Hello Oldman,
I ran OTL under Thunder (with admin privileges), The sound icon is not present, and the MSE icon stays red. However when I go into the security center, the anti virus (MSE) shows started, I suspected it because when I double click on the red icon (or single click and the click "open") it instantly turns green. So it seems to be an icon status display issue and not the service itself. I'm posting the OTL log and then will copy the otl.exe file on the destop of theSR71 user to run it under that user name. I also noticed that if I switch user from Thunder (No sound icon) to SR71 (sound icon present) and then revert back to Thunder, the sound icon is present but when I reboot (Thunder) it's not there ! so it seems that the SR71 profile calls for the icon to be placed in the tray and as long as you do not reboot, the icon stays even when you switch users. The other way of displaying the icon under Thunder is to go to: control panel/sound & audio devices, untick the "place the volume icon in the task bar", click apply and then tick it click apply again...
********************************************************************************
************
OTL Log: Thunder (w/Admin privileges)
********************************************************************************
************
OTL logfile created on: 3/14/2011 6:32:18 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Thunder\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): E:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 17.64 Gb Free Space | 47.37% Space Free | Partition Type: NTFS
Drive E: | 76.33 Gb Total Space | 35.48 Gb Free Space | 46.48% Space Free | Partition Type: NTFS
Computer Name: DELL-450 | User Name: Thunder | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/03/12 15:07:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Thunder\Desktop\OTL.exe
PRC - [2011/03/05 00:42:00 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/11/30 14:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 13:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/12/18 11:47:08 | 009,158,656 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/04/09 12:32:32 | 000,019,456 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CtHelper.exe
PRC - [2006/01/19 10:22:20 | 000,049,152 | ---- | M] (Pinnacle Systems) -- E:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
========== Modules (SafeList) ==========
MOD - [2011/03/12 15:07:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Thunder\Desktop\OTL.exe
MOD - [2010/11/05 20:32:13 | 000,040,448 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 01:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009/07/12 01:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
MOD - [2007/04/09 12:32:30 | 000,008,704 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\ctagent.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/11/11 13:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/03/25 10:25:22 | 030,969,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2008/12/18 11:47:08 | 009,158,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe -- (MSSQL$PINNACLESYS)
SRV - [2007/02/25 22:55:18 | 000,125,048 | ---- | M] (TOSHIBA CORPORATION) [Disabled | Stopped] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2006/01/19 10:22:20 | 000,049,152 | ---- | M] (Pinnacle Systems) [Auto | Running] -- E:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe -- (PinnacleSys.MediaServer)
SRV - [2005/05/03 22:42:56 | 000,323,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE -- (SQLAgent$PINNACLESYS)
SRV - [2001/08/09 02:01:00 | 000,090,112 | ---- | M] (SEIKO EPSON CORPORATION) [Disabled | Stopped] -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)
========== Driver Services (SafeList) ==========
DRV - [2011/03/14 18:28:32 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{755F041A-545E-4088-A890-2DE6B9609B96}\MpKsl564be05d.sys -- (MpKsl564be05d)
DRV - [2011/01/01 19:28:59 | 000,138,664 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2009/06/10 11:23:04 | 000,036,992 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiBus.sys -- (SaiNtBus)
DRV - [2009/06/10 11:23:04 | 000,014,080 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiMini.sys -- (SaiMini)
DRV - [2009/03/18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/04/13 14:36:41 | 000,063,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mf.sys -- (mf)
DRV - [2007/06/11 15:25:28 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2007/05/24 15:27:30 | 000,064,000 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2007/05/01 16:11:28 | 000,132,232 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiH0255.sys -- (SaiH0255)
DRV - [2007/05/01 15:34:56 | 000,132,232 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiHFF12.sys -- (SaiHFF12)
DRV - [2007/05/01 15:34:56 | 000,016,256 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiIFF12.sys -- (SaiIFF12) Immersion's HID USB Driver (FF12)
DRV - [2007/04/24 14:20:06 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (Tosrfbd)
DRV - [2007/04/18 08:59:40 | 000,098,600 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\COMMONFX.DLL -- (COMMONFX.DLL)
DRV - [2007/04/12 08:10:26 | 000,164,608 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CT20XUT.DLL -- (CT20XUT.DLL)
DRV - [2007/04/12 08:10:26 | 000,066,816 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTHWIUT.DLL -- (CTHWIUT.DLL)
DRV - [2007/04/12 08:10:24 | 001,317,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEXFIFX.DLL -- (CTEXFIFX.DLL)
DRV - [2007/04/12 08:10:22 | 000,323,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEDSPSY.DLL -- (CTEDSPSY.DLL)
DRV - [2007/04/12 08:10:22 | 000,128,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEDSPIO.DLL -- (CTEDSPIO.DLL)
DRV - [2007/04/12 08:10:20 | 000,280,320 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEDSPFX.DLL -- (CTEDSPFX.DLL)
DRV - [2007/04/12 08:10:20 | 000,094,976 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTERFXFX.DLL -- (CTERFXFX.DLL)
DRV - [2007/04/12 08:10:18 | 000,168,192 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEAPSFX.DLL -- (CTEAPSFX.DLL)
DRV - [2007/04/12 08:10:16 | 000,560,384 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\CTSBLFX.DLL -- (CTSBLFX.DLL)
DRV - [2007/04/12 08:10:16 | 000,546,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\CTAUDFX.DLL -- (CTAUDFX.DLL)
DRV - [2007/04/10 06:00:24 | 000,157,480 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2007/04/10 05:59:04 | 000,126,760 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2007/04/10 04:32:06 | 000,189,736 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\haP17v2k.sys -- (hap17v2k)
DRV - [2007/04/10 04:31:18 | 000,163,112 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\haP16v2k.sys -- (hap16v2k)
DRV - [2007/04/10 04:29:10 | 000,797,992 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha10kx2k.sys -- (ha10kx2k)
DRV - [2007/04/10 04:28:36 | 000,092,968 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)
DRV - [2007/04/10 04:25:46 | 000,014,632 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2007/04/10 04:21:06 | 000,347,128 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2007/04/10 04:20:38 | 000,520,488 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2007/04/10 04:19:30 | 000,511,272 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2007/03/01 17:53:10 | 000,073,728 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2007/01/22 11:43:26 | 000,053,376 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2006/11/20 18:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (Tosrfbnp)
DRV - [2006/10/10 20:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2005/06/02 20:28:38 | 000,171,008 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2005/02/23 18:40:26 | 000,011,264 | ---- | M] (VOB Computersysteme GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asapiW2k.sys -- (ASAPIW2K)
DRV - [2005/01/06 14:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2003/08/18 16:33:48 | 000,014,564 | ---- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PCLEPCI.sys -- (PCLEPCI)
DRV - [2003/08/08 04:01:00 | 000,004,256 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\userport.sys -- (UserPort)
DRV - [2002/10/16 14:55:48 | 000,002,851 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2001/08/17 14:12:22 | 000,010,368 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrUsbScn.sys -- (BrUsbScn)
DRV - [2001/08/17 14:12:12 | 000,002,944 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrFilt.sys -- (brfilt)
DRV - [2001/08/17 13:12:24 | 000,003,168 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrParImg.sys -- (brparimg)
DRV - [2001/08/17 13:12:18 | 000,039,552 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrParwdm.sys -- (BrParWdm)
DRV - [1999/09/10 13:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "file:///E:/Advent%20files/Docs/bookmarks.html"
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/05 20:32:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/12 17:45:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/05 00:42:12 | 000,000,000 | ---D | M]
[2009/06/28 21:02:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Thunder\Application Data\Mozilla\Extensions
[2011/03/14 15:26:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Thunder\Application Data\Mozilla\Firefox\Profiles\4ddqcgf1.default\extensions
[2010/05/02 13:09:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Thunder\Application Data\Mozilla\Firefox\Profiles\4ddqcgf1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/13 15:12:01 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Documents and Settings\Thunder\Application Data\Mozilla\Firefox\Profiles\4ddqcgf1.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2011/03/14 15:26:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/12/31 14:00:59 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/10/12 20:59:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/29 12:36:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/13 13:46:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/11/05 20:32:14 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/10/12 20:58:52 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Photo Downloader] File not found
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PCLEPCI] C:\Program Files\Pinnacle\PPE\PPE.exe (Pinnacle Systems GmbH)
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BMUpdate] C:\WINDOWS\system32\BMUpdate.exe (EchoBahn.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onec...lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1246220607619 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Thunder\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Thunder\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/11 18:57:39 | 000,000,095 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
MsConfig - Services: "WZCSVC"
MsConfig - Services: "TOSHIBA Bluetooth Service"
MsConfig - Services: "EPSONStatusAgent2"
MsConfig - Services: "CiSvc"
MsConfig - Services: "Bonjour Service"
MsConfig - Services: "Apple Mobile Device"
MsConfig - Services: "JavaQuickStarterService"
MsConfig - Services: "mnmsrvc"
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe - (TOSHIBA CORPORATION.)
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe - (Microsoft Corporation)
MsConfig - StartUpFolder: C:^Documents and Settings^Thunder^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig - StartUpFolder: C:^Documents and Settings^Thunder^Start Menu^Programs^Startup^reminder-ScanSoft Product Registration.lnk - C:\Program Files\Visioneer\PaperPort\Config\Ereg\REMIND32.EXE - ()
MsConfig - StartUpReg:
Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
Adobe Photo Downloader - hkey= - key= - File not found
MsConfig - StartUpReg:
Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
Google Update - hkey= - key= - C:\Documents and Settings\Thunder\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg:
nwiz - hkey= - key= - File not found
MsConfig - StartUpReg:
OneTouch Monitor - hkey= - key= - C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
MsConfig - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg:
Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - StartUpReg:
SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg:
TkBellExe - hkey= - key= - C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 2
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
========== Files/Folders - Created Within 30 Days ==========
[2011/03/13 18:45:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Softland
[2011/03/13 18:44:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FBackup 4
[2011/03/13 18:44:12 | 000,000,000 | ---D | C] -- C:\Program Files\Softland
[2011/03/13 13:58:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/03/13 13:47:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/03/13 13:46:50 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/03/13 13:46:50 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/03/13 13:46:50 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/03/13 13:45:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011/03/12 15:07:19 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Thunder\Desktop\OTL.exe
[2011/03/10 19:39:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\My Documents\My Pictures
[2011/03/10 19:39:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\My Documents\My Videos
[2011/03/10 19:38:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\My Documents\OneNote Notebooks
[2011/03/10 19:38:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\My Documents\School
[2011/03/10 19:38:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\My Documents\Scan2PDF
[2011/03/10 12:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Desktop\Virus
[2011/03/10 12:05:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Desktop\New Folder
[2011/03/10 11:54:02 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Thunder\Desktop\HijackThis.exe
[2011/03/10 10:12:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\Malwarebytes
[2011/03/10 10:12:30 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/10 10:12:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/10 10:12:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/03/10 10:12:26 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/10 10:12:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/10 10:10:26 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Thunder\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/10 02:20:01 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Thunder\My Documents
[2011/03/10 01:49:28 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/03/10 01:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/03/10 01:48:26 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/03/10 01:48:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Desktop\bookmark g_files
[2011/03/10 01:47:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Desktop\World1
[2011/03/10 01:46:17 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/03/09 23:40:25 | 000,000,000 | ---D | C] -- C:\eeepc_iso
[2011/03/09 23:13:08 | 000,000,000 | ---D | C] -- C:\Program Files\WinImage
[2011/03/09 23:10:32 | 000,000,000 | ---D | C] -- C:\Program Files\RMPrepUSB
[2011/03/09 10:29:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/03/03 21:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\xml-pull
[2011/03/03 21:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\scalingrenderer
[2011/03/03 21:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\org
[2011/03/03 21:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\javax
[2011/03/03 21:19:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\de
[2011/03/01 13:05:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Desktop\NT Password editor
[2011/03/01 12:53:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Application Data\FreeBurner
[2011/02/28 10:53:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Scan2PDF
[2011/02/28 00:44:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2011/02/25 10:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Desktop\Pictures Misc
[2011/02/23 19:52:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Local Settings\Application Data\AirMouse
[2011/02/23 19:51:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Thunder\Local Settings\Application Data\Downloaded Installations
[2011/02/23 19:47:18 | 004,465,568 | ---- | C] (RPA Tech, Inc ) -- C:\Documents and Settings\Thunder\Desktop\setup2.5.0.exe
[2011/02/14 17:33:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011/01/24 21:37:42 | 009,777,448 | ---- | C] (Apple Inc.) -- C:\Program Files\iTunes.exe
[2007/04/09 12:32:58 | 000,034,816 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2007/04/09 12:19:16 | 000,010,240 | ---- | C] ( ) -- C:\WINDOWS\System32\killapps.exe
========== Files - Modified Within 30 Days ==========
[2011/03/14 18:33:32 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/14 18:32:15 | 000,482,462 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/14 18:32:15 | 000,086,516 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/14 18:28:55 | 000,000,038 | ---- | M] () -- C:\WINDOWS\BMUpdate.ini
[2011/03/14 18:28:43 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/14 18:28:07 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-1409082233-725345543-1003.job
[2011/03/14 18:28:06 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/14 18:28:06 | 000,000,304 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-1409082233-725345543-1005.job
[2011/03/14 18:27:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/14 18:27:57 | 1609,637,888 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/14 18:27:11 | 000,030,912 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-0000000D-00001102-00000004-10031102}.rfx
[2011/03/14 18:27:11 | 000,030,912 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000005-00000000-0000000D-00001102-00000004-10031102}.rfx
[2011/03/14 18:27:11 | 000,030,120 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-0000000D-00001102-00000004-10031102}.rfx
[2011/03/14 18:27:11 | 000,030,120 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-0000000D-00001102-00000004-10031102}.rfx
[2011/03/14 18:27:11 | 000,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000005-00000000-0000000D-00001102-00000004-10031102}.rfx
[2011/03/14 18:18:57 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-1409082233-725345543-1003.job
[2011/03/14 18:03:04 | 014,746,624 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\outlook.pst
[2011/03/14 17:56:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/14 17:52:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1409082233-725345543-1003UA.job
[2011/03/14 15:30:47 | 000,573,885 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\duo_quickstartguide.pdf
[2011/03/14 10:41:39 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/03/14 10:35:56 | 000,000,312 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-1409082233-725345543-1005.job
[2011/03/13 20:52:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1409082233-725345543-1003Core.job
[2011/03/13 18:44:48 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FBackup 4.lnk
[2011/03/13 17:51:11 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/03/13 15:29:10 | 000,002,652 | ---- | M] () -- C:\WINDOWS\BrmfBidi.ini
[2011/03/13 14:54:52 | 000,000,212 | -HS- | M] () -- C:\boot.ini
[2011/03/12 15:07:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Thunder\Desktop\OTL.exe
[2011/03/11 14:58:09 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/03/11 11:52:58 | 000,033,738 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\3900 Ford Road.jpg
[2011/03/10 20:15:48 | 016,395,215 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Performance4.pdf
[2011/03/10 17:07:30 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/03/10 16:55:08 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/10 16:39:11 | 000,002,507 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Microsoft Outlook 2010.lnk
[2011/03/10 11:54:03 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Thunder\Desktop\HijackThis.exe
[2011/03/10 10:12:30 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/10 10:11:24 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Thunder\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/09 23:10:08 | 001,548,199 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Install_RMPrepUSB_Lite_v2.1.617.zip
[2011/03/09 11:32:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/09 09:49:39 | 000,049,235 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\bookmark1.htm
[2011/03/09 09:48:35 | 000,052,074 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\bookmark.htm
[2011/03/08 00:31:08 | 010,321,985 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Floola-win.zip
[2011/03/07 23:53:53 | 000,002,501 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Microsoft Word 2010.lnk
[2011/03/07 20:41:59 | 000,723,718 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\SDK's Mods 1.3 v4.zip
[2011/03/07 20:10:14 | 000,072,749 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\ModLoader B1.3_01v5.zip
[2011/03/05 20:58:10 | 000,173,190 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\INVedit(2).zip
[2011/03/05 20:29:18 | 000,814,609 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\SDK's Mods 1.3 v1.zip
[2011/03/04 00:27:29 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Earth.lnk
[2011/03/02 11:35:07 | 000,028,160 | ---- | M] () -- C:\Documents and Settings\Thunder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/02 10:56:52 | 000,027,163 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\ICAO TOEFL paper.pdf
[2011/03/01 15:30:22 | 000,231,507 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\Tax Return full version.pdf
[2011/03/01 15:28:21 | 000,205,044 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\Tax returns 2010.pdf
[2011/03/01 14:11:18 | 000,140,935 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\W2 Fox & Roach 2010.pdf
[2011/03/01 12:53:12 | 000,000,639 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Free Easy Burner.lnk
[2011/03/01 11:44:47 | 000,553,125 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\PFS_Online_Instruction_Workbook.pdf
[2011/02/28 12:32:19 | 006,154,847 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\1964 Tamatia Love- Sherman Offer.pdf
[2011/02/28 11:53:47 | 004,379,020 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\1964 1.pdf
[2011/02/28 10:53:51 | 000,000,529 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Scan2PDF.lnk
[2011/02/26 18:01:26 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Flight Instructor.lnk
[2011/02/26 18:01:26 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Install Fighter Ace 2.lnk
[2011/02/26 18:01:26 | 000,000,789 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Flight Simulator 2002.lnk
[2011/02/26 09:50:40 | 000,003,352 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\SettingMulti.class
[2011/02/24 01:16:40 | 000,011,129 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\ModSettings.class
[2011/02/24 01:16:40 | 000,005,414 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\nr.class
[2011/02/24 01:16:40 | 000,004,136 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\ModAction.class
[2011/02/24 01:16:40 | 000,003,272 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\GuiWidgetScreen.class
[2011/02/24 01:16:40 | 000,003,037 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\SettingInt.class
[2011/02/24 01:16:40 | 000,002,909 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetText.class
[2011/02/24 01:16:40 | 000,002,888 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\SettingFloat.class
[2011/02/24 01:16:40 | 000,002,849 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\bq.class
[2011/02/24 01:16:40 | 000,002,742 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\rf.class
[2011/02/24 01:16:40 | 000,002,674 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\SettingKey.class
[2011/02/24 01:16:40 | 000,002,619 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetFloat.class
[2011/02/24 01:16:40 | 000,002,573 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetInt.class
[2011/02/24 01:16:40 | 000,002,518 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetClassicWindow.class
[2011/02/24 01:16:40 | 000,002,484 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetKeybinding.class
[2011/02/24 01:16:40 | 000,002,377 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\lo.class
[2011/02/24 01:16:40 | 000,002,363 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\GuiModScreen.class
[2011/02/24 01:16:40 | 000,002,311 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetBoolean.class
[2011/02/24 01:16:40 | 000,002,253 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\SettingBoolean.class
[2011/02/24 01:16:40 | 000,001,935 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetMulti.class
[2011/02/24 01:16:40 | 000,001,895 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\SettingText.class
[2011/02/24 01:16:40 | 000,001,894 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetClassicTwocolumn.class
[2011/02/24 01:16:40 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetSetting.class
[2011/02/24 01:16:40 | 000,001,650 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\ModSettingScreen.class
[2011/02/24 01:16:40 | 000,001,556 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\GuiModSelect.class
[2011/02/24 01:16:40 | 000,001,539 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\Subscreen.class
[2011/02/24 01:16:40 | 000,001,086 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\ModCallback.class
[2011/02/24 01:16:40 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\Setting.class
[2011/02/24 01:16:40 | 000,000,487 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\WidgetSlider.class
[2011/02/24 01:16:40 | 000,000,299 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\ScreenScaleProxy.class
[2011/02/23 19:48:55 | 004,465,568 | ---- | M] (RPA Tech, Inc ) -- C:\Documents and Settings\Thunder\Desktop\setup2.5.0.exe
[2011/02/21 20:34:40 | 000,011,144 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\font.fnt
[2011/02/21 13:49:16 | 001,663,331 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\Rayan Wrestling Team.JPG
[2011/02/21 04:06:38 | 000,006,671 | ---- | M] () -- C:\Documents and Settings\Thunder\Application Data\twlGuiTheme.xml
[2011/02/19 14:56:16 | 001,500,588 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\Globefish seafood highlights.pdf
[2011/02/19 14:50:35 | 000,834,240 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\Japan Tuna Report March 2004.pdf
[2011/02/19 13:41:24 | 000,116,724 | ---- | M] () -- C:\Documents and Settings\Thunder\My Documents\senegal_fishery_profile_apr08.pdf
[2011/02/17 18:30:54 | 015,624,192 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\viviane ndour_1er anniversaire_.mp3
[2011/02/17 18:29:30 | 027,666,155 | ---- | M] () -- C:\Documents and Settings\Thunder\Desktop\viviane ndour_1er anniversaire_.mp4
[2011/02/13 16:22:21 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
========== Files Created - No Company Name ==========
[2011/03/14 15:30:41 | 000,573,885 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\duo_quickstartguide.pdf
[2011/03/13 18:44:48 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FBackup 4.lnk
[2011/03/12 18:14:34 | 000,000,304 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-1409082233-725345543-1005.job
[2011/03/12 18:14:33 | 000,000,312 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-1409082233-725345543-1005.job
[2011/03/11 11:52:58 | 000,033,738 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\3900 Ford Road.jpg
[2011/03/10 22:33:03 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/10 20:13:38 | 016,395,215 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\Performance4.pdf
[2011/03/10 17:07:02 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/03/10 12:51:50 | 1609,637,888 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/10 10:12:30 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/09 23:09:55 | 001,548,199 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\Install_RMPrepUSB_Lite_v2.1.617.zip
[2011/03/09 10:29:57 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/03/09 09:49:39 | 000,049,235 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\bookmark1.htm
[2011/03/09 09:48:34 | 000,052,074 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\bookmark.htm
[2011/03/08 00:29:36 | 010,321,985 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\Floola-win.zip
[2011/03/07 20:10:51 | 000,723,718 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\SDK's Mods 1.3 v4.zip
[2011/03/07 20:10:12 | 000,072,749 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\ModLoader B1.3_01v5.zip
[2011/03/05 20:53:22 | 000,173,190 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\INVedit(2).zip
[2011/03/05 20:24:46 | 000,814,609 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\SDK's Mods 1.3 v1.zip
[2011/03/04 00:27:29 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Earth.lnk
[2011/03/03 21:19:42 | 000,011,144 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\font.fnt
[2011/03/03 21:19:42 | 000,006,671 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\twlGuiTheme.xml
[2011/03/03 21:19:42 | 000,005,414 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\nr.class
[2011/03/03 21:19:42 | 000,002,742 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\rf.class
[2011/03/03 21:19:42 | 000,002,377 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\lo.class
[2011/03/03 21:19:42 | 000,001,222 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\twlGuiThemeIndentedbuttons.png
[2011/03/03 21:19:41 | 000,011,129 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\ModSettings.class
[2011/03/03 21:19:41 | 000,004,136 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\ModAction.class
[2011/03/03 21:19:41 | 000,003,352 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\SettingMulti.class
[2011/03/03 21:19:41 | 000,003,272 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\GuiWidgetScreen.class
[2011/03/03 21:19:41 | 000,003,037 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\SettingInt.class
[2011/03/03 21:19:41 | 000,002,909 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetText.class
[2011/03/03 21:19:41 | 000,002,888 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\SettingFloat.class
[2011/03/03 21:19:41 | 000,002,849 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\bq.class
[2011/03/03 21:19:41 | 000,002,674 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\SettingKey.class
[2011/03/03 21:19:41 | 000,002,619 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetFloat.class
[2011/03/03 21:19:41 | 000,002,573 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetInt.class
[2011/03/03 21:19:41 | 000,002,518 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetClassicWindow.class
[2011/03/03 21:19:41 | 000,002,484 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetKeybinding.class
[2011/03/03 21:19:41 | 000,002,363 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\GuiModScreen.class
[2011/03/03 21:19:41 | 000,002,311 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetBoolean.class
[2011/03/03 21:19:41 | 000,002,253 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\SettingBoolean.class
[2011/03/03 21:19:41 | 000,001,935 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetMulti.class
[2011/03/03 21:19:41 | 000,001,895 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\SettingText.class
[2011/03/03 21:19:41 | 000,001,894 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetClassicTwocolumn.class
[2011/03/03 21:19:41 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetSetting.class
[2011/03/03 21:19:41 | 000,001,650 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\ModSettingScreen.class
[2011/03/03 21:19:41 | 000,001,556 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\GuiModSelect.class
[2011/03/03 21:19:41 | 000,001,539 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\Subscreen.class
[2011/03/03 21:19:41 | 000,001,086 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\ModCallback.class
[2011/03/03 21:19:41 | 000,000,591 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\Setting.class
[2011/03/03 21:19:41 | 000,000,487 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\WidgetSlider.class
[2011/03/03 21:19:41 | 000,000,299 | ---- | C] () -- C:\Documents and Settings\Thunder\Application Data\ScreenScaleProxy.class
[2011/03/02 10:56:52 | 000,027,163 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\ICAO TOEFL paper.pdf
[2011/03/01 15:30:22 | 000,231,507 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\Tax Return full version.pdf
[2011/03/01 15:28:21 | 000,205,044 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\Tax returns 2010.pdf
[2011/03/01 14:11:18 | 000,140,935 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\W2 Fox & Roach 2010.pdf
[2011/03/01 12:53:12 | 000,000,639 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\Free Easy Burner.lnk
[2011/03/01 11:44:47 | 000,553,125 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\PFS_Online_Instruction_Workbook.pdf
[2011/02/28 12:32:19 | 006,154,847 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\1964 Tamatia Love- Sherman Offer.pdf
[2011/02/28 11:53:47 | 004,379,020 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\1964 1.pdf
[2011/02/28 10:53:51 | 000,000,529 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Scan2PDF.lnk
[2011/02/26 18:01:26 | 000,000,817 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Flight Instructor.lnk
[2011/02/26 18:01:26 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Install Fighter Ace 2.lnk
[2011/02/26 18:01:26 | 000,000,789 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Flight Simulator 2002.lnk
[2011/02/21 13:49:15 | 001,663,331 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\Rayan Wrestling Team.JPG
[2011/02/19 14:56:16 | 001,500,588 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\Globefish seafood highlights.pdf
[2011/02/19 14:50:35 | 000,834,240 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\Japan Tuna Report March 2004.pdf
[2011/02/19 13:41:24 | 000,116,724 | ---- | C] () -- C:\Documents and Settings\Thunder\My Documents\senegal_fishery_profile_apr08.pdf
[2011/02/17 18:30:00 | 015,624,192 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\viviane ndour_1er anniversaire_.mp3
[2011/02/17 18:29:28 | 027,666,155 | ---- | C] () -- C:\Documents and Settings\Thunder\Desktop\viviane ndour_1er anniversaire_.mp4
[2011/02/13 16:21:27 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-1409082233-725345543-1003.job
[2010/12/13 00:27:34 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/12/11 21:18:28 | 000,000,017 | ---- | C] () -- C:\WINDOWS\MovingPicture.ini
[2010/12/11 19:16:01 | 000,194,248 | ---- | C] () -- C:\WINDOWS\System32\LTRFD13n.DLL
[2010/12/11 19:14:28 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Thunder\Local Settings\Application Data\fusioncache.dat
[2010/12/11 18:57:39 | 000,001,208 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2010/12/11 18:57:38 | 000,196,096 | ---- | C] () -- C:\WINDOWS\System32\macd32.dll
[2010/12/11 18:57:38 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2010/12/11 18:57:38 | 000,136,192 | ---- | C] () -- C:\WINDOWS\System32\mamc32.dll
[2010/12/11 18:57:38 | 000,057,856 | ---- | C] () -- C:\WINDOWS\System32\masd32.dll
[2010/12/11 18:57:38 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2010/09/19 17:11:47 | 000,000,084 | ---- | C] () -- C:\WINDOWS\opt_2460.ini
[2010/09/19 17:11:47 | 000,000,050 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2010/09/19 17:08:54 | 000,002,652 | ---- | C] () -- C:\WINDOWS\BrmfBidi.ini
[2010/09/19 17:07:07 | 000,000,871 | ---- | C] () -- C:\WINDOWS\Brpcfx.ini
[2010/09/19 17:07:03 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2010/09/19 17:06:51 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\brfxdial.dll
[2010/09/19 12:07:09 | 000,000,038 | ---- | C] () -- C:\WINDOWS\BMUpdate.ini
[2010/09/05 15:10:59 | 000,000,261 | ---- | C] () -- C:\WINDOWS\SMSI.INI
[2010/09/05 15:10:38 | 000,000,410 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2010/09/05 15:10:38 | 000,000,173 | ---- | C] () -- C:\WINDOWS\brqikmon.ini
[2010/09/05 15:08:18 | 000,002,588 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/09/05 15:08:18 | 000,000,091 | ---- | C] () -- C:\WINDOWS\calera.ini
[2010/09/05 15:08:14 | 000,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
[2010/09/05 15:08:14 | 000,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
[2010/09/05 15:08:14 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
[2010/09/05 15:08:04 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
[2010/09/05 15:07:08 | 000,000,038 | ---- | C] () -- C:\WINDOWS\VISSETUP.INI
[2010/08/24 12:59:51 | 001,913,328 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/18 23:01:01 | 000,138,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/08/18 23:00:21 | 000,214,864 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010/08/18 22:58:21 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010/08/09 22:39:41 | 000,000,032 | ---- | C] () -- C:\WINDOWS\vb_mconf.ini
[2010/04/11 13:31:43 | 000,028,160 | ---- | C] () -- C:\Documents and Settings\Thunder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/31 17:37:48 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\brmsl01.bin
[2009/12/27 16:38:13 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\GIF89.DLL
[2009/12/27 16:38:10 | 000,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009/12/14 22:09:33 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/11/16 17:48:57 | 000,000,615 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2009/11/14 17:46:17 | 000,000,100 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2009/11/14 15:39:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2009/11/08 12:22:55 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT
[2009/11/08 12:12:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/10/25 09:40:13 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/06/28 21:02:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/06/28 15:32:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/06/28 15:26:03 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/06/28 11:09:14 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/28 11:08:08 | 000,325,112 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/05/01 16:11:28 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_0C.dll
[2007/05/01 16:11:28 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_10.dll
[2007/05/01 16:11:28 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_0A.dll
[2007/05/01 16:11:28 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_09.dll
[2007/05/01 16:11:28 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_11.dll
[2007/05/01 16:11:26 | 000,847,872 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255.Dll
[2007/05/01 16:11:26 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_07.dll
[2007/05/01 16:11:26 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\SaiC0255_0402.dll
[2007/05/01 15:34:56 | 002,011,136 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12.Dll
[2007/05/01 15:34:56 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_0C.dll
[2007/05/01 15:34:56 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_10.dll
[2007/05/01 15:34:56 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_0A.dll
[2007/05/01 15:34:56 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_07.dll
[2007/05/01 15:34:56 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_09.dll
[2007/05/01 15:34:56 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_0402.dll
[2007/05/01 15:34:56 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\SaiCFF12_11.dll
[2007/04/12 08:10:28 | 000,105,728 | ---- | C] () -- C:\WINDOWS\System32\APOMgrH.dll
[2007/04/09 12:55:14 | 000,097,785 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2007/04/09 12:55:14 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2007/04/09 12:33:50 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll
[2007/04/09 12:32:32 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\psconv.exe
[2007/04/09 12:24:30 | 000,325,821 | ---- | C] () -- C:\WINDOWS\System32\ctdlang.dat
[2007/04/09 12:24:30 | 000,046,273 | ---- | C] () -- C:\WINDOWS\System32\ctdnlstr.dat
[2007/04/09 12:21:44 | 000,048,128 | ---- | C] () -- C:\WINDOWS\System32\regplib.exe
[2007/04/09 12:21:28 | 000,149,838 | ---- | C] () -- C:\WINDOWS\System32\ctbas2w.dat
[2007/04/09 12:19:44 | 000,274,587 | ---- | C] () -- C:\WINDOWS\System32\ctsbas2w.dat
[2007/04/09 12:19:36 | 000,241,084 | ---- | C] () -- C:\WINDOWS\System32\CTSBASW.DAT
[2007/04/09 12:19:36 | 000,115,166 | ---- | C] () -- C:\WINDOWS\System32\CTBASICW.DAT
[2007/04/09 12:19:20 | 000,313,207 | ---- | C] () -- C:\WINDOWS\System32\ctstatic.dat
[2007/04/09 12:19:20 | 000,053,932 | ---- | C] () -- C:\WINDOWS\System32\ctdaught.dat
[2007/04/09 12:19:18 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\enlocstr.exe
[2007/03/16 17:00:00 | 000,003,403 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2006/12/05 14:05:04 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2006/10/02 09:25:18 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\kill.ini
[2005/07/29 14:38:24 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2005/07/22 22:30:18 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2005/06/16 10:17:16 | 000,071,680 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll
[2005/03/21 19:48:05 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/03/21 19:48:05 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/11/13 00:04:23 | 000,004,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\userport.sys
[2004/08/04 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 06:00:00 | 000,482,462 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 06:00:00 | 000,086,516 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 06:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 06:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/02 20:03:00 | 000,102,441 | ---- | C] () -- C:\WINDOWS\System32\getvpd.dll
[2004/08/02 20:03:00 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\getvpdc.exe
[2004/08/02 20:03:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\pmemw.dll
[2004/06/19 21:07:42 | 000,004,256 | ---- | C] () -- C:\WINDOWS\System32\userport.sys
[2004/03/11 01:26:10 | 000,406,016 | ---- | C] () -- C:\WINDOWS\System32\PSDrvCheck.exe
========== Custom Scans ==========
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008/04/13 20:12:16 | 000,015,360 | ---- | M] (Microsoft Corporation)
"BMUpdate" = C:\WINDOWS\system32\BMUpdate.exe -- [2001/07/03 14:12:36 | 000,176,128 | ---- | M] (EchoBahn.com)
========== Alternate Data Streams ==========
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CFF5F08
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B9AB561D
< End of report >