57 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\jperine\ntuser.ini
[2010/06/02 19:45:56 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\jperine\NTUSER.DAT
[2010/06/02 19:41:30 | 003,765,898 | -H-- | M] () -- C:\Documents and Settings\jperine\Local Settings\Application Data\IconCache.db
[2010/06/02 18:05:24 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\jperine\ntuser.pol
[2010/06/02 16:35:09 | 003,145,728 | -H-- | M] () -- C:\Documents and Settings\cpetrucci\NTUSER.DAT
[2010/06/02 16:35:09 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.ini
[2010/06/02 15:12:56 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mcastillo\ntuser.ini
[2010/06/02 15:12:55 | 003,407,872 | -H-- | M] () -- C:\Documents and Settings\mcastillo\NTUSER.DAT
[2010/06/01 20:09:58 | 002,097,152 | -H-- | M] () -- C:\Documents and Settings\kcreger\NTUSER.DAT
[2010/06/01 20:09:58 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\kcreger\ntuser.ini
[2010/05/28 20:16:15 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\rjacobo\NTUSER.DAT
[2010/05/28 20:16:15 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\rjacobo\ntuser.ini
[2010/05/28 20:16:04 | 003,233,718 | -H-- | M] () -- C:\Documents and Settings\rjacobo\Local Settings\Application Data\IconCache.db
[2010/05/27 20:09:26 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\msnoble\ntuser.ini
[2010/05/27 20:09:25 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\msnoble\NTUSER.DAT
[2010/05/27 20:09:13 | 004,286,162 | -H-- | M] () -- C:\Documents and Settings\msnoble\Local Settings\Application Data\IconCache.db
[2010/05/27 18:23:16 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\msnoble\ntuser.pol
[2010/05/26 19:07:59 | 000,000,864 | ---- | M] () -- C:\Documents and Settings\mviehweg\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
[2010/05/25 18:09:00 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mcastillo\ntuser.pol
[2010/05/22 09:21:04 | 000,005,228 | RHS- | M] () -- C:\Documents and Settings\kcreger\ntuser.pol
[2010/05/21 18:25:22 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\rjacobo\ntuser.pol
[2010/05/21 09:13:31 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.pol
[2010/05/20 18:05:51 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mviehweg\ntuser.pol
[2010/05/19 17:24:05 | 000,024,408 | ---- | M] () -- C:\Documents and Settings\mviehweg\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/06/14 17:59:19 | 003,706,469 | R--- | C] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/06/11 16:00:54 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/06/11 16:00:46 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/06/11 15:29:09 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/06/11 15:29:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/06/11 15:29:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/06/11 15:29:09 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/06/11 15:29:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/06/11 15:26:45 | 003,706,469 | R--- | C] () -- C:\Documents and Settings\etaylor\Desktop\ComboFix.exe
[2010/06/09 08:31:58 | 001,113,559 | ---- | C] () -- C:\Documents and Settings\etaylor\Desktop\sav_log.csv
[2010/06/03 17:11:14 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\etaylor\Desktop\gmer.exe
[2010/06/03 17:11:05 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\etaylor\Desktop\dds.scr
[2010/05/26 19:07:59 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\mviehweg\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
[2010/01/08 15:11:23 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\mlalowski\ntuser.pol
[2010/01/08 15:11:21 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\mlalowski\ntuser.ini
[2010/01/08 15:11:18 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\mlalowski\ntuser.dat.LOG
[2010/01/08 15:11:17 | 001,048,576 | -H-- | C] () -- C:\Documents and Settings\mlalowski\NTUSER.DAT
[2010/01/04 09:17:32 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\rjacobo\ntuser.pol
[2010/01/04 09:17:27 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\rjacobo\ntuser.ini
[2010/01/04 09:17:23 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\rjacobo\ntuser.dat.LOG
[2010/01/04 09:17:22 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\rjacobo\NTUSER.DAT
[2009/12/29 10:14:38 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\mviehweg\ntuser.pol
[2009/12/29 10:14:36 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\mviehweg\ntuser.ini
[2009/12/29 10:14:32 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\mviehweg\NTUSER.DAT
[2009/12/29 10:14:32 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\mviehweg\ntuser.dat.LOG
[2009/11/03 19:13:23 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\jperine\ntuser.pol
[2009/11/03 19:13:21 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\jperine\ntuser.ini
[2009/11/03 19:13:18 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\jperine\ntuser.dat.LOG
[2009/11/03 19:13:17 | 001,572,864 | -H-- | C] () -- C:\Documents and Settings\jperine\NTUSER.DAT
[2009/08/24 08:19:26 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\rruettiger\ntuser.pol
[2009/08/24 08:19:24 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\rruettiger\ntuser.ini
[2009/08/24 08:19:20 | 001,048,576 | -H-- | C] () -- C:\Documents and Settings\rruettiger\NTUSER.DAT
[2009/08/24 08:19:20 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\rruettiger\ntuser.dat.LOG
[2009/06/05 14:48:59 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\sathanasiou\ntuser.pol
[2009/06/05 14:48:57 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\sathanasiou\ntuser.ini
[2009/06/05 14:48:54 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\sathanasiou\NTUSER.DAT
[2009/06/05 14:48:54 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\sathanasiou\ntuser.dat.LOG
[2009/05/11 17:43:17 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\ascholp\ntuser.pol
[2009/05/11 17:43:15 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\ascholp\ntuser.ini
[2009/05/11 17:43:11 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\ascholp\NTUSER.DAT
[2009/05/11 17:43:11 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\ascholp\ntuser.dat.LOG
[2009/03/23 18:02:38 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\jsicinski\ntuser.pol
[2009/03/23 18:02:36 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\jsicinski\ntuser.ini
[2009/03/23 18:02:33 | 001,048,576 | -H-- | C] () -- C:\Documents and Settings\jsicinski\NTUSER.DAT
[2009/03/23 18:02:33 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\jsicinski\ntuser.dat.LOG
[2008/12/30 16:10:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2008/12/19 11:15:28 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\momara\ntuser.pol
[2008/12/19 11:15:26 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\momara\ntuser.ini
[2008/12/19 11:15:23 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\momara\ntuser.dat.LOG
[2008/12/19 11:15:22 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\momara\NTUSER.DAT
[2008/12/18 16:41:53 | 000,006,808 | RHS- | C] () -- C:\Documents and Settings\kwilson\ntuser.pol
[2008/12/18 16:41:51 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\kwilson\ntuser.ini
[2008/12/18 16:41:48 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\kwilson\ntuser.dat.LOG
[2008/12/18 16:41:47 | 000,786,432 | -H-- | C] () -- C:\Documents and Settings\kwilson\NTUSER.DAT
[2008/12/06 10:33:20 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\jwilliamson\ntuser.pol
[2008/12/06 10:33:19 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\jwilliamson\ntuser.ini
[2008/12/06 10:33:16 | 002,359,296 | -H-- | C] () -- C:\Documents and Settings\jwilliamson\NTUSER.DAT
[2008/12/06 10:33:16 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\jwilliamson\ntuser.dat.LOG
[2008/11/07 13:20:13 | 000,004,748 | RHS- | C] () -- C:\Documents and Settings\etaylor\ntuser.pol
[2008/11/07 13:20:10 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\etaylor\ntuser.ini
[2008/11/07 13:20:07 | 001,835,008 | -H-- | C] () -- C:\Documents and Settings\etaylor\NTUSER.DAT
[2008/11/07 13:20:07 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\etaylor\ntuser.dat.LOG
[2008/10/08 15:23:07 | 000,005,228 | RHS- | C] () -- C:\Documents and Settings\kcreger\ntuser.pol
[2008/10/08 15:23:06 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\kcreger\ntuser.ini
[2008/10/08 15:23:03 | 002,097,152 | -H-- | C] () -- C:\Documents and Settings\kcreger\NTUSER.DAT
[2008/10/08 15:23:03 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\kcreger\ntuser.dat.LOG
[2008/09/22 16:51:58 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\cpetrucci\ntuser.pol
[2008/09/22 16:51:56 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\cpetrucci\ntuser.ini
[2008/09/22 16:51:54 | 003,145,728 | -H-- | C] () -- C:\Documents and Settings\cpetrucci\NTUSER.DAT
[2008/09/22 16:51:54 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\cpetrucci\ntuser.dat.LOG
[2008/06/23 14:34:55 | 000,004,624 | RHS- | C] () -- C:\Documents and Settings\scan\ntuser.pol
[2008/06/23 14:34:53 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\scan\ntuser.ini
[2008/06/23 14:34:50 | 000,786,432 | -H-- | C] () -- C:\Documents and Settings\scan\NTUSER.DAT
[2008/06/23 14:34:50 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\scan\ntuser.dat.LOG
[2008/02/06 17:23:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\mcastillo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/05 18:54:08 | 000,004,253 | ---- | C] () -- C:\WINDOWS\pixcache.ini
[2008/01/14 17:10:51 | 000,002,688 | RHS- | C] () -- C:\Documents and Settings\administrator.NCU\ntuser.pol
[2007/02/20 10:02:24 | 000,262,144 | ---- | C] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat
[2007/02/20 10:02:24 | 000,008,192 | -H-- | C] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
[2007/01/10 14:52:26 | 000,006,808 | RHS- | C] () -- C:\Documents and Settings\lrobinson\ntuser.pol
[2007/01/10 14:52:24 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\lrobinson\ntuser.ini
[2007/01/10 14:52:23 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\lrobinson\ntuser.dat.LOG
[2007/01/10 14:52:22 | 000,786,432 | -H-- | C] () -- C:\Documents and Settings\lrobinson\NTUSER.DAT
[2007/01/05 17:15:00 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\ODMA32.dll
[2007/01/05 16:21:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\BridgerInsight.INI
[2007/01/03 12:24:36 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/19 17:21:58 | 000,004,748 | RHS- | C] () -- C:\Documents and Settings\pfhouse\ntuser.pol
[2006/12/05 13:21:52 | 000,008,628 | RHS- | C] () -- C:\Documents and Settings\nmartinez\ntuser.pol
[2006/12/05 13:21:50 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\nmartinez\ntuser.ini
[2006/12/05 13:21:49 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\nmartinez\ntuser.dat.LOG
[2006/12/05 13:21:47 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\nmartinez\NTUSER.DAT
[2006/12/03 13:51:59 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\administrator.NCU\ntuser.ini
[2006/12/03 13:51:58 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\administrator.NCU\ntuser.dat.LOG
[2006/12/03 13:51:57 | 001,048,576 | -H-- | C] () -- C:\Documents and Settings\administrator.NCU\NTUSER.DAT
[2006/12/01 15:54:35 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\HPPAPR01.DLL
[2006/11/30 15:41:43 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\mcastillo\ntuser.pol
[2006/11/30 15:41:40 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\mcastillo\ntuser.ini
[2006/11/30 15:41:39 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\mcastillo\ntuser.dat.LOG
[2006/11/30 15:41:38 | 003,407,872 | -H-- | C] () -- C:\Documents and Settings\mcastillo\NTUSER.DAT
[2006/11/30 13:48:44 | 000,006,568 | RHS- | C] () -- C:\Documents and Settings\msnoble\ntuser.pol
[2006/11/30 13:48:42 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\msnoble\ntuser.dat.LOG
[2006/11/30 13:48:42 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\msnoble\ntuser.ini
[2006/11/30 13:48:41 | 001,572,864 | -H-- | C] () -- C:\Documents and Settings\msnoble\NTUSER.DAT
[2006/11/28 11:29:19 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\SharpImg.dll
[2006/11/28 11:29:18 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\EpsStmEW.DLL
[2006/11/28 11:03:42 | 000,003,062 | ---- | C] () -- C:\WINDOWS\SigPlus.ini
[2006/11/02 19:58:55 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/02 18:49:51 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\pfhouse\ntuser.dat.LOG
[2006/11/02 18:49:51 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\pfhouse\ntuser.ini
[2006/11/02 18:49:50 | 001,572,864 | -H-- | C] () -- C:\Documents and Settings\pfhouse\NTUSER.DAT
[2006/11/02 18:12:03 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2006/11/02 18:12:02 | 000,077,824 | -H-- | C] () -- C:\Documents and Settings\Administrator\ntuser.dat.LOG
[2006/11/02 18:12:01 | 000,786,432 | -H-- | C] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2006/11/02 18:04:05 | 000,262,144 | -H-- | C] () -- C:\Documents and Settings\LocalService\NTUSER.DAT
[2006/11/02 18:04:05 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2006/11/02 18:04:05 | 000,000,020 | -HS- | C] () -- C:\Documents and Settings\LocalService\ntuser.ini
[2006/11/02 15:19:43 | 000,000,020 | -HS- | C] () -- C:\Documents and Settings\NetworkService\ntuser.ini
[2006/11/02 15:19:42 | 000,262,144 | -H-- | C] () -- C:\Documents and Settings\NetworkService\NTUSER.DAT
[2006/11/02 15:19:42 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2006/05/12 12:08:43 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\HPB1320V.DLL
[2006/05/12 12:08:43 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2006/01/30 12:00:00 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\VSHP1020.DLL
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ========== [2008/01/14 17:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\administrator.NCU\Application Data\Windows Desktop Search
[2009/05/29 15:00:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2009/05/11 17:44:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ascholp\Application Data\Windows Desktop Search
[2010/02/10 14:47:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cpetrucci\Application Data\OpenOffice.org
[2008/09/22 16:52:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cpetrucci\Application Data\Windows Desktop Search
[2008/11/07 13:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\etaylor\Application Data\Windows Desktop Search
[2010/02/25 14:59:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jperine\Application Data\OpenOffice.org
[2009/11/03 19:14:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jperine\Application Data\Windows Desktop Search
[2009/03/23 18:03:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jsicinski\Application Data\Windows Desktop Search
[2008/12/06 10:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jwilliamson\Application Data\Windows Desktop Search
[2010/02/19 11:24:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kcreger\Application Data\OpenOffice.org
[2008/10/08 15:23:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kcreger\Application Data\Windows Desktop Search
[2008/12/18 16:42:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kwilson\Application Data\Windows Desktop Search
[2008/12/09 17:44:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lrobinson\Application Data\Windows Desktop Search
[2010/03/30 18:34:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mcastillo\Application Data\OpenOffice.org
[2007/10/29 18:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mcastillo\Application Data\Windows Desktop Search
[2010/01/08 15:12:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mlalowski\Application Data\Windows Desktop Search
[2008/12/19 11:16:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\momara\Application Data\Windows Desktop Search
[2008/03/19 14:22:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\msnoble\Application Data\Windows Desktop Search
[2010/05/24 18:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mviehweg\Application Data\OpenOffice.org
[2009/12/29 10:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mviehweg\Application Data\Windows Desktop Search
[2007/12/05 16:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nmartinez\Application Data\Windows Desktop Search
[2007/11/03 12:14:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pfhouse\Application Data\Windows Desktop Search
[2010/04/23 13:46:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rjacobo\Application Data\OpenOffice.org
[2010/01/04 09:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rjacobo\Application Data\Windows Desktop Search
[2009/08/24 08:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rruettiger\Application Data\Windows Desktop Search
[2009/06/05 14:49:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\sathanasiou\Application Data\Windows Desktop Search
[2008/06/23 14:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\scan\Application Data\Windows Desktop Search
========== Purity Check ========== ========== Custom Scans ========== Invalid Environment Variable: %ALLUSERSPROFILE%\Application Data\*.
Invalid Environment Variable: %ALLUSERSPROFILE%\Application Data\*.exe
Invalid Environment Variable: %APPDATA%\*.
Invalid Environment Variable: %APPDATA%\*.exe
< %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2005/11/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2005/11/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2005/11/01 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2005/11/01 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2005/11/01 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2005/11/01 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USERINIT.EXE >[2005/11/01 08:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 06:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 06:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2006/11/02 08:13:30 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/11/02 08:13:30 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/11/02 08:13:30 | 000,876,544 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2008/06/20 13:46:57 | 000,147,968 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dnsapi.dll
[2010/05/04 13:20:35 | 006,067,200 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\ieframe.dll
[2010/05/04 13:20:36 | 000,268,288 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\iertutil.dll
[2008/04/14 06:42:02 | 000,274,944 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 06:42:04 | 000,067,072 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\ntdsapi.dll
[2008/04/14 06:42:04 | 000,023,040 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\psapi.dll
[2008/06/17 15:02:19 | 008,461,312 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< CREATERESTOREPOINT >< End of report >
[2010/06/16 13:38:45 | 000,077,824 | -H-- | M] () -- C:\Documents and Settings\Administrator\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\sathanasiou\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\rruettiger\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\mviehweg\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\mcastillo\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\kcreger\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\jwilliamson\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\jperine\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\etaylor\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\ascholp\ntuser.dat.LOG
[2010/06/16 13:34:02 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\administrator.NCU\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\scan\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\rjacobo\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\pfhouse\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\nmartinez\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\msnoble\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\momara\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\mlalowski\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\lrobinson\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\kwilson\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\jsicinski\ntuser.dat.LOG
[2010/06/16 13:34:01 | 000,008,192 | -H-- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.dat.LOG
[2010/06/16 13:27:05 | 000,262,144 | -H-- | M] () -- C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/06/16 13:27:05 | 000,262,144 | -H-- | M] () -- C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/06/16 13:26:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/16 13:26:46 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/14 18:04:12 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/06/14 18:04:11 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/06/14 18:04:02 | 003,766,762 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/06/14 18:02:40 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Administrator\Cookies
[2010/06/14 18:02:31 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Administrator\Application Data\Microsoft
[2010/06/14 18:02:25 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Administrator\Application Data
[2010/06/14 18:02:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Sun
[2010/06/14 17:59:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Desktop
[2010/06/14 17:45:32 | 001,835,008 | -H-- | M] () -- C:\Documents and Settings\etaylor\NTUSER.DAT
[2010/06/14 17:45:32 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\etaylor\ntuser.ini
[2010/06/14 17:22:00 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/11 17:04:37 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mviehweg\ntuser.ini
[2010/06/11 17:04:36 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\mviehweg\NTUSER.DAT
[2010/06/11 17:04:25 | 003,771,514 | -H-- | M] () -- C:\Documents and Settings\mviehweg\Local Settings\Application Data\IconCache.db
[2010/06/11 16:59:32 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\mviehweg\Application Data
[2010/06/11 16:59:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mviehweg\Application Data\Sun
[2010/06/11 16:52:30 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\mviehweg\Cookies
[2010/06/11 16:19:02 | 000,141,240 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 16:13:32 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\etaylor\Application Data
[2010/06/11 15:26:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\etaylor\Desktop
[2010/06/11 15:23:58 | 003,706,469 | R--- | M] () -- C:\Documents and Settings\etaylor\Desktop\ComboFix.exe
[2010/06/11 15:23:58 | 003,706,469 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/06/09 17:40:43 | 000,000,112 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/09 17:38:21 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/09 17:25:32 | 000,521,470 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/09 17:25:32 | 000,456,304 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/09 17:25:32 | 000,075,210 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/09 17:04:02 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/06/09 08:32:02 | 001,113,559 | ---- | M] () -- C:\Documents and Settings\etaylor\Desktop\sav_log.csv
[2010/06/04 15:59:32 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\etaylor\Recent
[2010/06/04 13:46:09 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\etaylor\Cookies
[2010/06/04 13:44:28 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\NetworkService\Cookies
[2010/06/04 13:42:46 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\LocalService\Cookies
[2010/06/04 12:32:39 | 000,000,000 | ---D | M] -- C:\Program Files\Symantec AntiVirus
[2010/06/03 17:08:36 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\etaylor\Desktop\dds.scr
[2010/06/03 16:44:51 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\cpetrucci\Cookies
[2010/06/03 16:44:32 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\jperine\Cookies
[2010/06/03 16:44:19 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\kcreger\Cookies
[2010/06/03 16:43:50 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\mcastillo\Cookies
[2010/06/03 16:43:48 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\msnoble\Cookies
[2010/06/03 16:42:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\rjacobo\Cookies
[2010/06/03 16:37:52 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\mcastillo\Recent
[2010/06/03 16:37:52 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\cpetrucci\Recent
[2010/06/03 16:37:51 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\rjacobo\Recent
[2010/06/03 16:29:52 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\Java
[2010/06/03 16:29:03 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/06/03 16:26:27 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\etaylor\Local Settings
[2010/06/03 15:52:27 | 000,004,748 | RHS- | M] () -- C:\Documents and Settings\etaylor\ntuser.pol
[2010/06/02 19:45:57 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\jperine\ntuser.ini
[2010/06/02 19:45:56 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\jperine\NTUSER.DAT
[2010/06/02 19:41:30 | 003,765,898 | -H-- | M] () -- C:\Documents and Settings\jperine\Local Settings\Application Data\IconCache.db
[2010/06/02 18:05:24 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\jperine\ntuser.pol
[2010/06/02 16:35:09 | 003,145,728 | -H-- | M] () -- C:\Documents and Settings\cpetrucci\NTUSER.DAT
[2010/06/02 16:35:09 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.ini
[2010/06/02 15:12:56 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mcastillo\ntuser.ini
[2010/06/02 15:12:55 | 003,407,872 | -H-- | M] () -- C:\Documents and Settings\mcastillo\NTUSER.DAT
[2010/06/01 20:09:58 | 002,097,152 | -H-- | M] () -- C:\Documents and Settings\kcreger\NTUSER.DAT
[2010/06/01 20:09:58 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\kcreger\ntuser.ini
[2010/05/28 20:16:15 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\rjacobo\NTUSER.DAT
[2010/05/28 20:16:15 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\rjacobo\ntuser.ini
[2010/05/28 20:16:04 | 003,233,718 | -H-- | M] () -- C:\Documents and Settings\rjacobo\Local Settings\Application Data\IconCache.db
[2010/05/27 20:09:26 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\msnoble\ntuser.ini
[2010/05/27 20:09:25 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\msnoble\NTUSER.DAT
[2010/05/27 20:09:13 | 004,286,162 | -H-- | M] () -- C:\Documents and Settings\msnoble\Local Settings\Application Data\IconCache.db
[2010/05/27 18:23:16 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\msnoble\ntuser.pol
[2010/05/26 19:07:59 | 000,000,864 | ---- | M] () -- C:\Documents and Settings\mviehweg\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
[2010/05/26 19:07:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\mviehweg\Application Data\Microsoft
[2010/05/25 18:09:00 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mcastillo\ntuser.pol
[2010/05/24 18:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mviehweg\Application Data\OpenOffice.org
[2010/05/22 09:21:04 | 000,005,228 | RHS- | M] () -- C:\Documents and Settings\kcreger\ntuser.pol
[2010/05/21 18:25:22 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\rjacobo\ntuser.pol
[2010/05/21 09:13:31 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.pol
[2010/05/20 18:05:51 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mviehweg\ntuser.pol
[2010/05/19 17:24:05 | 000,024,408 | ---- | M] () -- C:\Documents and Settings\mviehweg\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/18 18:11:52 | 000,000,000 | R--D | M] -- C:\Documents and Settings\mcastillo\Favorites
[2010/04/22 13:55:57 | 000,024,408 | ---- | M] () -- C:\Documents and Settings\cpetrucci\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/06 16:42:50 | 005,366,094 | -H-- | M] () -- C:\Documents and Settings\etaylor\Local Settings\Application Data\IconCache.db
[2010/02/06 14:04:43 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\ascholp\NTUSER.DAT
[2010/02/06 14:04:43 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\ascholp\ntuser.ini
[2010/02/06 14:04:32 | 003,773,172 | -H-- | M] () -- C:\Documents and Settings\ascholp\Local Settings\Application Data\IconCache.db
[2010/02/02 21:12:57 | 004,313,666 | -H-- | M] () -- C:\Documents and Settings\kcreger\Local Settings\Application Data\IconCache.db
[2010/01/22 21:39:02 | 002,359,296 | -H-- | M] () -- C:\Documents and Settings\jwilliamson\NTUSER.DAT
[2010/01/22 21:39:02 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\jwilliamson\ntuser.ini
[2010/01/22 21:38:51 | 004,311,178 | -H-- | M] () -- C:\Documents and Settings\jwilliamson\Local Settings\Application Data\IconCache.db
[2010/01/20 11:20:37 | 001,048,576 | -H-- | M] () -- C:\Documents and Settings\mlalowski\NTUSER.DAT
[2010/01/20 11:20:37 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mlalowski\ntuser.ini
[2010/01/20 11:20:26 | 003,225,406 | -H-- | M] () -- C:\Documents and Settings\mlalowski\Local Settings\Application Data\IconCache.db
[2010/01/20 11:08:11 | 000,020,624 | ---- | M] () -- C:\Documents and Settings\mlalowski\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/19 15:20:08 | 000,020,624 | ---- | M] () -- C:\Documents and Settings\jperine\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/16 15:24:01 | 003,781,844 | -H-- | M] () -- C:\Documents and Settings\cpetrucci\Local Settings\Application Data\IconCache.db
[2010/01/15 14:35:55 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\ascholp\ntuser.pol
[2010/01/08 15:11:24 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mlalowski\ntuser.pol
[2010/01/05 19:45:55 | 000,020,232 | ---- | M] () -- C:\Documents and Settings\jwilliamson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/05 15:54:42 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\jwilliamson\ntuser.pol
[2009/09/04 09:27:09 | 001,048,576 | -H-- | M] () -- C:\Documents and Settings\rruettiger\NTUSER.DAT
[2009/09/04 09:27:05 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\nmartinez\NTUSER.DAT
[2009/09/04 09:27:05 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\nmartinez\ntuser.ini
[2009/09/04 09:26:59 | 003,772,208 | -H-- | M] () -- C:\Documents and Settings\nmartinez\Local Settings\Application Data\IconCache.db
[2009/09/04 08:54:45 | 000,008,628 | RHS- | M] () -- C:\Documents and Settings\nmartinez\ntuser.pol
[2009/09/01 20:08:07 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\rruettiger\ntuser.ini
[2009/09/01 20:07:50 | 002,694,442 | -H-- | M] () -- C:\Documents and Settings\rruettiger\Local Settings\Application Data\IconCache.db
[2009/08/27 15:33:02 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\momara\NTUSER.DAT
[2009/08/27 15:33:02 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\momara\ntuser.ini
[2009/08/27 15:32:48 | 003,230,626 | -H-- | M] () -- C:\Documents and Settings\momara\Local Settings\Application Data\IconCache.db
[2009/08/27 15:13:46 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\momara\ntuser.pol
[2009/08/24 08:19:27 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\rruettiger\ntuser.pol
[2009/08/21 19:06:27 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\sathanasiou\NTUSER.DAT
[2009/08/21 19:06:27 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\sathanasiou\ntuser.ini
[2009/08/21 19:06:22 | 003,228,350 | -H-- | M] () -- C:\Documents and Settings\sathanasiou\Local Settings\Application Data\IconCache.db
[2009/07/10 15:57:08 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\pfhouse\NTUSER.DAT
[2009/07/10 15:14:43 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\sathanasiou\ntuser.pol
[2009/07/03 13:52:38 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\pfhouse\ntuser.ini
[2009/07/03 13:50:29 | 000,004,748 | RHS- | M] () -- C:\Documents and Settings\pfhouse\ntuser.pol
[2009/06/30 11:54:59 | 000,020,232 | ---- | M] () -- C:\Documents and Settings\kcreger\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/06/11 17:03:35 | 000,020,232 | ---- | M] () -- C:\Documents and Settings\mcastillo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/05/12 18:14:38 | 001,048,576 | -H-- | M] () -- C:\Documents and Settings\administrator.NCU\NTUSER.DAT
[2009/05/11 17:11:48 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\administrator.NCU\ntuser.ini
[2009/05/11 17:11:35 | 003,765,890 | -H-- | M] () -- C:\Documents and Settings\administrator.NCU\Local Settings\Application Data\IconCache.db
[2009/05/11 16:37:35 | 000,002,688 | RHS- | M] () -- C:\Documents and Settings\administrator.NCU\ntuser.pol
[2009/03/23 20:21:21 | 001,048,576 | -H-- | M] () -- C:\Documents and Settings\jsicinski\NTUSER.DAT
[2009/03/23 20:21:21 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\jsicinski\ntuser.ini
[2009/03/23 20:21:12 | 002,692,554 | -H-- | M] () -- C:\Documents and Settings\jsicinski\Local Settings\Application Data\IconCache.db
[2009/03/23 18:02:39 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\jsicinski\ntuser.pol
[2009/03/02 21:00:53 | 004,309,866 | -H-- | M] () -- C:\Documents and Settings\mcastillo\Local Settings\Application Data\IconCache.db
[2008/12/18 18:57:33 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\kwilson\NTUSER.DAT
[2008/12/18 18:57:00 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\kwilson\ntuser.ini
[2008/12/18 18:56:42 | 002,691,346 | -H-- | M] () -- C:\Documents and Settings\kwilson\Local Settings\Application Data\IconCache.db
[2008/12/18 16:41:54 | 000,006,808 | RHS- | M] () -- C:\Documents and Settings\kwilson\ntuser.pol
[2008/12/11 21:08:21 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\lrobinson\NTUSER.DAT
[2008/12/11 21:07:28 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\lrobinson\ntuser.ini
[2008/12/11 21:07:21 | 003,235,974 | -H-- | M] () -- C:\Documents and Settings\lrobinson\Local Settings\Application Data\IconCache.db
[2008/12/09 17:44:05 | 000,006,808 | RHS- | M] () -- C:\Documents and Settings\lrobinson\ntuser.pol
[2008/10/09 16:24:24 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\pfhouse\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/07/09 17:02:49 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\scan\NTUSER.DAT
[2008/07/02 16:39:05 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\scan\ntuser.ini
[2008/07/02 15:15:48 | 002,692,452 | -H-- | M] () -- C:\Documents and Settings\scan\Local Settings\Application Data\IconCache.db
[2008/06/23 14:34:56 | 000,004,624 | RHS- | M] () -- C:\Documents and Settings\scan\ntuser.pol
[2008/05/08 19:09:23 | 000,004,608 | ---- | M] () -- C:\Documents and Settings\mcastillo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/03 12:27:51 | 005,354,498 | -H-- | M] () -- C:\Documents and Settings\pfhouse\Local Settings\Application Data\IconCache.db
[2007/02/20 10:02:24 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat
[2006/11/02 18:04:05 | 000,000,020 | -HS- | M] () -- C:\Documents and Settings\LocalService\ntuser.ini
[2006/11/02 15:19:43 | 000,000,020 | -HS- | M] () -- C:\Documents and Settings\NetworkService\ntuser.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\scan\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\sathanasiou\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\rruettiger\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\rjacobo\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\pfhouse\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\nmartinez\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\mviehweg\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\msnoble\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\momara\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\mlalowski\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\mcastillo\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\lrobinson\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\kwilson\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\kcreger\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\jwilliamson\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\jsicinski\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\jperine\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\etaylor\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\cpetrucci\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\ascholp\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Administrator\Application Data\desktop.ini
[2006/11/02 08:14:50 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\administrator.NCU\Application Data\desktop.ini
[2006/06/29 15:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/06/16 13:27:05 | 000,262,144 | -H-- | M] () -- C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/06/16 13:27:05 | 000,262,144 | -H-- | M] () -- C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/06/16 13:26:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/16 13:26:46 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/14 18:04:12 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/06/14 18:04:11 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/06/14 18:04:02 | 003,766,762 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/06/14 17:45:32 | 001,835,008 | -H-- | M] () -- C:\Documents and Settings\etaylor\NTUSER.DAT
[2010/06/14 17:45:32 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\etaylor\ntuser.ini
[2010/06/14 17:22:00 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/11 17:04:37 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mviehweg\ntuser.ini
[2010/06/11 17:04:36 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\mviehweg\NTUSER.DAT
[2010/06/11 17:04:25 | 003,771,514 | -H-- | M] () -- C:\Documents and Settings\mviehweg\Local Settings\Application Data\IconCache.db
[2010/06/11 16:19:02 | 000,141,240 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 16:00:54 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/06/11 15:23:58 | 003,706,469 | R--- | M] () -- C:\Documents and Settings\etaylor\Desktop\ComboFix.exe
[2010/06/11 15:23:58 | 003,706,469 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/06/09 17:40:43 | 000,000,112 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/09 17:38:21 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/09 17:25:32 | 000,521,470 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/09 17:25:32 | 000,456,304 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/09 17:25:32 | 000,075,210 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/09 08:32:02 | 001,113,559 | ---- | M] () -- C:\Documents and Settings\etaylor\Desktop\sav_log.csv
[2010/06/03 17:08:36 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\etaylor\Desktop\dds.scr
[2010/06/03 15:52:27 | 000,004,748 | RHS- | M] () -- C:\Documents and Settings\etaylor\ntuser.pol
[2010/06/02 19:45:57 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\jperine\ntuser.ini
[2010/06/02 19:45:56 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\jperine\NTUSER.DAT
[2010/06/02 19:41:30 | 003,765,898 | -H-- | M] () -- C:\Documents and Settings\jperine\Local Settings\Application Data\IconCache.db
[2010/06/02 18:05:24 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\jperine\ntuser.pol
[2010/06/02 16:35:09 | 003,145,728 | -H-- | M] () -- C:\Documents and Settings\cpetrucci\NTUSER.DAT
[2010/06/02 16:35:09 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.ini
[2010/06/02 15:12:56 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\mcastillo\ntuser.ini
[2010/06/02 15:12:55 | 003,407,872 | -H-- | M] () -- C:\Documents and Settings\mcastillo\NTUSER.DAT
[2010/06/01 20:09:58 | 002,097,152 | -H-- | M] () -- C:\Documents and Settings\kcreger\NTUSER.DAT
[2010/06/01 20:09:58 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\kcreger\ntuser.ini
[2010/05/28 20:16:15 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\rjacobo\NTUSER.DAT
[2010/05/28 20:16:15 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\rjacobo\ntuser.ini
[2010/05/28 20:16:04 | 003,233,718 | -H-- | M] () -- C:\Documents and Settings\rjacobo\Local Settings\Application Data\IconCache.db
[2010/05/27 20:09:26 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\msnoble\ntuser.ini
[2010/05/27 20:09:25 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\msnoble\NTUSER.DAT
[2010/05/27 20:09:13 | 004,286,162 | -H-- | M] () -- C:\Documents and Settings\msnoble\Local Settings\Application Data\IconCache.db
[2010/05/27 18:23:16 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\msnoble\ntuser.pol
[2010/05/26 19:07:59 | 000,000,864 | ---- | M] () -- C:\Documents and Settings\mviehweg\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
[2010/05/25 18:09:00 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mcastillo\ntuser.pol
[2010/05/22 09:21:04 | 000,005,228 | RHS- | M] () -- C:\Documents and Settings\kcreger\ntuser.pol
[2010/05/21 18:25:22 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\rjacobo\ntuser.pol
[2010/05/21 09:13:31 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\cpetrucci\ntuser.pol
[2010/05/20 18:05:51 | 000,006,568 | RHS- | M] () -- C:\Documents and Settings\mviehweg\ntuser.pol
[2010/05/19 17:24:05 | 000,024,408 | ---- | M] () -- C:\Documents and Settings\mviehweg\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== LOP Check ========== [2008/01/14 17:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\administrator.NCU\Application Data\Windows Desktop Search
[2009/05/29 15:00:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2009/05/11 17:44:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ascholp\Application Data\Windows Desktop Search
[2010/02/10 14:47:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cpetrucci\Application Data\OpenOffice.org
[2008/09/22 16:52:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cpetrucci\Application Data\Windows Desktop Search
[2008/11/07 13:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\etaylor\Application Data\Windows Desktop Search
[2010/02/25 14:59:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jperine\Application Data\OpenOffice.org
[2009/11/03 19:14:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jperine\Application Data\Windows Desktop Search
[2009/03/23 18:03:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jsicinski\Application Data\Windows Desktop Search
[2008/12/06 10:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jwilliamson\Application Data\Windows Desktop Search
[2010/02/19 11:24:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kcreger\Application Data\OpenOffice.org
[2008/10/08 15:23:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kcreger\Application Data\Windows Desktop Search
[2008/12/18 16:42:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kwilson\Application Data\Windows Desktop Search
[2008/12/09 17:44:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lrobinson\Application Data\Windows Desktop Search
[2010/03/30 18:34:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mcastillo\Application Data\OpenOffice.org
[2007/10/29 18:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mcastillo\Application Data\Windows Desktop Search
[2010/01/08 15:12:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mlalowski\Application Data\Windows Desktop Search
[2008/12/19 11:16:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\momara\Application Data\Windows Desktop Search
[2008/03/19 14:22:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\msnoble\Application Data\Windows Desktop Search
[2010/05/24 18:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mviehweg\Application Data\OpenOffice.org
[2009/12/29 10:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mviehweg\Application Data\Windows Desktop Search
[2007/12/05 16:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nmartinez\Application Data\Windows Desktop Search
[2007/11/03 12:14:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pfhouse\Application Data\Windows Desktop Search
[2010/04/23 13:46:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rjacobo\Application Data\OpenOffice.org
[2010/01/04 09:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rjacobo\Application Data\Windows Desktop Search
[2009/08/24 08:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rruettiger\Application Data\Windows Desktop Search
[2009/06/05 14:49:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\sathanasiou\Application Data\Windows Desktop Search
[2008/06/23 14:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\scan\Application Data\Windows Desktop Search
========== Purity Check ========== ========== Custom Scans ========== Invalid Environment Variable: %ALLUSERSPROFILE%\Application Data\*.
Invalid Environment Variable: %ALLUSERSPROFILE%\Application Data\*.exe
Invalid Environment Variable: %APPDATA%\*.
Invalid Environment Variable: %APPDATA%\*.exe
< %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2005/11/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2005/11/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2005/11/01 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2005/11/01 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2005/11/01 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2005/11/01 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USERINIT.EXE >[2005/11/01 08:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 06:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 06:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2006/11/02 08:13:30 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/11/02 08:13:30 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/11/02 08:13:30 | 000,876,544 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2008/06/20 13:46:57 | 000,147,968 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dnsapi.dll
[2010/05/04 13:20:35 | 006,067,200 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\ieframe.dll
[2010/05/04 13:20:36 | 000,268,288 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\iertutil.dll
[2008/04/14 06:42:02 | 000,274,944 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 06:42:04 | 000,067,072 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\ntdsapi.dll
[2008/04/14 06:42:04 | 000,023,040 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\psapi.dll
[2008/06/17 15:02:19 | 008,461,312 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
[2010/05/04 13:20:39 | 001,168,384 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\urlmon.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< CREATERESTOREPOINT >< End of report >