Sorry for the wait, I've been trying to back up my system before doing anything. In any case, I ran OTL and DeFogger fine, but GMER didn't work - at first the program kept closing for some reason, and then my computer starting shutting down suddenly (blue screen), so I stopped trying. I ran DeFogger and re-enabled the drivers, and I'm posting the two text files with OTL scan results.
OTL logfile created on: 3/10/2010 9:46:06 AM - Run 1
OTL by OldTimer - Version 3.1.36.0 Folder = C:\Users\Tamara\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.32 Gb Total Space | 2.12 Gb Free Space | 1.92% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 31.56 Gb Free Space | 21.18% Space Free | Partition Type: NTFS
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TAMARA-PC
Current User Name: Tamara
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/10 09:43:34 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Tamara\Downloads\OTL(2).exe
PRC - [2010/02/27 18:32:25 | 000,815,184 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/02/27 18:32:24 | 001,229,232 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/12/09 04:05:51 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccsvchst.exe
PRC - [2009/11/06 20:51:54 | 000,323,392 | —- | M] (BitTorrent, Inc.) – C:\Users\Tamara\Program Files\DNA\btdna.exe
PRC - [2009/07/17 22:12:12 | 000,257,440 | R— | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe
PRC - [2009/05/19 00:23:16 | 000,049,968 | —- | M] (AOL LLC) – C:\Program Files\AIM6\aim6.exe
PRC - [2009/02/12 03:04:50 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/06 12:33:00 | 000,041,264 | —- | M] (AOL LLC) – C:\Program Files\AIM6\aolsoftware.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/10/25 08:18:50 | 000,098,696 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/01/18 22:33:14 | 000,299,520 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\ieuser.exe
PRC - [2007/03/16 14:47:02 | 000,131,072 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\PELMICED.EXE
PRC - [2007/02/13 11:30:24 | 000,405,504 | —- | M] (Chicony) – C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
PRC - [2007/02/13 01:44:26 | 004,411,392 | —- | M] () – C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
PRC - [2007/02/06 20:50:08 | 004,374,528 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/02/02 17:56:52 | 000,118,784 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2007/02/02 16:07:14 | 000,192,512 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynToshiba.exe
PRC - [2007/01/25 20:50:26 | 000,063,096 | —- | M] () – c:\Toshiba\IVP\swupdate\swupdtmr.exe
PRC - [2007/01/25 20:47:50 | 000,136,816 | —- | M] () – C:\Toshiba\IVP\ISM\pinger.exe
PRC - [2007/01/19 01:24:20 | 000,448,632 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2007/01/17 16:46:32 | 000,534,648 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/12/20 02:16:44 | 000,411,768 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
PRC - [2006/12/20 02:15:44 | 000,428,152 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
PRC - [2006/12/03 18:51:38 | 000,021,504 | —- | M] (UPEK Inc.) – C:\Program Files\Protector Suite QL\upeksvr.exe
PRC - [2006/11/15 01:02:36 | 001,372,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
PRC - [2006/11/15 00:19:42 | 000,405,504 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
PRC - [2006/11/14 23:33:10 | 000,040,960 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2006/11/10 17:22:26 | 000,417,792 | —- | M] (TOSHIBA) – C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2006/10/23 12:54:36 | 000,056,128 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\ico.exe
PRC - [2006/10/05 14:10:12 | 000,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe
PRC - [2006/08/23 19:39:48 | 000,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2006/05/25 21:30:16 | 000,114,688 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe
========== Modules (SafeList) ==========
MOD - [2010/03/10 09:43:34 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Tamara\Downloads\OTL(2).exe
MOD - [2008/01/18 22:26:36 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/02/27 18:32:24 | 001,229,232 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/12/09 04:05:51 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe – (NAV)
SRV - [2009/10/20 13:19:48 | 000,117,264 | —- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2008/01/18 22:38:26 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/18 13:40:02 | 000,181,784 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2007/02/02 17:56:52 | 000,118,784 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe – (TOSHIBA Bluetooth Service)
SRV - [2007/01/25 20:50:26 | 000,063,096 | —- | M] () [Auto | Running] – c:\Toshiba\IVP\swupdate\swupdtmr.exe – (Swupdtmr)
SRV - [2007/01/25 20:47:50 | 000,136,816 | —- | M] () [Auto | Running] – C:\Toshiba\IVP\ISM\pinger.exe – (pinger)
SRV - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2006/12/20 02:15:44 | 000,428,152 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV - [2006/11/14 23:33:10 | 000,040,960 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe – (CFSvcs)
SRV - [2006/10/05 14:10:12 | 000,009,216 | —- | M] (Agere Systems) [Auto | Running] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2006/08/23 19:39:48 | 000,049,152 | —- | M] (Ulead Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper)
SRV - [2006/05/25 21:30:16 | 000,114,688 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\System32\TODDSrv.exe – (TODDSrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://msn.com"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.53
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\ [2010/02/08 10:19:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/02 22:30:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/02 22:30:01 | 000,000,000 | —D | M]
[2008/12/11 21:37:14 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Mozilla\Extensions
[2010/03/10 09:21:47 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions
[2009/09/02 20:39:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/08 20:28:15 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/12/11 23:12:58 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ipsbho.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Users\Tamara\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] File not found
O4 - Startup: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation)
O4 - Startup: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\Windows\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3259739a-de20-11de-bc1e-00a0d17664fd}\Shell - "" = AutoRun
O33 - MountPoints2\{3259739a-de20-11de-bc1e-00a0d17664fd}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{56d97bff-365d-11dc-aa66-0013e822c423}\Shell - "" = AutoRun
O33 - MountPoints2\{56d97bff-365d-11dc-aa66-0013e822c423}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\Shell\Auto\command - "" = RECYCLER\koyko.exe
O33 - MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\Shell\AutoRun\command - "" = RECYCLER\koyko.exe
O33 - MountPoints2\{b727f909-165f-11dd-9739-00a0d17664fd}\Shell\AutoRun\command - "" = G:\umenu.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/09/12 16:10:34 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!
========== Files/Folders - Created Within 14 Days ==========
[2010/03/07 22:01:58 | 000,000,000 | RH-D | C] – C:\Users\Tamara\Desktop\$RECYCLE.BIN
[2010/03/05 01:48:06 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Roaming\Wireshark
[2010/03/05 01:30:27 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2010/03/05 01:26:45 | 000,000,000 | —D | C] – C:\Program Files\Wireshark
[2010/03/03 21:50:54 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/02 23:13:55 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Roaming\Facebook
[2010/03/02 22:25:57 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Local\CrashDumps
[2010/03/02 18:34:46 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/02/27 18:39:18 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/02/27 18:39:18 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/02/27 18:34:00 | 000,064,288 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2010/02/27 18:28:37 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/02/27 18:27:51 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/02/27 18:27:51 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/02/27 18:18:37 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Roaming\Malwarebytes
[2010/02/27 18:18:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/27 18:18:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/02/27 18:18:26 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/02/27 18:18:26 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[3 C:\Users\Tamara\Documents\*.tmp files -> C:\Users\Tamara\Documents\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010/03/10 09:45:41 | 003,932,160 | -HS- | M] () – C:\Users\Tamara\ntuser.dat
[2010/03/10 08:55:44 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/10 08:54:24 | 000,000,370 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/03/10 08:53:04 | 000,059,752 | —- | M] () – C:\Users\Tamara\AppData\Roaming\nvModes.001
[2010/03/10 08:50:56 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/10 08:50:23 | 000,003,680 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/10 08:50:23 | 000,003,680 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/10 08:50:20 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/10 08:50:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/10 08:49:59 | 2145,443,840 | -HS- | M] () – C:\hiberfil.sys
[2010/03/10 08:49:55 | 289,483,030 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/03/10 01:15:56 | 000,059,752 | —- | M] () – C:\Users\Tamara\AppData\Roaming\nvModes.dat
[2010/03/09 14:15:56 | 000,063,989 | —- | M] () – C:\Users\Tamara\Documents\ACE Coding 301-351.xlsx
[2010/03/09 01:34:13 | 000,249,344 | —- | M] () – C:\Users\Tamara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/08 17:18:20 | 000,030,720 | —- | M] () – C:\Users\Tamara\Documents\Tamara Movsesova cover letter - MHA.doc
[2010/03/08 17:10:51 | 000,037,376 | —- | M] () – C:\Users\Tamara\Documents\TamaraMovsesova resume1.doc
[2010/03/08 17:05:00 | 000,173,573 | —- | M] () – C:\Users\Tamara\Desktop\bookmarks-2010-03-08.json
[2010/03/08 01:43:16 | 000,065,536 | -HS- | M] () – C:\Users\Tamara\ntuser.dat{e7573853-26e7-11dd-b7fd-00a0d17664fd}.TM.blf
[2010/03/08 01:43:15 | 000,524,288 | -HS- | M] () – C:\Users\Tamara\ntuser.dat{e7573853-26e7-11dd-b7fd-00a0d17664fd}.TMContainer00000000000000000001.regtrans-ms
[2010/03/08 00:08:30 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/03/08 00:08:30 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/03/08 00:08:30 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/03/07 23:35:12 | 000,012,714 | —- | M] () – C:\Users\Tamara\Documents\internships.docx
[2010/03/07 21:47:35 | 000,000,165 | -H– | M] () – C:\Users\Tamara\Documents\~$ACE Coding 301-351.xlsx
[2010/03/07 19:07:08 | 000,075,623 | —- | M] () – C:\Users\Tamara\Documents\ACE Coding Sheets.xlsx
[2010/03/04 23:55:17 | 002,555,960 | -H– | M] () – C:\Users\Tamara\AppData\Local\IconCache.db
[2010/03/04 01:08:53 | 000,040,960 | —- | M] () – C:\Users\Tamara\Documents\TamaraMovsesova cv1.doc
[2010/03/03 21:50:55 | 000,001,885 | —- | M] () – C:\Users\Tamara\Desktop\HijackThis.lnk
[2010/02/28 20:10:17 | 001,830,912 | —- | M] () – C:\Users\Tamara\Documents\Movsesova - SURF.doc
[2010/02/27 22:19:52 | 001,825,280 | —- | M] () – C:\Users\Tamara\Documents\Summer_Research_Program_Application.doc
[2010/02/27 18:39:45 | 000,001,066 | —- | M] () – C:\Users\Tamara\Desktop\Spybot - Search & Destroy.lnk
[2010/02/27 18:33:28 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/02/27 18:33:23 | 000,015,880 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2010/02/27 18:28:33 | 000,001,018 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/02/27 18:27:04 | 000,035,328 | —- | M] () – C:\Users\Tamara\Documents\UCI SURF personal statement.doc
[2010/02/27 18:18:33 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/26 23:06:00 | 000,083,288 | —- | M] () – C:\Users\Tamara\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/26 22:01:49 | 000,001,356 | —- | M] () – C:\Users\Tamara\AppData\Local\d3d9caps.dat
[2010/02/26 17:54:07 | 000,326,088 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/02/25 02:04:31 | 000,030,720 | —- | M] () – C:\Users\Tamara\Documents\2010ApplicantAdvertisingLetter.doc
[2010/02/24 18:30:12 | 000,030,208 | —- | M] () – C:\Users\Tamara\Documents\NIH cover letter.doc
[3 C:\Users\Tamara\Documents\*.tmp files -> C:\Users\Tamara\Documents\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/10 08:54:20 | 000,000,370 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/03/08 17:04:59 | 000,173,573 | —- | C] () – C:\Users\Tamara\Desktop\bookmarks-2010-03-08.json
[2010/03/07 21:47:35 | 000,063,989 | —- | C] () – C:\Users\Tamara\Documents\ACE Coding 301-351.xlsx
[2010/03/07 21:47:35 | 000,000,165 | -H– | C] () – C:\Users\Tamara\Documents\~$ACE Coding 301-351.xlsx
[2010/03/03 21:50:55 | 000,001,885 | —- | C] () – C:\Users\Tamara\Desktop\HijackThis.lnk
[2010/02/28 20:10:15 | 001,830,912 | —- | C] () – C:\Users\Tamara\Documents\Movsesova - SURF.doc
[2010/02/28 18:32:30 | 2145,443,840 | -HS- | C] () – C:\hiberfil.sys
[2010/02/28 03:55:04 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/02/27 18:39:44 | 000,001,066 | —- | C] () – C:\Users\Tamara\Desktop\Spybot - Search & Destroy.lnk
[2010/02/27 18:28:32 | 000,001,018 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/02/27 18:26:41 | 000,035,328 | —- | C] () – C:\Users\Tamara\Documents\UCI SURF personal statement.doc
[2010/02/27 18:18:32 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/26 17:47:49 | 001,825,280 | —- | C] () – C:\Users\Tamara\Documents\Summer_Research_Program_Application.doc
[2010/02/25 02:04:31 | 000,030,720 | —- | C] () – C:\Users\Tamara\Documents\2010ApplicantAdvertisingLetter.doc
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2009/10/15 03:00:54 | 000,000,448 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/12 15:19:52 | 000,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2008/09/10 20:20:45 | 000,716,272 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/05/18 23:07:41 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2008/04/19 23:58:03 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2008/04/19 23:58:00 | 002,102,272 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2008/04/19 23:57:59 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/04/19 23:57:59 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/04/19 23:57:59 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/04/19 23:57:56 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/04/19 23:57:56 | 000,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2008/01/30 02:03:48 | 000,000,067 | —- | C] () – C:\Windows\swupdate.INI
[2007/09/04 12:00:01 | 000,001,356 | —- | C] () – C:\Users\Tamara\AppData\Local\d3d9caps.dat
[2007/08/25 20:30:19 | 000,031,232 | —- | C] () – C:\Windows\System32\AsynInet.dll
[2007/08/25 20:30:18 | 000,027,136 | —- | C] () – C:\Windows\System32\tdecode.dll
[2007/08/25 20:30:18 | 000,024,064 | —- | C] () – C:\Windows\System32\TWBCust.dll
[2007/07/13 22:28:34 | 000,059,752 | —- | C] () – C:\Users\Tamara\AppData\Roaming\nvModes.dat
[2007/07/13 22:28:34 | 000,059,752 | —- | C] () – C:\Users\Tamara\AppData\Roaming\nvModes.001
[2007/07/13 19:09:12 | 000,007,587 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/07/13 18:58:58 | 000,249,344 | —- | C] () – C:\Users\Tamara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/31 02:29:53 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2007/05/31 02:29:53 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2007/05/31 02:29:53 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2007/05/31 02:29:53 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2007/03/05 12:34:28 | 000,676,224 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2007/03/02 14:03:00 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2007/03/02 14:03:00 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2007/03/02 14:03:00 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2007/03/02 14:03:00 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2007/03/02 14:03:00 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2007/03/02 14:03:00 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/02/28 15:46:33 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2007/02/28 15:39:56 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000002.regtrans-ms
[2007/02/28 15:39:56 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000001.regtrans-ms
[2007/02/28 15:39:56 | 000,065,536 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TM.blf
[2007/02/28 15:39:55 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000002.regtrans-ms
[2007/02/28 15:39:55 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000001.regtrans-ms
[2007/02/28 15:39:55 | 000,262,144 | —- | C] () – C:\ProgramData\ntuser.dat
[2007/02/28 15:39:55 | 000,065,536 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TM.blf
[2007/02/28 15:39:55 | 000,005,120 | -H– | C] () – C:\ProgramData\ntuser.dat.LOG1
[2007/02/28 15:39:55 | 000,000,000 | -H– | C] () – C:\ProgramData\ntuser.dat.LOG2
[2006/12/05 16:05:06 | 000,114,688 | —- | C] () – C:\Windows\System32\TosBtAcc.dll
[2006/11/02 07:34:20 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 13:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/07/23 00:30:20 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll
[2002/10/06 13:42:56 | 000,237,568 | —- | C] () – C:\Windows\System32\OggDS.dll
[2002/10/04 18:04:24 | 000,921,600 | —- | C] () – C:\Windows\System32\VorbisEnc.dll
[2002/10/04 18:04:24 | 000,188,416 | —- | C] () – C:\Windows\System32\vorbis.dll
[2002/10/04 18:04:16 | 000,045,056 | —- | C] () – C:\Windows\System32\ogg.dll
[2001/06/15 11:41:12 | 000,000,601 | —- | C] () – C:\Windows\krb5.ini
[2000/04/14 10:12:48 | 000,032,768 | —- | C] () – C:\Windows\KCLNT32.dll
========== LOP Check ==========
[2007/08/26 17:48:02 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\acccore
[2009/09/28 21:23:41 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\DC++
[2008/10/30 19:40:26 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Dev-Cpp
[2010/03/10 09:43:30 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\DNA
[2010/03/02 23:14:06 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Facebook
[2009/02/27 18:01:32 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\GetRightToGo
[2009/12/04 13:29:00 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Image Zone Express
[2007/07/19 20:28:21 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\InterVideo
[2007/09/17 23:22:26 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Printer Info Cache
[2008/09/12 00:51:33 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\SPORE
[2010/02/26 17:49:09 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\uTorrent
[2007/07/25 16:57:27 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\WildTangent
[2010/03/05 01:48:06 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Wireshark
[2010/03/10 08:54:24 | 000,000,370 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/03/05 00:03:37 | 000,032,610 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/19 02:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/04/11 01:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 02:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\drivers\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 04:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/02/13 03:07:31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/02/13 03:07:31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/02/13 03:07:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EVENTLOG.DLL >
[2006/12/03 18:53:08 | 000,033,280 | —- | M] (UPEK Inc.) MD5=A23819D7B19E5ECF16AAD99D90291381 – C:\Program Files\Protector Suite QL\eventlog.dll
< MD5 for: IASTORV.SYS >
[2008/01/19 02:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: KR10N.SYS >
[2007/01/03 03:43:19 | 000,207,104 | —- | M] (TOSHIBA CORPORATION) MD5=A1963360E74931222A67356C8AD48378 – C:\Windows\System32\drivers\KR10N.sys
[2007/01/03 03:43:19 | 000,207,104 | —- | M] (TOSHIBA CORPORATION) MD5=A1963360E74931222A67356C8AD48378 – C:\Windows\System32\DriverStore\FileRepository\kr10n.inf_f8c77270\KR10N.sys
< MD5 for: NETLOGON.DLL >
[2006/11/02 04:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 01:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 02:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\System32\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 04:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 04:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 02:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/19 02:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\System32\scecli.dll
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 04:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/11 01:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/12/18 08:01:57 | 000,193,024 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\iepeers.dll
[2008/01/18 22:38:04 | 000,242,744 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2008/01/18 22:36:12 | 000,225,792 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\SLC.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2008/09/10 20:20:46 | 000,716,272 | —- | M] ()
Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2007/02/28 14:10:52 | 007,147,520 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2007/02/28 14:10:49 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2007/02/28 14:10:52 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2007/02/28 14:11:00 | 016,031,744 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2007/02/28 14:11:02 | 006,070,272 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
========== Files - Unicode (All) ==========
[2008/07/10 19:58:44 | 000,010,145 | —- | M] ()(C:\Users\Tamara\Documents\???????????.docx) – C:\Users\Tamara\Documents\日本語がぜんぶ忘れたよ.docx
[2008/07/10 19:58:43 | 000,010,145 | —- | C] ()(C:\Users\Tamara\Documents\???????????.docx) – C:\Users\Tamara\Documents\日本語がぜんぶ忘れたよ.docx
[2008/07/10 19:50:57 | 000,027,006 | —- | M] ()(C:\Users\Tamara\Documents\???.docx) – C:\Users\Tamara\Documents\日本語.docx
[2008/07/10 19:50:56 | 000,027,006 | —- | C] ()(C:\Users\Tamara\Documents\???.docx) – C:\Users\Tamara\Documents\日本語.docx
[2008/04/30 02:28:57 | 000,015,850 | —- | M] ()(C:\Users\Tamara\Documents\??????.docx) – C:\Users\Tamara\Documents\ロッシアお酒.docx
[2008/04/30 02:28:56 | 000,015,850 | —- | C] ()(C:\Users\Tamara\Documents\??????.docx) – C:\Users\Tamara\Documents\ロッシアお酒.docx
[2007/11/08 01:36:26 | 000,010,414 | —- | M] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\ひゃ二重万安い.docx
[2007/11/08 01:36:25 | 000,010,414 | —- | C] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\ひゃ二重万安い.docx
[2007/09/15 15:33:34 | 000,010,291 | —- | M] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\いった抱きます.docx
[2007/09/15 15:33:34 | 000,010,291 | —- | C] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\いった抱きます.docx
< End of report >