i did everything that i did before but this time only 1 notepad came up….not 2
I feel like a dunce…..i copied what the notepad came up with but feel bad….feel like i'm wasting your time…..
I"M SORRY
OTL logfile created on: 12/12/2009 1:52:01 PM - Run 2
OTL by OldTimer - Version 3.1.16.0 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.71 Mb Total Physical Memory | 290.38 Mb Available Physical Memory | 28.65% Memory free
2.38 Gb Paging File | 1.90 Gb Available in Paging File | 79.61% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.07 Gb Total Space | 123.15 Gb Free Space | 67.64% Space Free | Partition Type: NTFS
Drive D: | 4.23 Gb Total Space | 1.64 Gb Free Space | 38.80% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BEGOOD
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\zHotkey.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (RoxLiveShare10) – File not found
SRV - (KodakCCS) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (PdiPorts) – C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (SunkFilt39) – C:\WINDOWS\system32\drivers\Sunkfilt39.sys (Alcor Micro Corp.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (OVT511Plus) – C:\WINDOWS\system32\drivers\omcamvid.sys (OmniVision Technologies, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.comcast.net/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/12/12 09:12:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2009/11/06 20:03:17 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/11/20 22:01:16 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/07 20:16:50 | 00,000,000 | —D | M]
[2008/05/26 18:54:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/12/11 17:52:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\aq2708vv.default\extensions
[2008/08/05 20:16:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\aq2708vv.default\extensions\[removed]
[2008/07/20 14:13:25 | 00,002,207 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\aq2708vv.default\searchplugins\askcom.xml
[2009/12/12 09:51:36 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/09/15 11:52:06 | 00,376,832 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
O1 HOSTS File: (319159 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10946 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKCU..\RunOnce: [] C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF 03 [binary data]
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Reg Error: Value error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1260244265359 (MUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 13:04:39 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 00,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O33 - MountPoints2\{2a05193c-3daf-11dd-98d3-0011118e81ba}\Shell - "" = AutoRun
O33 - MountPoints2\{2a05193c-3daf-11dd-98d3-0011118e81ba}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2a05193c-3daf-11dd-98d3-0011118e81ba}\Shell\AutoRun\command - "" = K:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/26 13:03:54 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891947461378048)
========== Files/Folders - Created Within 30 Days ==========
[2009/12/10 18:12:03 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Tracing
[2009/12/10 18:05:05 | 00,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2009/12/07 21:25:39 | 00,062,009 | —- | C] (Portrait Displays, Inc.) – C:\WINDOWS\System32\wpfb_ialmrnt5.dll
[2009/12/07 21:25:17 | 00,062,009 | —- | C] (Portrait Displays, Inc.) – C:\WINDOWS\System32\WPFB.DLL
[2009/12/07 21:25:17 | 00,017,465 | —- | C] (Portrait Displays, Inc.) – C:\WINDOWS\System32\drivers\pivot.sys
[2009/12/07 21:25:17 | 00,011,323 | —- | C] (Portrait Displays, Inc.) – C:\WINDOWS\System32\drivers\pivotmou.sys
[2009/12/07 21:24:23 | 00,017,136 | —- | C] (Portrait Displays, Inc.) – C:\WINDOWS\System32\drivers\PdiPorts.sys
[2009/12/07 21:23:48 | 01,392,671 | —- | C] (Microsoft Corporation) – C:\WINDOWS\msvbvm60.dll
[2009/12/07 21:23:48 | 01,093,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\mfc80u.dll
[2009/12/07 21:23:48 | 00,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\mfc70.dll
[2009/12/07 21:23:48 | 00,487,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\msvcp70.dll
[2009/12/07 21:23:48 | 00,344,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\msvcr70.dll
[2009/12/07 21:23:48 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\mfcm80.dll
[2009/12/07 21:23:48 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\mfcm80u.dll
[2009/12/07 21:23:47 | 01,101,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\mfc80.dll
[2009/12/07 21:23:47 | 00,626,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\msvcr80.dll
[2009/12/07 21:23:47 | 00,548,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\msvcp80.dll
[2009/12/07 21:23:47 | 00,479,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\msvcm80.dll
[2009/12/07 21:23:47 | 00,372,736 | —- | C] (Intel Corporation) – C:\WINDOWS\ijl15.dll
[2009/12/07 21:23:47 | 00,096,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\atl80.dll
[2009/12/07 21:11:25 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2009/12/07 21:11:09 | 00,014,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2009/12/07 20:26:04 | 00,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2009/12/07 20:26:01 | 00,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2009/12/07 20:18:56 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2009/12/07 20:18:44 | 00,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2009/12/07 20:18:39 | 00,000,000 | —D | C] – C:\Program Files\JRE
[2009/12/07 20:15:56 | 00,000,000 | —D | C] – C:\Program Files\ESET
[2009/12/04 19:13:28 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/12/04 19:13:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/12/04 19:13:21 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/11/28 18:06:01 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\AskToolbar
[2009/11/28 17:55:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\DisplayTune
[2009/11/28 17:51:30 | 00,000,000 | —D | C] – C:\Program Files\Portrait Displays
[2009/11/28 17:50:45 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Portrait Displays
[2009/11/28 17:50:45 | 00,000,000 | —D | C] – C:\Program Files\Acer Display
[2009/11/28 17:31:40 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\hidserv(2).dll
[2009/11/24 20:48:04 | 00,000,000 | —D | C] – C:\Program Files\FrostWire
[2009/11/24 20:46:53 | 00,000,000 | —D | C] – C:\Program Files\Ask.com
[2009/11/13 23:01:52 | 00,093,360 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2009/11/13 22:58:16 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2009/11/06 19:57:13 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/11/06 19:57:12 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/11/06 19:57:12 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/07/18 18:05:11 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/05/28 17:52:34 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/06/29 20:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Roxio
[42 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009/12/12 13:50:32 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/12/12 13:48:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/12/12 13:48:25 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/12/12 13:48:24 | 10,630,30784 | -HS- | M] () – C:\hiberfil.sys
[2009/12/12 13:46:44 | 06,553,600 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2009/12/12 13:46:44 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2009/12/12 13:46:19 | 00,000,020 | —- | M] () – C:\Documents and Settings\Owner\defogger_reenable
[2009/12/12 13:01:00 | 00,000,238 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2009/12/12 09:11:08 | 46,542,550 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/12/11 23:16:23 | 00,002,841 | —- | M] () – C:\Documents and Settings\Owner\Desktop\flax.rtf
[2009/12/11 18:33:57 | 00,123,577 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/12/11 18:13:00 | 00,292,864 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2009/12/10 18:16:46 | 00,070,430 | —- | M] () – C:\Documents and Settings\Owner\Desktop\system.zip
[2009/12/10 18:16:01 | 01,426,468 | —- | M] () – C:\Documents and Settings\Owner\Desktop\system.nfo
[2009/12/10 18:14:50 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/10 18:09:28 | 00,219,755 | —- | M] () – C:\Documents and Settings\Owner\Desktop\UPDATES1.JPG
[2009/12/10 07:45:52 | 04,428,008 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/12/09 06:32:33 | 00,564,392 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/09 06:32:33 | 00,471,092 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/09 06:32:33 | 00,083,554 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/09 03:03:41 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/12/07 22:40:52 | 00,000,054 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2009/12/07 22:40:52 | 00,000,039 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2009/12/07 22:03:28 | 00,062,009 | —- | M] (Portrait Displays, Inc.) – C:\WINDOWS\System32\wpfb_ialmrnt5.dll
[2009/12/07 21:12:52 | 00,000,913 | —- | M] () – C:\Documents and Settings\Owner\Desktop\chuckie.rtf
[2009/12/07 21:02:27 | 00,000,507 | —- | M] () – C:\WINDOWS\win.ini
[2009/12/07 21:02:27 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/07 21:02:27 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/12/05 19:05:03 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/12/04 20:08:21 | 00,000,000 | —- | M] () – C:\Documents and Settings\Owner\settings.dat
[2009/12/04 17:34:00 | 00,000,436 | —- | M] () – C:\WINDOWS\tasks\EasyShare Registration Task.job
[2009/12/02 17:39:03 | 00,002,365 | —- | M] () – C:\Documents and Settings\Owner\Desktop\christmas.rtf
[2009/12/01 18:04:27 | 00,115,768 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/11/25 18:35:25 | 00,000,833 | —- | M] () – C:\Documents and Settings\Owner\My Documents\chuckie.rtf
[2009/11/22 21:28:46 | 02,278,400 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/11/22 21:28:00 | 04,604,928 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/11/21 10:51:42 | 01,206,508 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/11/21 10:51:04 | 00,471,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2009/11/20 21:39:53 | 00,001,070 | —- | M] () – C:\Documents and Settings\Owner\Desktop\The Beatles.rtf
[2009/11/13 23:01:40 | 00,093,360 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2009/11/13 23:01:33 | 00,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/11/13 22:58:11 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[42 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009/12/12 13:46:09 | 00,000,020 | —- | C] () – C:\Documents and Settings\Owner\defogger_reenable
[2009/12/12 11:41:18 | 00,292,864 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2009/12/10 18:16:46 | 00,070,430 | —- | C] () – C:\Documents and Settings\Owner\Desktop\system.zip
[2009/12/10 18:14:48 | 01,426,468 | —- | C] () – C:\Documents and Settings\Owner\Desktop\system.nfo
[2009/12/10 18:09:28 | 00,219,755 | —- | C] () – C:\Documents and Settings\Owner\Desktop\UPDATES1.JPG
[2009/12/09 03:02:42 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/12/07 22:30:07 | 10,630,30784 | -HS- | C] () – C:\hiberfil.sys
[2009/12/07 21:25:19 | 00,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2009/12/07 21:23:47 | 00,002,371 | —- | C] () – C:\WINDOWS\Microsoft.VC80.MFC.manifest
[2009/12/07 21:23:47 | 00,001,869 | —- | C] () – C:\WINDOWS\Microsoft.VC80.CRT.manifest
[2009/12/07 21:23:47 | 00,000,456 | —- | C] () – C:\WINDOWS\Microsoft.VC80.ATL.manifest
[2009/12/04 20:08:21 | 00,000,000 | —- | C] () – C:\Documents and Settings\Owner\settings.dat
[2009/11/25 18:36:23 | 00,000,913 | —- | C] () – C:\Documents and Settings\Owner\Desktop\chuckie.rtf
[2009/11/25 18:35:25 | 00,000,833 | —- | C] () – C:\Documents and Settings\Owner\My Documents\chuckie.rtf
[2009/11/24 20:46:58 | 00,000,238 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2009/11/19 19:24:08 | 00,002,841 | —- | C] () – C:\Documents and Settings\Owner\Desktop\flax.rtf
[2009/11/13 22:58:11 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/06/16 20:31:10 | 00,007,680 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\clear.log
[2008/09/09 20:49:35 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/05/26 18:08:41 | 00,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2008/05/26 18:08:40 | 00,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2008/05/26 18:08:28 | 00,000,029 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2008/05/26 17:56:34 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2004/08/27 05:50:59 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/26 11:12:43 | 00,000,463 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/08/26 11:12:43 | 00,000,413 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2001/09/18 11:00:00 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\bmpproc.dll
========== LOP Check ==========
[2009/11/06 20:04:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/06 20:02:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/06/22 18:01:44 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/06/29 15:42:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/11/20 18:37:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/07 09:21:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wal-Mart
[2009/11/13 22:58:20 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2008/08/04 19:16:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/04/14 20:35:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2009/12/07 22:44:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DisplayTune
[2008/07/25 22:15:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LimeWire
[2008/05/26 18:59:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2009/09/20 19:13:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OOo-dev3
[2008/05/26 18:08:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2008/06/17 13:34:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2008/11/14 22:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2009/04/07 08:41:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart
[2009/04/07 09:19:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2009/12/12 13:50:32 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/12/04 17:34:00 | 00,000,436 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2009/12/12 13:01:00 | 00,000,238 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 08:07:42 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 00:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 07:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2004/08/04 00:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 14:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 14:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 14:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< End of report >