OTL Extras logfile created on: 6/9/2009 2:02:14 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Kelly chen\Local Settings\Temporary Internet Files\Content.IE5\DTSLYD8J
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.23 Mb Total Physical Memory | 458.25 Mb Available Physical Memory | 45.14% Memory free
2.38 Gb Paging File | 1.94 Gb Available in Paging File | 81.36% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 66.57 Gb Free Space | 89.33% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC183754137168
Current User Name: Kelly chen
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0517F875-BBB2-4812-A63E-733B33CEF215}" = Roxio Instant Restore
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{275E7C8F-5407-4E2D-9506-0DC5BC59B14E}" = MigoMobile DESKTOP 4
"{2B682751-E749-441C-A4B3-1F538E26E56E}" = Roxio Instant Restore Recovery Disk
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32F9BACF-FCD3-4B6A-AD85-255A449B6FA5}" = Roxio BackOnTrack
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4F2AF17E-94F0-4F22-943D-216CE46AC502}" = HP Mobile Broadband Setup Utility
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{69DAC00A-7665-4E9B-B441-093D40736429}" = HP BatteryCheck 2.10 A2
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{87A83C6F-F53C-448A-B078-FF00E3EAEB29}" = Roxio Disaster Recovery
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{909B62B0-8ACA-4061-A83B-09CAEF609619}" = MSXML 6.0 Parser
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B5B25043-42A0-4490-A425-C7A6284213E6}" = HP User Guides 0130
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"553D07C7937AEF19AECBF1E27F5709BCDA84B2C7" = Windows Driver Package - SMSC LAN9500 USB 2.0 to Ethernet 10/100 Adapter x86 Driver (05/12/2008 1.52.0000.0000)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AIM_6" = AIM 6
"AOL Toolbar" = AOL Toolbar 5.0
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NIS" = Norton Internet Security
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ System Events ]
Error - 6/2/2009 9:41:25 AM | Computer Name = PC183754137168 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 6/4/2009 11:22:33 AM | Computer Name = PC183754137168 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.143 on
the Network Card with network address 00242B7F8DCF.
Error - 6/4/2009 11:27:51 AM | Computer Name = PC183754137168 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the crd service to connect.
Error - 6/4/2009 11:27:51 AM | Computer Name = PC183754137168 | Source = Service Control Manager | ID = 7000
Description = The crd service failed to start due to the following error: %%1053
Error - 6/4/2009 10:21:00 PM | Computer Name = PC183754137168 | Source = PlugPlayManager | ID = 12
Description = The device 'Marvell Yukon 88E8040 PCI-E Fast Ethernet Controller'
(PCI\VEN_11AB&DEV_4354&SUBSYS_361A103C&REV_00\4&23c6fc68&0&00E1) disappeared from
the system without first being prepared for removal.
Error - 6/5/2009 7:04:37 PM | Computer Name = PC183754137168 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.104 for the Network Card with network
address 00248140A083 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 6/9/2009 1:30:24 AM | Computer Name = PC183754137168 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.33 for the Network Card with network
address 00248140A083 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
< End of report >
OTL logfile created on: 6/9/2009 2:02:14 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Kelly chen\Local Settings\Temporary Internet Files\Content.IE5\DTSLYD8J
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.23 Mb Total Physical Memory | 458.25 Mb Available Physical Memory | 45.14% Memory free
2.38 Gb Paging File | 1.94 Gb Available in Paging File | 81.36% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 66.57 Gb Free Space | 89.33% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC183754137168
Current User Name: Kelly chen
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Roxio\BackOnTrack\Instant Restore\BOTService.exe (Sonic Solutions)
PRC - c:\program files\idt\wdm\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe ()
PRC - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\WINDOWS\system32\AESTFltr.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - c:\program files\aol\aol toolbar 5.0\AolTbServer.exe (AOL LLC)
PRC - C:\Documents and Settings\Kelly chen\Local Settings\Temporary Internet Files\Content.IE5\DTSLYD8J\OTL[2].exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269 [Auto | Running]) – C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (BOTService [Auto | Running]) – C:\Program Files\Roxio\BackOnTrack\Instant Restore\BOTService.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmiex [On_Demand | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Norton Internet Security [Auto | Running]) – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (STacSV [Auto | Running]) – c:\program files\idt\wdm\stacsv.exe (IDT, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (spupdsvc [Auto | Stopped]) – C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (AESTAud [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AESTAud.sys (Andrea Electronics Corporation)
DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BHDrvx86 [System | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\BHDrvx86.sys (Symantec Corporation)
DRV - (ccHP [System | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\ccHPx86.sys (Symantec Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (IDSxpx86 [System | Running]) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090604.001\IDSxpx86.sys (Symantec Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NAVENG [On_Demand | Running]) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090608.033\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090608.033\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (SahdIa32 [Boot | Running]) – C:\WINDOWS\System32\Drivers\SahdIa32.sys (Sonic Solutions)
DRV - (SaibIa32 [Boot | Running]) – C:\WINDOWS\System32\Drivers\SaibIa32.sys (Sonic Solutions)
DRV - (SaibVd32 [System | Running]) – C:\WINDOWS\System32\Drivers\SaibVd32.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (SRTSP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEFA [Boot | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMIDS.SYS (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMTDI.SYS (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (SysCow [Boot | Running]) – C:\WINDOWS\system32\drivers\syscow32x.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (yukonwxp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\yk51x86.sys (Marvell)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {7BA52691-1876-45ce-9EE6-54BCB3B04BBC}:3.0
FF - prefs.js..extensions.enabledItems: {8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/05 12:56:09 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/05 12:54:48 | 00,000,000 | —D | M]
[2009/06/05 13:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\mozilla\Extensions
[2009/06/05 13:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/05 13:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\mozilla\Firefox\Profiles\8h0gatt6.default\extensions
[2009/06/09 13:26:26 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/06/05 12:54:49 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/24 12:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 12:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/24 08:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 08:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 08:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 08:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 08:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 08:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 08:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg (Andrea Electronics Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Mobile Broadband] c:\SWsetup\HPQWWAN\HPMobileBroadband.exe /TrayMode (Hewlett-Packard Company)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IDTSysTrayApp] sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC ()
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-MY\local\search.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/06 07:14:36 | 00,000,000 | —D | M]
========== Files/Folders - Created Within 30 Days ==========
[36 C:\WINDOWS\System32\*.tmp files]
[2009/06/09 13:51:28 | 00,000,000 | —D | C] – C:\Rooter$
[2009/06/09 13:46:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\Malwarebytes
[2009/06/09 13:46:07 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/09 13:46:02 | 00,040,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/09 13:45:55 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/09 13:45:54 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/09 13:45:53 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/09 13:37:16 | 00,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2009/06/09 13:36:42 | 00,000,150 | —- | C] () – C:\WINDOWS\System32\spupdsvc.inf
[2009/06/09 13:27:58 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/06/07 23:51:31 | 00,268,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2009/06/07 23:51:31 | 00,208,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\muweb.dll
[2009/06/07 23:51:31 | 00,027,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2009/06/06 07:14:36 | 00,001,734 | —- | C] () – C:\Documents and Settings\Kelly chen\Desktop\HijackThis.lnk
[2009/06/06 07:14:34 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/05 18:16:10 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/06/05 14:00:14 | 00,138,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\afd.sys
[2009/06/05 14:00:14 | 00,138,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\afd.sys
[2009/06/05 13:57:41 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/06/05 13:57:40 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/06/05 13:57:40 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sc.exe
[2009/06/05 13:57:40 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/06/05 13:57:39 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/06/05 13:57:39 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/06/05 13:57:39 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\services.exe
[2009/06/05 13:57:39 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/06/05 13:57:38 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/06/05 13:57:37 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\lsasrv.dll
[2009/06/05 13:57:37 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/06/05 13:57:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ntdll.dll
[2009/06/05 13:57:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/06/05 13:57:37 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/06/05 13:57:37 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\advapi32.dll
[2009/06/05 13:57:35 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ntoskrnl.exe
[2009/06/05 13:57:35 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2009/06/05 13:57:33 | 02,189,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2009/06/05 13:57:32 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ntkrnlpa.exe
[2009/06/05 13:57:32 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2009/06/05 13:50:01 | 00,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2009/06/05 13:46:02 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/06/05 13:46:01 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/06/05 13:46:00 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/06/05 13:44:59 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthport.sys
[2009/06/05 13:44:59 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/06/05 13:40:16 | 00,765,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2009/06/05 13:27:37 | 00,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rmcast.sys
[2009/06/05 13:27:37 | 00,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2009/06/05 13:27:04 | 00,455,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mrxsmb.sys
[2009/06/05 13:27:04 | 00,455,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2009/06/05 13:25:08 | 00,333,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\srv.sys
[2009/06/05 13:25:08 | 00,333,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2009/06/05 13:24:00 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/06/05 13:21:25 | 00,691,712 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcomm.dll
[2009/06/05 13:15:22 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/06/05 13:14:54 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/06/05 13:14:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live
[2009/06/05 13:07:05 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\Mozilla
[2009/06/05 13:04:18 | 00,247,326 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\strmdll.dll
[2009/06/05 13:04:18 | 00,247,326 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\strmdll.dll
[2009/06/05 13:01:40 | 00,000,591 | —- | C] () – C:\Documents and Settings\Kelly chen\Desktop\Shortcut to KMPlayer.lnk
[2009/06/05 13:01:22 | 00,000,000 | —D | C] – C:\Program Files\KMP
[2009/06/05 12:56:43 | 01,106,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2009/06/05 12:56:12 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/06/05 12:55:01 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/06/05 12:54:40 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/06/05 12:51:47 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/06/05 00:13:07 | 00,000,000 | R–D | C] – C:\Documents and Settings\Kelly chen\My Documents\My Videos
[2009/06/05 00:13:07 | 00,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2009/06/05 00:12:57 | 00,000,782 | —- | C] () – C:\Documents and Settings\Kelly chen\Desktop\Windows Media Player.lnk
[2009/06/05 00:12:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/06/05 00:11:12 | 00,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBSTOR.SYS
[2009/06/04 23:23:23 | 00,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2009/06/02 22:07:38 | 00,202,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuweb.dll
[2009/06/02 22:07:35 | 00,323,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2009/06/02 22:07:34 | 01,809,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaueng.dll
[2009/06/02 22:07:34 | 00,213,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaucpl.cpl
[2009/06/02 22:07:33 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuauclt.exe
[2009/06/02 22:07:32 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2009/06/02 22:07:31 | 00,092,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cdm.dll
[2009/05/30 22:44:30 | 00,000,205 | —- | C] () – C:\Documents and Settings\Kelly chen\Desktop\HP Battery Check.lnk
[2009/05/30 21:05:12 | 00,035,888 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2009/05/30 21:05:03 | 00,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2009/05/30 21:05:02 | 00,124,464 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/05/30 21:05:02 | 00,010,635 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/05/30 21:05:02 | 00,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/05/30 21:05:01 | 00,000,000 | —D | C] – C:\Program Files\Symantec
[2009/05/30 21:05:01 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2009/05/30 01:09:26 | 00,000,062 | -HS- | C] () – C:\Documents and Settings\Kelly chen\Application Data\desktop.ini
[2009/05/30 01:09:25 | 00,000,081 | -HS- | C] () – C:\Documents and Settings\Kelly chen\My Documents\desktop.ini
[2009/05/30 01:09:25 | 00,000,062 | -HS- | C] () – C:\Documents and Settings\Kelly chen\Local Settings\desktop.ini
[2009/05/30 01:09:24 | 00,000,084 | -HS- | C] () – C:\Documents and Settings\Kelly chen\Start Menu\Programs\Startup\desktop.ini
[2009/05/30 01:09:24 | 00,000,000 | –SD | C] – C:\Documents and Settings\Kelly chen\Application Data\Microsoft
[2009/05/30 01:09:24 | 00,000,000 | R–D | C] – C:\Documents and Settings\Kelly chen\My Documents\My Pictures
[2009/05/30 01:09:24 | 00,000,000 | R–D | C] – C:\Documents and Settings\Kelly chen\My Documents\My Music
[2009/05/30 01:09:24 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Kelly chen\Local Settings\Temporary Internet Files
[2009/05/30 01:09:24 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Kelly chen\Local Settings\History
[2009/05/30 01:09:24 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Kelly chen\Local Settings\Application Data
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Local Settings\Temp
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\TMP
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\Sun
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\MigoMobile
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\Macromedia
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\InstallShield
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\Identities
[2009/05/30 01:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kelly chen\Application Data\Adobe
[2009/05/29 10:21:54 | 00,221,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmpns.dll
[2009/05/29 10:20:49 | 03,170,304 | RHS- | C] () – C:\Boot.sdi
[2009/05/29 10:20:49 | 00,333,203 | RHS- | C] () – C:\bootmgr
[2009/05/29 10:20:49 | 00,259,584 | RHS- | C] (Microsoft Corporation) – C:\BCDEDIT.EXE
[2009/05/29 10:20:49 | 00,259,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bcdedit.exe
[2009/05/29 10:20:49 | 00,102,400 | RHS- | C] (Microsoft Corporation) – C:\bootsect.exe
[2009/05/29 10:20:10 | 18,356,0527 | RHS- | C] () – C:\BootENU.wim
[2009/05/29 10:20:10 | 00,000,000 | -HSD | C] – C:\Boot
[2009/05/29 10:20:05 | 00,000,282 | —- | C] () – C:\WINDOWS\tasks\BackOnTrack Instant Restore Idle.job
[2009/05/29 10:19:51 | 00,111,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\BootSect.exe
[2009/05/29 10:19:43 | 00,001,931 | —- | C] () – C:\Documents and Settings\All Users\Desktop\eBay.com.my.lnk
[2009/05/29 10:19:41 | 00,001,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My HP Games.lnk
[2009/05/29 10:19:10 | 00,873,134 | —- | C] () – C:\WINDOWS\System32\oem1.inf
[2009/05/29 10:14:28 | 00,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2009/05/29 10:11:27 | 00,571,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TINTLGNT.IME
[2009/05/29 10:11:27 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CINTLGNT.IME
[2009/05/29 10:11:26 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winar30.ime
[2009/05/29 10:11:26 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\phon.ime
[2009/05/29 10:11:26 | 00,078,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dayi.ime
[2009/05/29 10:11:26 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\chajei.ime
[2009/05/29 10:11:26 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\quick.ime
[2009/05/29 10:11:26 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\uniime.dll
[2009/05/29 10:11:26 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winime.ime
[2009/05/29 10:11:26 | 00,065,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\unicdime.ime
[2009/05/29 10:11:26 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\romanime.ime
[2009/05/29 10:11:26 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\miniime.tpl
[2009/05/29 10:11:24 | 00,482,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\PINTLGNT.IME
[2009/05/29 10:11:23 | 00,218,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\c_g18030.dll
[2009/05/29 10:11:23 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINZM.IME
[2009/05/29 10:11:23 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINSP.IME
[2009/05/29 10:11:23 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINPY.IME
[2009/05/29 10:11:23 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\imekr61.ime
[2009/05/29 10:11:23 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGB.IME
[2009/05/29 10:11:23 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdibm02.dll
[2009/05/29 10:11:23 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\f3ahvoas.dll
[2009/05/29 10:11:23 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdlk41a.dll
[2009/05/29 10:11:23 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdlk41j.dll
[2009/05/29 10:11:23 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd106n.dll
[2009/05/29 10:11:22 | 00,811,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\imjp81k.dll
[2009/05/29 10:11:22 | 00,340,023 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\imjp81.ime
[2009/05/29 10:11:22 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdax2.dll
[2009/05/29 10:11:22 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd101.dll
[2009/05/29 10:11:20 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Thawbrkr.dll
[2009/05/29 10:11:20 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\c_864.nls
[2009/05/29 10:11:20 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\c_720.nls
[2009/05/29 10:11:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\c_708.nls
[2009/05/29 10:11:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\C_28596.NLS
[2009/05/29 10:11:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\c_10004.nls
[2009/05/29 10:11:20 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\c_iscii.dll
[2009/05/29 10:11:20 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdusa.dll
[2009/05/29 10:11:19 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\c_862.nls
[2009/05/29 10:11:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\c_10005.nls
[2009/05/29 10:11:18 | 01,875,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msir3jp.lex
[2009/05/29 10:11:18 | 01,677,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\chsbrkr.dll
[2009/05/29 10:11:18 | 01,158,818 | —- | C] () – C:\WINDOWS\System32\korwbrkr.lex
[2009/05/29 10:11:18 | 00,838,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\chtbrkr.dll
[2009/05/29 10:11:18 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msir3jp.dll
[2009/05/29 10:11:18 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\korwbrkr.dll
[2009/05/29 10:11:18 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\c_10021.nls
[2009/05/29 10:11:18 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ftlx041e.dll
[2009/05/29 10:11:18 | 00,002,060 | —- | C] () – C:\WINDOWS\System32\noise.jpn
[2009/05/29 10:11:18 | 00,001,486 | —- | C] () – C:\WINDOWS\System32\noise.kor
[2009/05/29 10:11:14 | 00,211,938 | —- | C] () – C:\WINDOWS\System32\lcphrase.tbl
[2009/05/29 10:11:14 | 00,195,618 | —- | C] () – C:\WINDOWS\System32\c_10002.nls
[2009/05/29 10:11:14 | 00,146,126 | —- | C] () – C:\WINDOWS\System32\array30.tab
[2009/05/29 10:11:14 | 00,116,285 | —- | C] () – C:\WINDOWS\System32\msdayi.tbl
[2009/05/29 10:11:14 | 00,110,566 | —- | C] () – C:\WINDOWS\System32\arphr.tbl
[2009/05/29 10:11:14 | 00,082,172 | —- | C] () – C:\WINDOWS\System32\bopomofo.nls
[2009/05/29 10:11:14 | 00,066,728 | —- | C] () – C:\WINDOWS\System32\big5.nls
[2009/05/29 10:11:14 | 00,044,370 | —- | C] () – C:\WINDOWS\System32\acode.tbl
[2009/05/29 10:11:14 | 00,044,370 | —- | C] () – C:\WINDOWS\System32\a234.tbl
[2009/05/29 10:11:14 | 00,043,242 | —- | C] () – C:\WINDOWS\System32\phoncode.tbl
[2009/05/29 10:11:14 | 00,024,114 | —- | C] () – C:\WINDOWS\System32\lcptr.tbl
[2009/05/29 10:11:14 | 00,018,600 | —- | C] () – C:\WINDOWS\System32\arrayhw.tab
[2009/05/29 10:11:14 | 00,016,312 | —- | C] () – C:\WINDOWS\System32\arptr.tbl
[2009/05/29 10:11:14 | 00,016,254 | —- | C] () – C:\WINDOWS\System32\PINTLPAE.HLP
[2009/05/29 10:11:14 | 00,014,821 | —- | C] () – C:\WINDOWS\System32\PINTLPAD.HLP
[2009/05/29 10:11:14 | 00,004,071 | —- | C] () – C:\WINDOWS\System32\phon.tbl
[2009/05/29 10:11:14 | 00,002,714 | —- | C] () – C:\WINDOWS\System32\phonptr.tbl
[2009/05/29 10:11:14 | 00,001,460 | —- | C] () – C:\WINDOWS\System32\a15.tbl
[2009/05/29 10:11:14 | 00,000,700 | —- | C] () – C:\WINDOWS\System32\dayiptr.tbl
[2009/05/29 10:11:14 | 00,000,520 | —- | C] () – C:\WINDOWS\System32\dayiphr.tbl
[2009/05/29 10:11:11 | 01,783,864 | —- | C] () – C:\WINDOWS\System32\WINPY.MB
[2009/05/29 10:11:11 | 01,564,868 | —- | C] () – C:\WINDOWS\System32\WINSP.MB
[2009/05/29 10:11:11 | 01,223,500 | —- | C] () – C:\WINDOWS\System32\WINZM.MB
[2009/05/29 10:11:11 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\c_10008.nls
[2009/05/29 10:11:11 | 00,083,748 | —- | C] () – C:\WINDOWS\System32\prcp.nls
[2009/05/29 10:11:11 | 00,083,748 | —- | C] () – C:\WINDOWS\System32\prc.nls
[2009/05/29 10:11:11 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd101a.dll
[2009/05/29 10:11:06 | 00,189,986 | —- | C] () – C:\WINDOWS\System32\c_1361.nls
[2009/05/29 10:11:06 | 00,177,698 | —- | C] () – C:\WINDOWS\System32\c_10003.nls
[2009/05/29 10:11:06 | 00,047,066 | —- | C] () – C:\WINDOWS\System32\ksc.nls
[2009/05/29 10:11:06 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnecAT.dll
[2009/05/29 10:11:06 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnecNT.dll
[2009/05/29 10:11:06 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnec95.dll
[2009/05/29 10:10:58 | 00,180,770 | —- | C] () – C:\WINDOWS\System32\c_20932.nls
[2009/05/29 10:10:58 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\c_20000.nls
[2009/05/29 10:10:58 | 00,177,698 | —- | C] () – C:\WINDOWS\System32\c_20949.nls
[2009/05/29 10:10:58 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\c_20936.nls
[2009/05/29 10:10:58 | 00,162,850 | —- | C] () – C:\WINDOWS\System32\c_10001.nls
[2009/05/29 10:10:58 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\c_21027.nls
[2009/05/29 10:10:58 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\c_20290.nls
[2009/05/29 10:10:58 | 00,028,288 | —- | C] () – C:\WINDOWS\System32\xjis.nls
[2009/05/29 10:10:58 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\c_is2022.dll
[2009/05/29 10:10:55 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdjpn.dll
[2009/05/29 10:10:55 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdkor.dll
[2009/05/29 10:10:55 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd106.dll
[2009/05/29 10:10:55 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd101c.dll
[2009/05/29 10:10:55 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd103.dll
[2009/05/29 10:10:51 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd101b.dll
[2009/05/29 10:08:38 | 10,646,20032 | -HS- | C] () – C:\hiberfil.sys
[2009/02/01 02:54:32 | 00,028,510 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/02/01 02:30:39 | 00,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2008/06/25 01:48:20 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/06/25 01:25:40 | 00,000,507 | —- | C] () – C:\WINDOWS\win.ini
[2008/06/24 18:06:38 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[36 C:\WINDOWS\System32\*.tmp files]
[2009/06/09 13:46:07 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/09 13:42:19 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/06/09 13:36:42 | 00,000,150 | —- | M] () – C:\WINDOWS\System32\spupdsvc.inf
[2009/06/09 13:30:58 | 00,401,632 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/06/09 13:30:58 | 00,062,746 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/06/09 13:30:57 | 00,471,150 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/09 13:27:03 | 00,000,282 | —- | M] () – C:\WINDOWS\tasks\BackOnTrack Instant Restore Idle.job
[2009/06/09 13:26:53 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Kelly chen\Local Settings\desktop.ini
[2009/06/09 13:26:21 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/09 13:26:18 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/06/09 13:26:13 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/06/09 13:26:09 | 10,646,20032 | -HS- | M] () – C:\hiberfil.sys
[2009/06/06 07:14:36 | 00,001,734 | —- | M] () – C:\Documents and Settings\Kelly chen\Desktop\HijackThis.lnk
[2009/06/05 19:18:39 | 00,231,184 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/05 13:01:40 | 00,000,591 | —- | M] () – C:\Documents and Settings\Kelly chen\Desktop\Shortcut to KMPlayer.lnk
[2009/06/05 12:56:12 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/06/05 12:55:01 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/06/05 00:12:58 | 00,000,782 | —- | M] () – C:\Documents and Settings\Kelly chen\Desktop\Windows Media Player.lnk
[2009/05/30 22:44:30 | 00,000,205 | —- | M] () – C:\Documents and Settings\Kelly chen\Desktop\HP Battery Check.lnk
[2009/05/30 21:05:02 | 00,124,464 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/05/30 21:05:02 | 00,010,635 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/05/30 21:05:02 | 00,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/05/30 21:05:01 | 00,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2009/05/30 21:04:57 | 00,001,984 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
[2009/05/30 01:10:00 | 00,000,081 | -HS- | M] () – C:\Documents and Settings\Kelly chen\My Documents\desktop.ini
[2009/05/29 10:20:49 | 18,356,0527 | RHS- | M] () – C:\BootENU.wim
[2009/05/29 10:20:49 | 03,170,304 | RHS- | M] () – C:\Boot.sdi
[2009/05/29 10:20:49 | 00,333,203 | RHS- | M] () – C:\bootmgr
[2009/05/29 10:20:49 | 00,259,584 | RHS- | M] (Microsoft Corporation) – C:\BCDEDIT.EXE
[2009/05/29 10:20:49 | 00,259,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\bcdedit.exe
[2009/05/29 10:20:49 | 00,102,400 | RHS- | M] (Microsoft Corporation) – C:\bootsect.exe
[2009/05/29 10:19:41 | 00,001,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My HP Games.lnk
[2009/05/29 10:17:05 | 00,038,471 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2009/05/29 10:16:56 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/05/29 10:13:57 | 00,005,208 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2009/05/29 10:11:30 | 00,000,231 | —- | M] () – C:\WINDOWS\system.ini
[2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
========== LOP Check ==========
[2009/06/09 13:45:55 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/01 02:50:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/02/01 02:55:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/02/01 02:45:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/06/09 13:45:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/05 13:15:03 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/05/30 21:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Norton
[2009/02/01 02:12:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/02/01 02:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2009/02/01 02:47:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2009/02/01 02:51:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/06/05 00:12:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/06/09 13:46:14 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Kelly chen\Application Data
[2009/02/01 02:50:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\Adobe
[2009/02/01 17:58:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\Identities
[2009/02/01 02:43:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\InstallShield
[2009/02/01 02:50:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\Macromedia
[2009/06/09 13:46:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\Malwarebytes
[2009/06/05 18:40:34 | 00,000,000 | –SD | M] – C:\Documents and Settings\Kelly chen\Application Data\Microsoft
[2009/02/01 02:56:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\MigoMobile
[2009/06/05 13:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\Mozilla
[2009/02/01 02:47:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\Sun
[2009/02/01 02:32:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Kelly chen\Application Data\TMP
[2009/06/09 13:27:03 | 00,000,282 | —- | M] () – C:\WINDOWS\Tasks\BackOnTrack Instant Restore Idle.job
[2008/04/15 12:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/06/09 13:26:21 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >