pastormcarney
Topic Starter
I think I was able to correct the problem using the information provided by oldman960 at a link called "Facebook youtube video virus." I had tried most everything in the link already, but I used the combofix and I think that did it. I'm going to post my combofix log. If someone sees another problem I would appreciate a response.
ComboFix 10-03-23.03 - Owner 03/23/2010 16:52:18.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Local Settings\Application Data\010112010146111103.xxe
c:\windows\Downloaded Program Files\setup.dll
c:\windows\system\oeminfo.ini
c:\windows\system32\encapi32.dll
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\ps2.bat
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-02-23 to 2010-03-23 )))))))))))))))))))))))))))))))
.
2010-03-23 15:34 . 2010-03-23 15:34 ——– d—–w- c:\program files\ERUNT
2010-03-22 20:44 . 2010-03-22 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-03-20 21:09 . 2010-03-20 21:09 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4858230f-n\decora-sse.dll
2010-03-20 21:09 . 2010-03-20 21:09 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-457621a0-n\msvcp71.dll
2010-03-20 21:09 . 2010-03-20 21:09 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-457621a0-n\jmc.dll
2010-03-20 21:09 . 2010-03-20 21:09 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-457621a0-n\msvcr71.dll
2010-03-20 21:09 . 2010-03-20 21:09 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4858230f-n\decora-d3d.dll
2010-03-20 20:37 . 2009-11-25 17:01 1230080 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-03-20 20:32 . 2010-03-20 20:32 360584 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-03-20 20:32 . 2010-03-20 20:32 28424 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-03-20 20:32 . 2010-03-20 20:32 333192 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-03-20 20:32 . 2010-03-20 20:32 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-20 20:31 . 2010-03-20 20:22 1007896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-03-20 20:31 . 2010-03-20 20:22 800536 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-03-20 20:31 . 2010-03-20 20:22 613656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-03-20 20:31 . 2010-03-20 20:22 1658136 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-03-20 20:23 . 2010-03-20 20:35 ——– d—–w- C:\$AVG
2010-03-20 20:23 . 2010-03-20 20:32 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-20 20:23 . 2010-03-20 20:31 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-20 20:23 . 2010-03-20 20:32 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-20 20:23 . 2010-03-23 12:20 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-20 20:23 . 2010-03-20 20:26 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-03-20 20:22 . 2010-03-20 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-20 18:35 . 2010-03-20 18:35 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-03-20 18:35 . 2010-03-20 18:35 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2010-03-20 18:13 . 2010-03-20 18:13 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-03-20 18:09 . 2010-03-20 18:09 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-03-20 13:51 . 2010-03-20 13:51 ——– d—–w- c:\windows\system32\wbem\Repository
2010-03-20 03:11 . 2010-03-20 03:11 270336 —ha-w- C:\SZKGFS.dat
2010-03-19 23:37 . 2001-08-17 17:47 12928 -c–a-w- c:\windows\system32\dllcache\dot4prt.sys
2010-03-19 23:37 . 2001-08-17 17:47 12928 —-a-w- c:\windows\system32\drivers\Dot4Prt.sys
2010-03-19 23:37 . 2001-08-18 02:36 324608 -c–a-w- c:\windows\system32\dllcache\hpojwia.dll
2010-03-19 23:37 . 2001-08-18 02:36 324608 —-a-w- c:\windows\system32\hpojwia.dll
2010-03-19 23:37 . 2001-08-17 17:47 8704 -c–a-w- c:\windows\system32\dllcache\dot4scan.sys
2010-03-19 23:37 . 2001-08-17 17:47 8704 —-a-w- c:\windows\system32\drivers\Dot4scan.sys
2010-03-19 23:37 . 2001-08-17 17:47 23808 -c–a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-03-19 23:37 . 2001-08-17 17:47 23808 —-a-w- c:\windows\system32\drivers\Dot4usb.sys
2010-03-19 23:37 . 2008-04-13 18:39 206976 -c–a-w- c:\windows\system32\dllcache\dot4.sys
2010-03-19 23:37 . 2008-04-13 18:39 206976 —-a-w- c:\windows\system32\drivers\Dot4.sys
2010-03-19 23:07 . 2010-03-19 23:07 ——– d–h–w- c:\documents and settings\All Users\AVP9
2010-03-19 14:16 . 2010-03-19 14:16 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-03-19 14:16 . 2010-01-07 20:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-19 14:16 . 2010-03-19 14:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-19 14:16 . 2010-03-20 15:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-19 14:16 . 2010-01-07 20:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-18 13:47 . 2010-03-18 13:47 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2010-03-18 13:45 . 2010-03-18 13:45 ——– d—–w- c:\program files\Common Files\iS3
2010-03-18 13:45 . 2010-03-23 19:49 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-03-17 20:39 . 2010-03-17 20:39 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2010-03-17 20:08 . 2010-03-19 23:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-03-17 20:08 . 2010-03-17 20:08 ——– d—–w- c:\program files\Alwil Software
2010-03-10 13:15 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-05 22:16 . 2010-03-05 22:16 17408 —-a-r- c:\windows\system32\SZIO5.dll
2010-03-05 22:14 . 2010-03-05 22:14 442368 —-a-r- c:\windows\system32\SZBase5.dll
2010-03-05 22:13 . 2010-03-05 22:13 540672 —-a-r- c:\windows\system32\SZComp5.dll
2010-02-26 18:28 . 2010-03-18 07:33 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2010-02-24 19:06 . 2010-02-24 19:06 173328 —-a-r- c:\windows\system32\drivers\SZKGFS.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-23 20:46 . 2007-03-03 16:56 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-23 19:47 . 2010-03-23 19:28 3048 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-03-23 19:47 . 2003-02-20 18:57 ——– d—–w- c:\program files\Common Files\Intuit
2010-03-23 19:37 . 2003-02-20 18:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-23 15:01 . 2003-10-09 15:22 637024 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\program files\Spyware Doctor
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\program files\Common Files\PC Tools
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\documents and settings\Owner\Application Data\PC Tools
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-03-21 20:08 . 2007-04-20 13:20 ——– d—–w- c:\program files\e-Sword
2010-03-20 21:09 . 2008-06-04 20:53 ——– d—–w- c:\program files\Java
2010-03-20 20:40 . 2009-12-23 23:07 ——– d—–w- c:\documents and settings\Owner\Application Data\FCTB000061495
2010-03-20 20:22 . 2008-05-24 15:19 ——– d—–w- c:\program files\AVG
2010-03-20 18:59 . 2006-04-05 13:38 ——– d—–w- c:\program files\Logitech
2010-03-20 18:39 . 2008-07-19 20:11 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2010-03-19 23:07 . 2008-12-17 15:42 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-03-19 23:07 . 2003-11-06 18:14 ——– d—–w- c:\program files\McAfee
2010-03-19 23:07 . 2006-06-15 12:20 ——– d—–w- c:\program files\Google
2010-03-19 14:23 . 2008-11-25 23:03 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2010-03-18 13:19 . 2006-05-23 13:32 ——– d—–w- c:\program files\3B Software
2010-03-14 11:55 . 2007-07-25 21:08 2360 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-03-10 15:36 . 2010-03-23 14:25 217032 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-03-05 14:59 . 2007-10-03 00:14 ——– d—–w- c:\program files\AGES
2010-03-04 22:21 . 2008-12-01 19:36 ——– d—–w- c:\documents and settings\Owner\Application Data\Skype
2010-03-04 21:06 . 2007-11-28 19:36 ——– d—–w- c:\documents and settings\Owner\Application Data\skypePM
2010-02-25 22:33 . 2003-02-20 18:53 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-12 21:46 . 2010-02-12 21:45 17237488 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe
2010-02-12 21:45 . 2010-02-12 21:45 8406648 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\gtb_us\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-02-12 21:45 . 2010-02-12 21:45 10309448 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\chr\ChromeInstaller.exe
2010-02-12 21:44 . 2010-02-12 21:44 64000 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2010-02-12 21:44 . 2010-02-12 21:44 52288 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2010-02-12 21:44 . 2010-02-12 21:44 50688 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2010-02-12 21:44 . 2010-02-12 21:44 114688 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2010-02-05 13:25 . 2010-03-23 14:25 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-05 13:17 . 2010-03-23 14:25 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-03 17:25 . 2009-10-17 14:26 ——– d—–w- c:\documents and settings\Owner\Application Data\dvdcss
2010-01-22 13:56 . 2010-03-23 14:25 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-01-22 13:56 . 2010-03-23 14:25 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-01-22 13:56 . 2010-03-23 14:25 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-01-22 13:55 . 2010-03-23 14:25 767952 —-a-w- c:\windows\BDTSupport.dll
2009-12-31 16:50 . 2001-08-23 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-06-04 21:10 . 2008-07-19 19:12 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-06-04 21:10 . 2008-07-19 19:12 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-06-04 21:10 . 2008-07-19 19:12 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-06-04 21:10 . 2008-07-19 19:12 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-06-04 21:10 . 2008-07-19 19:12 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
——- Sigcheck ——-
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys
[-] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys
[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys
[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys
[-] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
[-] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\kbdclass.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys
[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ndis.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys
[-] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\$NtServicePackUninstall$\ntfs.sys
[-] 2002-08-29 . E3AE9C79498210A5F39FE5A9AD62BC55 . 561920 . . [5.1.2600.1106] . . c:\windows\I386\NTFS.SYS
[-] 2001-08-23 . 70FAE0DCFDFAA0838D6778FCA028CE01 . 533504 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ315403$\ntfs.sys
[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2006-01-13 . 5562CC0A47B2AEF06D3417B733F3C195 . 360448 . . [5.1.2600.2827] . . c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2005-05-25 . 63FDFEA54EB53DE2D863EE454937CE1E . 359936 . . [5.1.2600.2685] . . c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll
[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
[-] 2004-08-04 . E3CFCCDDA4EDD1D0DC9168B2E18F27B8 . 77312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\browser.dll
[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lsass.exe
[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll
[-] 2004-08-04 . 2C69EC7E5A311334D10DD95F338FCCEA . 382464 . . [6.6.2600.2180] . . c:\windows\$NtServicePackUninstall$\qmgr.dll
[-] 2001-08-23 . 3E6ACF2CD2E8C19B16E4B42D08CA3838 . 179200 . . [6.0.2600.0] . . c:\windows\$NtUninstallQ314862$\qmgr.dll
[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll
[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-01-14 . 419899803CA479B73B02390318C787C0 . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2GDR\rpcss.dll
[-] 2005-01-14 . 94456045BEB4545B5EBE1DCC85951AFA . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\rpcss.dll
[-] 2004-03-06 . 4EA08A8BBDF8DDEE0F173BB999C153C3 . 263680 . . [5.1.2600.1361] . . c:\windows\$xpsp1hfm$\KB828741\rpcss.dll
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe
[-] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe
[-] 2004-08-04 . C6CE6EEC82F187615D1002BB3BB50ED4 . 108032 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\services.exe
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2006-08-25 . B0124CB21D28B1C9F678B566B6B57D92 . 617472 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[-] 2002-08-29 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\I386\ASMS\6000\MSFT\WINDOWS\COMMON\CONTROLS\COMCTL32.DLL
[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll
[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
[-] 2004-08-04 . 10654F9DDCEA9C46CFB77554231BE73B . 60416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll
[-] 2008-07-07 20:32 . 60D1A6342238378BFB7545C81EE3606C . 253952 . . [2001.12.4414.320] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[-] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[-] 2008-07-07 20:06 . A4AB3DCA4A383F0DF4988ABDEB84F9A4 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[-] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
[-] 2004-03-06 02:16 . B748D0ABBACD362052D4D61DCD562289 . 226816 . . [2001.12.4414.53] . . c:\windows\$xpsp1hfm$\KB828741\es.dll
[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\imm32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll
[-] 2007-04-16 . 09F7CB3687F86EDAA4CA081F7AB66C03 . 986112 . . [5.1.2600.3119] . . c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
[-] 2007-04-16 . A01F9CA902A88F7CED06884174D6419D . 984576 . . [5.1.2600.3119] . . c:\windows\$NtServicePackUninstall$\kernel32.dll
[-] 2006-07-05 . 0FDD84928A5DDE2510761B7EC76CCEC9 . 985088 . . [5.1.2600.2945] . . c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll
[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lpk.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\system32\mshtml.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2009-12-21 . E6B64C6C729BBC38AB7CC92CE33F97A5 . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[-] 2009-10-29 . C0F9AC6FAB2C788FFEE3E69585A0E93F . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[-] 2009-10-29 . CBB1EF54B86EDB78649909DD1699E5CA . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll
[-] 2009-10-22 . CDA69BC1C23B0EA033B989F67CB722FF . 5939712 . . [8.00.6001.18852] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll
[-] 2009-10-22 . A6CF28C6E0B6D10098AB601D85EE55E8 . 5943296 . . [8.00.6001.22942] . . c:\windows\$hf_mig$\KB976749-IE8\SP3QFE\mshtml.dll
[-] 2009-08-29 . 0E49677EE57A928765FC47FFBACD5326 . 5940224 . . [8.00.6001.18828] . . c:\windows\ie8updates\KB976749-IE8\mshtml.dll
[-] 2009-08-29 . B68F6E6C66D17D9EDABF3D5DA71046DA . 5942272 . . [8.00.6001.22918] . . c:\windows\$hf_mig$\KB974455-IE8\SP3QFE\mshtml.dll
[-] 2009-07-19 . 5A32B43A48D6DCA339BF24105D9A028F . 5937152 . . [8.00.6001.18812] . . c:\windows\ie8updates\KB974455-IE8\mshtml.dll
[-] 2009-07-19 . F25D866DD486AD30E05E5596CB363C3E . 5938176 . . [8.00.6001.22902] . . c:\windows\$hf_mig$\KB972260-IE8\SP3QFE\mshtml.dll
[-] 2009-05-13 . EEAADAA744B20E68CF5EB4FBB4F8AFA9 . 5936128 . . [8.00.6001.18783] . . c:\windows\ie8updates\KB972260-IE8\mshtml.dll
[-] 2009-05-13 . 1290E417BF806185CC7B2845E78A104E . 5936128 . . [8.00.6001.22873] . . c:\windows\$hf_mig$\KB969897-IE8\SP3QFE\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB969897-IE8\mshtml.dll
[-] 2009-02-21 . 1BB754AB47B327DE8DBF2FA18C36357C . 3596800 . . [7.00.6000.21015] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll
[-] 2009-02-20 . C7C3E41CC2F6EB4A629FE2184136C098 . 3595264 . . [7.00.6000.16825] . . c:\windows\ie8\mshtml.dll
[-] 2009-01-17 . 3B413267DA8AE71C20E5EF3E54F74728 . 3594752 . . [7.00.6000.16809] . . c:\windows\ie7updates\KB963027-IE7\mshtml.dll
[-] 2009-01-16 . CC9D001B7370B292C35B366CA05B12B4 . 3596288 . . [7.00.6000.20996] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
[-] 2008-12-13 . 121EC39A64D64205A88C2C45B034B455 . 3593216 . . [7.00.6000.16788] . . c:\windows\ie7updates\KB961260-IE7\mshtml.dll
[-] 2008-12-13 . 121EC39A64D64205A88C2C45B034B455 . 3593216 . . [7.00.6000.16788] . . c:\windows\SoftwareDistribution\Download\11594e7b94fdf4fa05f80f796f4cd691\SP2GDR\mshtml.dll
[-] 2008-12-13 . C79FAD61CD4A26ED5AA8C16D991C6FBD . 3594752 . . [7.00.6000.20973] . . c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
[-] 2008-12-13 . C79FAD61CD4A26ED5AA8C16D991C6FBD . 3594752 . . [7.00.6000.20973] . . c:\windows\SoftwareDistribution\Download\11594e7b94fdf4fa05f80f796f4cd691\SP2QFE\mshtml.dll
[-] 2008-10-17 . EACAEDEF6FA2A969DE5B36190D45396F . 3593216 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB960714-IE7\mshtml.dll
[-] 2008-10-16 . B74F31A4BD83797D7A083F922169287D . 3595264 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
[-] 2008-08-27 . 1AD035E04A7068EC2820B055A3131ED8 . 3593216 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\mshtml.dll
[-] 2008-08-26 . 25CC085720EE3617FD1F8AB9E2F7CAB2 . 3594752 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
[-] 2008-06-24 . EC936148284F557F19C333178768109B . 3592192 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\mshtml.dll
[-] 2008-06-23 . 28B8231CA8D55FC85E027A57C90F5C88 . 3594240 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
[-] 2008-04-24 . 8976CAB317105F7431B08EA32AB73C65 . 3591680 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\mshtml.dll
[-] 2008-04-23 . 4D612FF5D3B7EEF200595AE6F95D5E68 . 3593728 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll
[-] 2008-04-14 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2008-03-01 . AB2C88167D78D71D93558ACECB24CC7A . 3591680 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\mshtml.dll
[-] 2008-03-01 . 4EE273E2B09317C1217EF0DB91F93534 . 3593216 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
[-] 2007-12-08 . A097C36412455F0C7E42377FAF8809B7 . 3592192 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\mshtml.dll
[-] 2007-12-07 . 976C46ED4A75FC66D9C596778898CE1E . 3593216 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
[-] 2007-10-30 . 54D8B404F17AA74C666F7F3AEF2AE459 . 3593216 . . [7.00.6000.20710] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll
[-] 2007-10-30 . 8AB7ECF59D6EBBE986277B65ED4A40A1 . 3590656 . . [7.00.6000.16587] . . c:\windows\ie7updates\KB944533-IE7\mshtml.dll
[-] 2007-08-22 . 591449BD8F2C8090B9259E88C78AE61D . 3058176 . . [6.00.2900.3199] . . c:\windows\ie7\mshtml.dll
[-] 2007-08-22 . 885E3BF99EA4B2213901EBC35B34CF12 . 3064832 . . [6.00.2900.3199] . . c:\windows\$hf_mig$\KB939653\SP2QFE\mshtml.dll
[-] 2007-08-20 . E267EE248CDA7667C19001C069DE867B . 3584512 . . [7.00.6000.16544] . . c:\windows\ie7updates\KB942615-IE7\mshtml.dll
[-] 2007-08-20 . AA8A4BD78D24FCDB96DDAEE3756AA372 . 3592192 . . [7.00.6000.20661] . . c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll
[-] 2007-08-13 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . c:\windows\ie7updates\KB939653-IE7\mshtml.dll
[-] 2007-06-15 . 53F3FD772C010622346C39284C4A863B . 3064320 . . [6.00.2900.3157] . . c:\windows\$hf_mig$\KB937143\SP2QFE\mshtml.dll
[-] 2007-05-04 . 00ADCB32832A10ED9419493BCEA97526 . 3064320 . . [6.00.2900.3132] . . c:\windows\$hf_mig$\KB933566\SP2QFE\mshtml.dll
[-] 2007-02-20 . 2991727809C7AC3A33E4178CC73244D8 . 3063296 . . [6.00.2900.3086] . . c:\windows\$hf_mig$\KB931768\SP2QFE\mshtml.dll
[-] 2007-01-04 . 1C45525574EF206346FBAFCAAC7CC4A5 . 3062272 . . [6.00.2900.3059] . . c:\windows\$hf_mig$\KB928090\SP2QFE\mshtml.dll
[-] 2006-10-23 . 88E1C15BB1A9ED3CBA4D6F2F408D5010 . 3061248 . . [6.00.2900.3020] . . c:\windows\$hf_mig$\KB925454\SP2QFE\mshtml.dll
[-] 2006-09-14 . CEFEA1C301139A817931BE132F0359FE . 3058688 . . [6.00.2900.2995] . . c:\windows\$hf_mig$\KB922760\SP2QFE\mshtml.dll
[-] 2006-07-28 . D251679BD9EF0250201FB899EC40FD32 . 3058176 . . [6.00.2900.2963] . . c:\windows\$hf_mig$\KB918899\SP2QFE\mshtml.dll
[-] 2006-05-19 . 8687E029BE63C77D4919485068C54D77 . 3055104 . . [6.00.2900.2912] . . c:\windows\$hf_mig$\KB916281\SP2QFE\mshtml.dll
[-] 2006-03-23 . ABCD123F888E4E97C8751378CCCC4F26 . 3055616 . . [6.00.2900.2873] . . c:\windows\$hf_mig$\KB912812\SP2QFE\mshtml.dll
[-] 2005-11-24 . D3F037F5DA702AE9DDD7663EC9D78BA7 . 3018240 . . [6.00.2900.2802] . . c:\windows\$hf_mig$\KB905915\SP2QFE\mshtml.dll
[-] 2005-10-05 . 3394299FBF1CD0B24089FC762611360B . 3017728 . . [6.00.2900.2769] . . c:\windows\$hf_mig$\KB896688\SP2QFE\mshtml.dll
[-] 2005-07-20 . A14A7A206AE22DE4FE563E44CFC7DDF5 . 3016192 . . [6.00.2900.2722] . . c:\windows\$hf_mig$\KB896727\SP2QFE\mshtml.dll
[-] 2005-05-02 . DCC5C79B99F02EEF8C826B074DBFC222 . 3014144 . . [6.00.2900.2668] . . c:\windows\$hf_mig$\KB883939\SP2QFE\mshtml.dll
[-] 2005-03-10 . 255C2CE965543ABDC3E0A25A5DA1874A . 3011072 . . [6.00.2900.2627] . . c:\windows\$hf_mig$\KB890923\SP2QFE\mshtml.dll
[-] 2005-01-27 . 91C5ADE25BC4E3322577854FA2E7B58B . 3008000 . . [6.00.2900.2604] . . c:\windows\$hf_mig$\KB867282\SP2QFE\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\mshtml.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
[-] 2004-08-04 . B0FEFA816D61EC66AA765DDF534EAB5E . 343040 . . [7.0.2600.2180] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll
[-] 2002-08-29 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCRT.DLL
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll
[-] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
[-] 2008-06-20 . 097722F235A1FB698BF9234E01B52637 . 245248 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\mswsock.dll
[-] 2008-06-20 . 1DFCA7713EA5A70D5D93B436AEA0317A . 245248 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
[-] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
[-] 2004-08-04 . 96353FCECBA774BB8DA74A1C6507015A . 407040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\netlogon.dll
[-] 2009-12-09 . 05BE3D9A71972223AFF6A3C823BA51B1 . 2189312 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\system32\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2009-08-04 . FDE779EA1A564EBFE16F4E0F82B61BAD . 2189312 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
[-] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 . 31914172342BFF330063F343AC6958FE . 2189184 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2007-02-28 . 5A5C8DB4AA962C714C8371FBDF189FC9 . 2182144 . . [5.1.2600.3093] . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
[-] 2007-02-28 . 582A8DBAA58C3B1F176EB2817DAEE77C . 2180352 . . [5.1.2600.3093] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[-] 2006-12-19 . CEF243F6DEFD20BE4ADDE26C7ECACB54 . 2182016 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
[-] 2005-03-02 . 28187802B7C368C0D3AEF7D4C382AABB . 2179456 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
[-] 2003-04-24 . 97EC4AB4650DA6FC521CF16F8A6DDCB0 . 1925760 . . [5.1.2600.1151] . . c:\windows\$xpsp1hfm$\Q811493\ntoskrnl.exe
[-] 2002-08-29 . B9080D97DBD631AADF9128F7316958D2 . 2042240 . . [5.1.2600.1106] . . c:\windows\$NtUninstallQ811493$\ntoskrnl.exe
[-] 2002-02-25 . 257AAFD1F77990355BB6E83650D52680 . 1875584 . . [5.1.2600.31] . . c:\windows\$NtUninstallQ811493_RTM$\ntoskrnl.exe
[-] 2001-08-23 . A29222D5281056E497408FCC9062F749 . 1982208 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ317277$\ntoskrnl.exe
[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\powrprof.dll
[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll
[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\scecli.dll
[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll
[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfc.dll
[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe
[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2003-09-25 . 32173306185F603E75C477E117F3BB8D . 560128 . . [5.1.2600.1255] . . c:\windows\$xpsp1hfm$\KB824141\user32.dll
[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\system32\wininet.dll
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\system32\dllcache\wininet.dll
[-] 2009-12-21 . 5E1F666B8955FD77E65D65C4C4D882A3 . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[-] 2009-10-29 . 6AF52998B90F72FF2325D84D90EDA1CC . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[-] 2009-10-29 . 75240F6EDBCE7B85DF66874407D38A4F . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll
[-] 2009-08-29 . CF0A5FE05BF614C24950D8FAEC1BC309 . 916480 . . [8.00.6001.18828] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll
[-] 2009-08-29 . 972B226BDAD71C55F3CC9A72BBF8F1C1 . 916480 . . [8.00.6001.22918] . . c:\windows\$hf_mig$\KB974455-IE8\SP3QFE\wininet.dll
[-] 2009-07-03 . 7E8A47A2E6561274B83E257CE74803FD . 915456 . . [8.00.6001.18806] . . c:\windows\ie8updates\KB974455-IE8\wininet.dll
[-] 2009-07-03 . 38114DAB42FB2EB84D1726C42B8D80C5 . 915456 . . [8.00.6001.22896] . . c:\windows\$hf_mig$\KB972260-IE8\SP3QFE\wininet.dll
[-] 2009-05-13 . 366C72AF6970DB7BB39AB0142BF09DB5 . 915456 . . [8.00.6001.18783] . . c:\windows\ie8updates\KB972260-IE8\wininet.dll
[-] 2009-05-13 . C0EB6850C8A02A154281749DC61FAF22 . 915456 . . [8.00.6001.22873] . . c:\windows\$hf_mig$\KB969897-IE8\SP3QFE\wininet.dll
[-] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB969897-IE8\wininet.dll
[-] 2009-03-03 . 28775945CCD53DEE280EF58DEA1A94C4 . 826368 . . [7.00.6000.16827] . . c:\windows\ie8\wininet.dll
[-] 2009-03-03 . C8667854873938CA13C986F16B0CD183 . 828416 . . [7.00.6000.21020] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[-] 2008-12-20 . 044E0A4E9FE97C0FB9AFE9C89E2A82E6 . 827904 . . [7.00.6000.20978] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[-] 2008-12-20 . A82935D32D0672E8FF4E91AE398E901C . 826368 . . [7.00.6000.16791] . . c:\windows\ie7updates\KB963027-IE7\wininet.dll
[-] 2008-10-16 . 6741EAF7B7F110E803A6E38F6E5FA6B0 . 826368 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB961260-IE7\wininet.dll
[-] 2008-10-16 . 0D5B75171FF51775B630A431B6C667E8 . 827904 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[-] 2008-08-26 . 77C192FE56A70D7FA0247BA0A6201C32 . 827904 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[-] 2008-08-26 . EF8EBA98145BFA44E80D17A3B3453300 . 826368 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\wininet.dll
[-] 2008-06-23 . 8C13D4A7479FA0A026EDA8ABCE82C0ED . 826368 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\wininet.dll
[-] 2008-06-23 . C66402A06B83B036C195242C0C8CF83C . 827904 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
[-] 2008-04-23 . F6589BE784647CFDBC22EA51CCB1A57A . 826368 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\wininet.dll
[-] 2008-04-23 . 41546B396A526918DA7995A02EA04E51 . 827392 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
[-] 2008-04-14 . 7A4F775ABB2F1C97DEF3E73AFA2FAEDD . 666112 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2008-03-01 . AD21461AEF8244EDEC2EF18E55E1DCF3 . 826368 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\wininet.dll
[-] 2008-03-01 . 6316C2F0C61271C8ABDFF7429174879E . 827392 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
[-] 2007-12-07 . 806D274C9A6C3AAEA5EAE8E4AF841E04 . 824832 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\wininet.dll
[-] 2007-12-07 . B5B411BB229AE6EAD7652A32ED47BFB9 . 825344 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
[-] 2007-10-10 . 30C1E0F34AD2972C72A01DB5C74AB065 . 824832 . . [7.00.6000.16574] . . c:\windows\ie7updates\KB944533-IE7\wininet.dll
[-] 2007-10-10 . 0E5D918F87EFA7D2424D66B499C7EB04 . 825344 . . [7.00.6000.20696] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
[-] 2007-08-22 . 1901AD51DA8BE9F8B38D5D526E5D1788 . 658944 . . [6.00.2900.3199] . . c:\windows\ie7\wininet.dll
[-] 2007-08-22 . A1BC17EB3758D73C3938B2318820F5B4 . 665600 . . [6.00.2900.3199] . . c:\windows\$hf_mig$\KB939653\SP2QFE\wininet.dll
[-] 2007-08-20 . 774435E499D8E9643EC961A6103C361F . 824832 . . [7.00.6000.16544] . . c:\windows\ie7updates\KB942615-IE7\wininet.dll
[-] 2007-08-20 . 357D54BF94FE9D6D8505A96B5C2A3BCA . 825344 . . [7.00.6000.20661] . . c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
[-] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie7updates\KB939653-IE7\wininet.dll
[-] 2007-06-26 . E1A3DD68B5380B360A7310A64D9BB188 . 665600 . . [6.00.2900.3164] . . c:\windows\$hf_mig$\KB937143\SP2QFE\wininet.dll
[-] 2007-04-18 . 4261BA03AFD659DE04F0A17DFBDD454D . 665600 . . [6.00.2900.3121] . . c:\windows\$hf_mig$\KB933566\SP2QFE\wininet.dll
[-] 2007-02-20 . B258C922D22DEEC880B60720531D7627 . 665600 . . [6.00.2900.3086] . . c:\windows\$hf_mig$\KB931768\SP2QFE\wininet.dll
[-] 2007-01-04 . 3FFA1573FC274E5AA7467D03941C45EE . 665088 . . [6.00.2900.3059] . . c:\windows\$hf_mig$\KB928090\SP2QFE\wininet.dll
[-] 2006-10-23 . 231EF4179ACABE486376B5CA893F1076 . 664576 . . [6.00.2900.3020] . . c:\windows\$hf_mig$\KB925454\SP2QFE\wininet.dll
[-] 2006-09-14 . D207370287CF769AEBEBF03837784963 . 664576 . . [6.00.2900.2995] . . c:\windows\$hf_mig$\KB922760\SP2QFE\wininet.dll
[-] 2006-06-23 . 64CE26DB72810B30F7855EA51E1DF836 . 664576 . . [6.00.2900.2937] . . c:\windows\$hf_mig$\KB918899\SP2QFE\wininet.dll
[-] 2006-05-10 . D94CFFDB53E7AC867438E2DFD50E7CBC . 663552 . . [6.00.2900.2904] . . c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
[-] 2006-03-04 . C0845ECBF4F9164E618EE381B79C9032 . 663552 . . [6.00.2900.2861] . . c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
[-] 2005-10-21 . AF785C4947676A7FC1673FDC5C8D0B5B . 661504 . . [6.00.2900.2781] . . c:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll
[-] 2005-09-02 . 97A6FD7CAFD688CF2C78939EBAF0CD0C . 660480 . . [6.00.2900.2753] . . c:\windows\$hf_mig$\KB896688\SP2QFE\wininet.dll
[-] 2005-07-03 . 6E533D155B259EB2363D3E04B5BE309F . 659456 . . [6.00.2900.2713] . . c:\windows\$hf_mig$\KB896727\SP2QFE\wininet.dll
[-] 2005-05-02 . E1E18136F9DD3DF1AD9C82193A5898A6 . 658944 . . [6.00.2900.2668] . . c:\windows\$hf_mig$\KB883939\SP2QFE\wininet.dll
[-] 2005-03-10 . C8663B488996E89A84C3D17C1D12B79E . 657920 . . [6.00.2900.2627] . . c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
[-] 2005-01-27 . A8EAC5330876548E9966A7D13025D196 . 657920 . . [6.00.2900.2598] . . c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\wininet.dll
[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
[-] 2004-08-04 . 92BDF74F12D6CBEC43C94D4B7F804838 . 170496 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\srsvc.dll
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
[-] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\xmlprov.dll
[-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll
[-] 2001-08-23 . 9E415EFDF50F26BCBC97C80F4E6C30CC . 1562112 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ309521$\sfcfiles.dll
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
[-] 2004-08-04 . 3151427DB7D87107D1C5BE58FAC53960 . 59904 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regsvc.dll
[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll
[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll
[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll
[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
[-] 2004-08-04 . 4B8D61792F7175BED48859CC18CE4E38 . 71680 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll
[-] 2001-08-23 . 126D90EE937FFEBACEE30BCA13D92F97 . 39936 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ315000$\ssdpsrv.dll
[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[-] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll
[-] 2001-08-23 . 458635D2E4559526CF9C895340A38702 . 197632 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ311889$\termsrv.dll
[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\appmgmts.dll
[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll
[-] 2004-08-04 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\appmgmts.dll
[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys
[-] 2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
[-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$NtServicePackUninstall$\aec.sys
[-] 2001-08-23 . B45A744CA0A15A59D8B0307CE9741E92 . 122472 . . [5.1.2520.0] . . c:\windows\$NtUninstallQ316397$\aec.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys
[-] 2004-08-04 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\agp440.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ip6fw.sys
[-] 2008-04-14 00:11 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll
[-] 2008-04-14 00:11 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
[-] 2006-11-01 19:17 . 925F8B61ED301A317BA850EBEECBDAA0 . 927504 . . [4.1.0.61] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll
[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
[-] 2004-08-04 . 95FD808E4AC22ABA025A7B3EAC0375D2 . 33792 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll
[-] 2003-10-21 . 41C5F3B926942EBDD35C6BF4154FE5F8 . 32256 . . [5.1.2600.1309] . . c:\windows\$xpsp1hfm$\KB828035\msgsvc.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2005-01-28 18:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2005-01-28 18:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[-] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
[-] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\ServicePackFiles\i386\mspmsnsv.dll
[-] 2009-12-09 . FFDCE1EEA79C678C40237D4E031E5B51 . 2066176 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-08-04 . 363B2BBEE0AEDC9E5433616D0AD0236A . 2066176 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
[-] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 . A25E9B86EFFB2AF33BF51E676B68BFB0 . 2066048 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2007-02-28 . 4D3DBDCCBF97F5BA1E74F322B155C3BA . 2059392 . . [5.1.2600.3093] . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
[-] 2007-02-28 . 515D30E2C90A3665A2739309334C9283 . 2057600 . . [5.1.2600.3093] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[-] 2006-12-19 . BA4B97C00A437C1CC3DA365D93EE1E9D . 2059392 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
[-] 2005-03-02 . D8ABA3EAB509627E707A3B14F00FBB6B . 2056832 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
[-] 2003-04-24 . 46AE6F2D416C39FFDCFC8BCB01203EA3 . 1949440 . . [5.1.2600.1151] . . c:\windows\$xpsp1hfm$\Q811493\ntkrnlpa.exe
[-] 2002-08-29 . 0E8EFB15746878A9B256E75267337233 . 1947904 . . [5.1.2600.1106] . . c:\windows\$NtUninstallQ811493$\ntkrnlpa.exe
[-] 2002-02-25 . 01FD1F7C82B263F1667A1CEA095756C5 . 1897856 . . [5.1.2600.31] . . c:\windows\$NtUninstallQ811493_RTM$\ntkrnlpa.exe
[-] 2001-08-23 . 46E2E3DCF54B819CFB2EBFE48A22B5C9 . 1896704 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ317277$\ntkrnlpa.exe
[-] 2008-04-14 00:12 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
[-] 2008-04-14 00:12 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
[-] 2004-08-04 07:56 . B62F29C00AC55A761B2E45877D85EA0F . 435200 . . [5.1.2400.2180] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll
[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll
[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
[-] 2007-02-05 . 36ACA6CDC19C95FF468A1426EB7F32F0 . 185344 . . [5.1.2600.3077] . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll
[-] 2007-02-05 . ACA5D98663D879C6BAAFCEA7E2F1B710 . 185344 . . [5.1.2600.3077] . . c:\windows\$NtServicePackUninstall$\upnphost.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 17:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2009-12-01 21:29 2166296 —-a-w- c:\program files\myBabylon_English\tbmyB1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyB1.dll" [2009-12-01 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\program files\myBabylon_English\tbmyB1.dll" [2009-12-01 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-30 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-30 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-05 630784]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-11-08 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-07-28 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CompuServe 7.0 Tray Icon.lnk]
backup=c:\windows\pss\CompuServe 7.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Corel MEDIA FOLDERS INDEXER 8.LNK]
backup=c:\windows\pss\Corel MEDIA FOLDERS INDEXER 8.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdBlocker
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
2002-06-18 07:11 69632 —-a-w- c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-03-08 18:38 48280 —-a-w- c:\program files\Common Files\AOL\1116607718\EE\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2002-10-16 14:05 114688 —-a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 07:41 49152 —-a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
2006-03-27 15:57 126104 —-a-w- c:\program files\Common Files\AOL\IPHSend\IPHSend.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JobHisInit]
2001-11-17 02:23 135168 —-a-w- c:\program files\RMClient\JobHisInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA magicolor2300WStatusDisplay]
2003-12-20 03:05 172032 —-a-w- c:\windows\system32\MSTMON_P.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\magicolor 2300WStatusDisplay]
2002-12-21 06:37 159744 —-a-w- c:\windows\system32\MSTMON_J.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaLifeService]
2005-06-03 22:09 110739 ——w- c:\program files\Logitech\MediaLife\MediaLifeService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MplSetUp]
2000-11-05 02:09 40960 —-a-w- c:\program files\RMClient\MplSetUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
2004-04-05 21:33 99480 —-a-w- c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2008-07-19 19:14 214560 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 14:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 15:01 155648 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-07-19 19:14 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WCOLOREAL]
2002-11-27 01:14 131072 —-a-w- c:\program files\Coloreal\COLOREAL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\1116607718\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\America Online 8.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ericom Software\\PowerTerm WebConnect 5.6\\151.203.99.51\\ptermX.exe"=
"c:\\Program Files\\Webs Credits\\TroubleShooter.exe"=
"c:\\Program Files\\Webs Credits\\ToolbarUpdate.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-20 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-20 242696]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-20 308064]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2009-12-24 311568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 13:23]
2010-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 13:23]
2010-03-23 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {7EC816D4-6FC3-4C58-A7DA-A770EE461602} - hxxp://151.203.99.51/Ericom/WebConnect%205.6/web/windows/ptdownloader.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{D09588AA-5560-4240-B2F2-774D78D7E917} - (no file)
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-Easy Synchronization - c:\program files\Logitech\Easy Synchronization\LogitechEasySync.exe
MSConfigStartUp-Logitech Hardware Abstraction Layer - KHALMNPR.EXE
MSConfigStartUp-MemDesktopToolApp - c:\program files\Quicken Medical Expense Manager\MemDesktopToolApp.exe
MSConfigStartUp-My Web Search Bar - c:\progra~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
MSConfigStartUp-Staples Easy Button - c:\program files\Staples Easy Button\EasyButton.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-Windows Registry Repair Pro - c:\program files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-23 16:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f7,5b,f7,aa,4f,40,df,45,94,be,02,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f7,5b,f7,aa,4f,40,df,45,94,be,02,\
[HKEY_USERS\S-1-5-21-1513334473-2246549229-786157266-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2010-03-23 17:03:41
ComboFix-quarantined-files.txt 2010-03-23 21:03
Pre-Run: 35,723,132,928 bytes free
Post-Run: 35,754,135,552 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 35C1A6297BB11C2AFEFCBF871E9E1456
I clicked on a facebook link to you tube. That infected my pc. I was able to download malewarebytes. That found koobface.trace and disabled.securitycenter. I also downloaded stopzilla which found a couple virus's. I was unable to access any anti-virus site so I copied a number of programs on a clean computer and used a flash drive to transfer them. I was able to run system restore via advanced system care. I was able to download AVG which has popped up several times saying a I have a trojan proxy virus. I've used several self help guides via you tube and tech sites. I deleted bill104.exe, ligh, fs1235.dat, brwmark.ini, and fw20.vxd. Nothing seems to be working, things seem to be getting worse.
I wanted to try turning off and on system restore, but when I open it I get a blank screen. File search opens with a blank screen in the left column, search companion. The buttons on stopzilla appear but do not work. I could not even register for this forum. I had to register on a clean computer then log on here. I cannot access my logs in the various anti-virus programs. I tried xp_taskmanager.exe, UnHookExec.inf, and GMER. I'm going to poste my OTL log:
OTL logfile created on: 3/23/2010 11:22:48 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.00 Mb Total Physical Memory | 455.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 1438 1438 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.43 Gb Total Space | 32.57 Gb Free Space | 46.24% Space Free | Partition Type: NTFS
Drive D: | 4.08 Gb Total Space | 0.16 Gb Free Space | 3.85% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 517.22 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 247.22 Mb Total Space | 211.48 Mb Free Space | 85.54% Space Free | Partition Type: FAT
Computer Name: YOUR-RVLNHR6V8D
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/03/20 12:46:00 | 000,177,600 | R— | M] (iS3, Inc.) – C:\Program Files\STOPzilla!\STOPzilla.exe
PRC - [2010/03/19 15:19:16 | 000,555,520 | —- | M] (OldTimer Tools) – C:\downloads\OTL.exe
PRC - [2010/01/07 16:07:10 | 001,394,000 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/03/19 15:19:16 | 000,555,520 | —- | M] (OldTimer Tools) – C:\downloads\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] – – (sdCoreService)
SRV - File not found [On_Demand | Stopped] – – (sdAuxService)
SRV - File not found [On_Demand | Stopped] – – (McSysmon)
SRV - File not found [Unknown | Stopped] – – (McShield)
SRV - File not found [Auto | Stopped] – – (McProxy)
SRV - File not found [On_Demand | Stopped] – – (McODS)
SRV - File not found [Auto | Stopped] – – (McNASvc)
SRV - File not found [Auto | Stopped] – – (mcmscsvc)
SRV - File not found [Auto | Stopped] – – (LBTServ)
SRV - File not found [On_Demand | Stopped] – – (gusvc)
SRV - File not found [Auto | Stopped] – – (AOL ACS)
SRV - [2010/03/20 16:31:58 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/18 15:59:36 | 000,057,344 | R— | M] (iS3, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe – (szserver)
SRV - [2010/01/22 09:56:24 | 000,112,592 | —- | M] (Threat Expert Ltd.) [Auto | Stopped] – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2009/12/24 18:02:30 | 000,311,568 | —- | M] (IObit) [Auto | Stopped] – C:\Program Files\IObit\IObit Security 360\is360srv.exe – (IS360service)
SRV - [2005/11/14 02:06:04 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2004/10/15 16:54:14 | 000,100,016 | —- | M] (America Online, Inc) [Auto | Stopped] – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor)
SRV - [2001/09/25 10:32:50 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Stopped] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2001/08/23 08:00:00 | 000,019,456 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\tcpsvcs.exe – (LPDSVC)
========== Driver Services (SafeList) ==========
DRV - [2010/03/20 16:32:07 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/03/20 16:32:03 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/03/20 16:31:50 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/03/10 11:36:36 | 000,217,032 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2010/02/24 15:06:36 | 000,173,328 | R— | M] (iS3, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\szkgfs.sys – (szkgfs)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R— | M] (iS3 Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\szkg.sys – (szkg5)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R— | M] (iS3 Inc.) [Kernel | Boot | Stopped] – C:\WINDOWS\system32\drivers\is3srv.sys – (is3srv)
DRV - [2009/05/09 01:14:20 | 000,014,736 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nuidfltr.sys – (NuidFltr)
DRV - [2008/06/04 16:54:59 | 000,102,664 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm)
DRV - [2006/04/11 09:21:50 | 000,028,256 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2006/03/22 20:22:00 | 000,328,237 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btaudio.sys – (btaudio)
DRV - [2006/03/22 20:19:04 | 000,851,402 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btkrnl.sys – (BTKRNL)
DRV - [2006/03/22 20:16:52 | 000,030,427 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btport.sys – (BTDriver)
DRV - [2006/03/22 20:16:12 | 000,065,784 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2006/03/22 20:12:12 | 000,045,683 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwhid.sys – (btwhid)
DRV - [2006/03/22 18:45:02 | 000,019,372 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\frmupgr.sys – (DFUBTUSB)
DRV - [2005/11/03 15:18:42 | 000,036,608 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LHidUsbK.sys – (LHidUsbK)
DRV - [2005/10/05 13:00:06 | 000,047,104 | —- | M] (ELTIMA Software) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\vserial.sys – (vserial)
DRV - [2005/10/05 13:00:06 | 000,018,167 | —- | M] (ELTIMA Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\vsb.sys – (vsbus)
DRV - [2004/10/22 11:41:46 | 000,413,824 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nvapu.sys – (nvnforce) Service for NVIDIA® nForce™
DRV - [2004/10/22 11:38:28 | 000,053,376 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nvax.sys – (nvax) Service for NVIDIA® nForce™
DRV - [2004/10/07 21:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2004/10/01 11:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/04 01:29:51 | 000,166,912 | —- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s3gnbm.sys – (S3Psddr)
DRV - [2004/06/10 10:08:09 | 000,010,308 | —- | M] () [Kernel | System | Stopped] – C:\WINDOWS\freedom.backup.dat – (Freedom)
DRV - [2003/07/28 15:19:00 | 001,341,339 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2003/07/09 01:52:02 | 000,020,032 | —- | M] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\MLPTDR_P.SYS – (MLPTDR_P)
DRV - [2003/06/23 12:45:34 | 000,027,650 | —- | M] (America Online) [Kernel | On_Demand | Stopped] – C:\Program Files\America Online 8.0\atwpkt2.sys – (ATWPKT2)
DRV - [2003/03/31 15:29:00 | 000,625,537 | —- | M] (LT) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/01/30 20:30:06 | 000,019,904 | —- | M] (Minolta Co., Ltd.) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\MLPTDR_J.SYS – (MLPTDR_J)
DRV - [2002/11/20 21:08:24 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2002/10/21 14:21:00 | 000,082,784 | —- | M] (VERITAS Software, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys – (drvmcdb)
DRV - [2002/10/15 16:32:16 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2002/09/23 21:37:00 | 000,080,896 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENET.sys – (NVENET)
DRV - [2002/09/06 22:24:00 | 000,013,568 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp)
DRV - [2001/06/04 17:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2010/02/18 15:44:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2010/02/18 15:44:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/20 16:34:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/20 16:23:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/17 09:58:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/18 15:44:35 | 000,000,000 | —D | M]
[2010/03/19 19:07:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions
[2009/07/12 23:23:55 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/02/13 11:29:00 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/03/19 09:41:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions\staged-xpis
[2010/03/20 17:09:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/07/19 15:12:50 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/03/19 19:04:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/07/19 15:12:38 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/06/04 17:10:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/06/04 17:10:33 | 000,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2009/06/04 17:10:33 | 000,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2009/06/04 17:10:33 | 000,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2009/06/04 17:10:36 | 000,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2009/06/04 17:10:37 | 000,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2003/02/24 16:58:34 | 000,729,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2002/08/29 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D09588AA-5560-4240-B2F2-774D78D7E917} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Ad Blocker Pro Toolbar) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - C:\Program Files\3B Software\3B Ad Blocker Pro\AKToolbar.dll (3B Software)
O3 - HKCU\..\Toolbar\WebBrowser: (myBabylon English Toolbar) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKCU..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=67633 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (Reg Error: Value error.)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Value error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Value error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {7EC816D4-6FC3-4C58-A7DA-A770EE461602} http://151.203.99.51/Ericom/WebConnect%205…tdownloader.cab (PowerTerm Downloader Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/…-131_02-win.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/02/20 13:39:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{0a590710-3029-11da-8102-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{0a590710-3029-11da-8102-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0a590710-3029-11da-8102-00038a000015}\Shell\AutoRun\command - "" = C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\AOLTEMP\setup.exe – [2005/11/01 11:48:44 | 000,142,232 | —- | M] (America Online)
O33 - MountPoints2\{34e34bd6-6d39-11d7-93c5-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{bfd48792-3cc9-11db-8142-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{bfd48792-3cc9-11db-8142-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/03/23 10:25:43 | 001,652,688 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2010/03/23 10:25:43 | 000,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2010/03/23 10:25:43 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2010/03/23 10:25:37 | 000,233,136 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/03/23 10:25:31 | 000,217,032 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/03/23 10:25:31 | 000,088,040 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/03/23 10:25:25 | 000,070,408 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\PC Tools
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/03/22 17:19:12 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/03/22 16:44:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/03/20 17:09:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/20 17:09:08 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/03/20 17:09:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/03/20 17:09:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/03/20 16:32:04 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/20 16:23:53 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/03/20 16:23:36 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/20 16:23:27 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/20 16:23:24 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/20 16:23:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/20 16:23:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/20 16:22:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/20 16:19:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/20 16:19:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/20 16:19:12 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/20 16:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/20 14:08:35 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/03/19 23:10:04 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2010/03/19 19:37:55 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2010/03/19 19:37:50 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\hpojwia.dll
[2010/03/19 19:37:50 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2010/03/19 19:37:50 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2010/03/19 19:37:43 | 000,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2010/03/19 19:37:42 | 000,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2010/03/19 19:07:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\AVP9
[2010/03/19 10:16:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2010/03/19 10:16:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/19 10:16:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/19 10:16:29 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/19 10:16:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/18 09:47:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/03/18 09:45:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2010/03/18 09:45:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/03/17 16:39:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Threat Expert
[2010/03/17 16:08:36 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/03/17 16:08:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/03/10 09:15:58 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/03/05 18:16:42 | 000,017,408 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2010/03/05 18:14:16 | 000,442,368 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2010/03/05 18:13:44 | 000,540,672 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2010/02/26 14:28:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Temp
[2010/02/24 15:06:36 | 000,173,328 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\drivers\SZKGFS.sys
[2010/02/07 09:28:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/07 09:23:25 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/03/23 11:09:36 | 000,001,016 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/03/23 11:01:31 | 000,637,024 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/23 10:54:28 | 000,001,180 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/23 10:53:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/23 10:53:26 | 001,907,560 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/23 10:52:39 | 011,010,048 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/03/23 10:52:39 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/03/23 10:25:30 | 000,001,654 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/03/23 09:38:42 | 000,000,315 | —- | M] () – C:\Documents and Settings\Owner\Desktop\regtool.vbs
[2010/03/23 09:35:16 | 000,000,610 | —- | M] () – C:\Documents and Settings\Owner\Desktop\UnHookExec.inf
[2010/03/23 09:28:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/23 09:28:16 | 003,715,890 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/03/23 08:39:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/23 08:20:17 | 057,556,517 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/23 08:17:36 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/03/23 08:17:34 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/21 16:06:05 | 000,000,016 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2010/03/21 10:48:39 | 000,000,265 | —- | M] () – C:\Documents and Settings\Owner\Desktop\The official U.S. time - clock.url
[2010/03/20 16:32:07 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/20 16:32:04 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/20 16:32:03 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/20 16:31:50 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/20 16:23:37 | 000,001,518 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/20 16:23:23 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/20 16:23:13 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/03/20 16:23:13 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/03/20 16:23:13 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/03/20 14:04:32 | 000,001,069 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/20 11:13:48 | 000,000,725 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/20 10:45:59 | 000,536,914 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/20 10:45:59 | 000,451,342 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/20 10:45:59 | 000,075,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/19 23:11:35 | 000,270,336 | -H– | M] () – C:\SZKGFS.dat
[2010/03/19 16:13:38 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/19 16:13:38 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/03/18 21:00:22 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/03/18 10:47:00 | 000,000,270 | —- | M] () – C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2010/03/17 15:10:51 | 000,026,624 | —- | M] () – C:\Documents and Settings\Owner\My Documents\faith.doc
[2010/03/17 11:32:34 | 000,000,002 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\010112010146111103.xxe
[2010/03/14 07:55:29 | 000,002,360 | —- | M] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2010/03/10 11:36:36 | 000,217,032 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/03/06 16:28:09 | 000,113,048 | —- | M] () – C:\Documents and Settings\Owner\My Documents\brethren-we-have-met-to-worship[1].pdf
[2010/03/05 18:16:42 | 000,017,408 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2010/03/05 18:14:16 | 000,442,368 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2010/03/05 18:13:44 | 000,540,672 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2010/03/04 10:06:53 | 000,002,257 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/03/02 10:28:07 | 000,897,520 | —- | M] () – C:\Documents and Settings\Owner\My Documents\2008Platform[1].pdf
[2010/02/25 18:33:41 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/02/25 10:06:34 | 000,000,639 | —- | M] () – C:\Documents and Settings\Owner\Desktop\lighthouse stationary2.doc.lnk
[2010/02/24 19:01:08 | 000,035,840 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Local church articles of faith from other churches in New England.doc
[2010/02/24 15:15:44 | 000,026,112 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Crabby Old Man.doc
[2010/02/24 15:06:36 | 000,173,328 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\drivers\SZKGFS.sys
[2010/02/23 10:49:57 | 000,031,232 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Hotel and Restaurant Suggestions.doc
[2010/02/23 10:17:38 | 006,560,768 | —- | M] () – C:\Documents and Settings\Owner\My Documents\IIWWPhotos3eReichRevueLife1.pps
[2010/02/22 14:43:00 | 000,000,754 | —- | M] () – C:\Documents and Settings\All Users\Desktop\IObit Security 360.lnk
[2010/02/21 14:08:01 | 000,083,968 | —- | M] () – C:\Documents and Settings\Owner\My Documents\GIBF meeting letter.doc
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/23 11:08:58 | 000,001,016 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/03/23 10:25:44 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/03/23 10:25:43 | 001,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2010/03/23 10:25:43 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2010/03/23 10:25:43 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2010/03/23 10:25:43 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2010/03/23 10:25:37 | 000,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/03/23 10:25:31 | 000,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/03/23 10:25:31 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctcore.cat
[2010/03/23 10:25:30 | 000,001,654 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/03/23 10:25:25 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/03/23 09:56:50 | 000,000,610 | —- | C] () – C:\Documents and Settings\Owner\Desktop\UnHookExec.inf
[2010/03/23 09:56:46 | 000,000,315 | —- | C] () – C:\Documents and Settings\Owner\Desktop\regtool.vbs
[2010/03/20 16:23:37 | 000,001,518 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/20 16:23:23 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/20 16:23:13 | 057,556,517 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/20 16:23:13 | 006,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/03/20 16:23:13 | 000,492,629 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/03/20 16:23:13 | 000,142,495 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/03/19 23:11:35 | 000,270,336 | -H– | C] () – C:\SZKGFS.dat
[2010/03/19 19:37:50 | 000,018,411 | —- | C] () – C:\WINDOWS\System32\hpo5500a.aio
[2010/03/19 19:37:50 | 000,018,411 | —- | C] () – C:\WINDOWS\System32\hpo5400a.aio
[2010/03/19 19:37:50 | 000,018,411 | —- | C] () – C:\WINDOWS\System32\hpo5300a.aio
[2010/03/19 17:50:32 | 000,000,016 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/03/19 10:16:39 | 000,000,725 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/17 15:10:51 | 000,026,624 | —- | C] () – C:\Documents and Settings\Owner\My Documents\faith.doc
[2010/03/17 11:32:34 | 000,000,002 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\010112010146111103.xxe
[2010/03/06 16:28:08 | 000,113,048 | —- | C] () – C:\Documents and Settings\Owner\My Documents\brethren-we-have-met-to-worship[1].pdf
[2010/03/05 10:59:14 | 000,046,972 | —- | C] () – C:\WINDOWS\System32\LSBTrans.TTF
[2010/03/05 10:59:14 | 000,045,384 | —- | C] () – C:\WINDOWS\System32\LSBGreek.TTF
[2010/03/05 10:59:14 | 000,039,704 | —- | C] () – C:\WINDOWS\System32\LSBHebre.TTF
[2010/03/02 10:28:07 | 000,897,520 | —- | C] () – C:\Documents and Settings\Owner\My Documents\2008Platform[1].pdf
[2010/02/25 10:06:34 | 000,000,639 | —- | C] () – C:\Documents and Settings\Owner\Desktop\lighthouse stationary2.doc.lnk
[2010/02/24 18:14:47 | 000,035,840 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Local church articles of faith from other churches in New England.doc
[2010/02/24 15:15:43 | 000,026,112 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Crabby Old Man.doc
[2010/02/23 10:17:34 | 006,560,768 | —- | C] () – C:\Documents and Settings\Owner\My Documents\IIWWPhotos3eReichRevueLife1.pps
[2010/02/21 11:44:48 | 000,031,232 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Hotel and Restaurant Suggestions.doc
[2010/02/21 11:34:29 | 000,083,968 | —- | C] () – C:\Documents and Settings\Owner\My Documents\GIBF meeting letter.doc
[2010/02/05 14:04:41 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2009/12/10 17:51:24 | 000,000,026 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/10 17:50:51 | 000,000,229 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/10 17:50:51 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/12/10 17:48:39 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2009/12/10 17:48:39 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2009/12/10 17:48:34 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2009/12/10 17:48:32 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/12/10 17:46:03 | 000,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2009/11/04 16:04:37 | 000,000,326 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\PrimoPDFSet.xml
[2009/10/17 11:20:49 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/24 16:21:21 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\U25STORE.DLL
[2009/07/24 16:21:21 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\U25TOTAL.DLL
[2009/07/24 16:21:20 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\U25DTS.DLL
[2009/07/24 16:21:19 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\IMPLODE.DLL
[2009/05/22 16:30:08 | 000,006,910 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PrimoPDFSet.xml
[2009/05/22 16:17:16 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/04/27 00:13:36 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2008/12/09 12:34:24 | 000,004,874 | —- | C] () – C:\Documents and Settings\Owner\Application Data\SAS7_000.DAT
[2008/08/31 19:52:46 | 000,000,050 | —- | C] () – C:\WINDOWS\Winamp.ini
[2008/08/31 19:52:43 | 000,000,041 | —- | C] () – C:\WINDOWS\winampa.ini
[2007/11/28 15:36:48 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/07/25 17:08:39 | 000,002,360 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2007/07/07 12:19:19 | 000,087,808 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2007/06/27 12:18:31 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/05/29 18:03:24 | 000,000,406 | —- | C] () – C:\WINDOWS\barcode.ini
[2007/04/27 19:10:49 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/04/10 16:48:17 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\sh33w32.dll
[2006/07/31 01:59:36 | 000,000,338 | —- | C] () – C:\WINDOWS\scrub2k.ini
[2006/06/13 08:21:40 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/04/05 09:44:48 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2006/03/22 20:28:58 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/05/20 12:37:41 | 000,000,101 | —- | C] () – C:\WINDOWS\upst.ini
[2005/05/20 12:37:41 | 000,000,025 | —- | C] () – C:\WINDOWS\atid.ini
[2005/04/19 18:19:00 | 000,000,319 | —- | C] () – C:\WINDOWS\SWWATER.INI
[2005/04/09 15:22:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\RPCS.ini
[2005/04/09 15:21:46 | 000,027,489 | —- | C] () – C:\WINDOWS\RicDB.ini
[2005/04/09 15:21:34 | 000,000,226 | —- | C] () – C:\WINDOWS\PMJobCli.ini
[2005/04/09 15:21:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\PMObservps.dll
[2005/04/09 15:21:28 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\rpnv2ui.dll
[2005/04/09 15:21:28 | 000,270,336 | R— | C] () – C:\WINDOWS\System32\rpnv2job.dll
[2005/04/09 15:21:28 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RLPR.dll
[2005/04/09 15:21:28 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\rtcpf.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApisv.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApipt.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApipl.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApino.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApinl.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApiit.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApihu.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApifr.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApifi.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApies.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApide.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApida.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApics.dll
[2005/04/09 15:21:26 | 000,012,027 | —- | C] () – C:\WINDOWS\PMRicMb.ini
[2005/04/09 15:21:26 | 000,006,702 | —- | C] () – C:\WINDOWS\PMRicPMb.ini
[2005/04/09 15:21:26 | 000,005,390 | —- | C] () – C:\WINDOWS\PMPrtMb.ini
[2005/04/09 15:21:26 | 000,003,611 | —- | C] () – C:\WINDOWS\PMRicFMb.ini
[2005/04/09 15:21:26 | 000,003,005 | —- | C] () – C:\WINDOWS\PMDvPrn.ini
[2005/04/09 15:21:26 | 000,002,087 | —- | C] () – C:\WINDOWS\PMDvDev.ini
[2005/04/09 15:21:26 | 000,002,047 | —- | C] () – C:\WINDOWS\PMDIOMb.ini
[2005/04/09 15:21:26 | 000,002,036 | —- | C] () – C:\WINDOWS\PMHostMb.ini
[2005/04/09 15:21:26 | 000,001,885 | —- | C] () – C:\WINDOWS\PMPSIOMb.ini
[2005/04/09 15:21:26 | 000,001,727 | —- | C] () – C:\WINDOWS\PMRicSMb.ini
[2005/04/09 15:21:26 | 000,001,706 | —- | C] () – C:\WINDOWS\PMRicCMb.ini
[2005/04/09 15:21:26 | 000,001,494 | —- | C] () – C:\WINDOWS\PMMib2Mb.ini
[2005/04/09 15:21:26 | 000,001,143 | —- | C] () – C:\WINDOWS\PMDPIMb.ini
[2005/04/09 15:21:26 | 000,001,094 | —- | C] () – C:\WINDOWS\PMAxsMb.ini
[2005/04/09 15:21:26 | 000,000,994 | —- | C] () – C:\WINDOWS\PMDvFax.ini
[2005/04/09 15:21:26 | 000,000,842 | —- | C] () – C:\WINDOWS\PMDvScan.ini
[2005/04/09 15:21:26 | 000,000,423 | —- | C] () – C:\WINDOWS\PMDvCopy.ini
[2005/04/09 15:21:26 | 000,000,332 | —- | C] () – C:\WINDOWS\PMSnmpMb.ini
[2005/04/07 08:17:31 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\AnexBC.dll
[2005/02/17 12:41:32 | 000,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2004/06/10 09:38:49 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/06/04 19:12:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/02/03 16:30:53 | 000,108,032 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/12/23 15:58:36 | 000,002,297 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/10/08 22:58:22 | 000,025,556 | —- | C] () – C:\WINDOWS\MSTMON_P.INI
[2003/09/23 15:57:37 | 000,000,751 | —- | C] () – C:\WINDOWS\Bti.ini
[2003/09/23 15:57:35 | 000,116,640 | —- | C] () – C:\WINDOWS\System32\Ptsaci40.dll
[2003/08/21 21:51:24 | 000,018,130 | —- | C] () – C:\WINDOWS\MSUMLT_P.INI
[2003/08/08 15:40:22 | 000,000,164 | —- | C] () – C:\WINDOWS\ImportClient.INI
[2003/06/25 16:21:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/06/25 14:49:03 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS2v.DLL
[2003/05/04 10:25:28 | 000,000,070 | —- | C] () – C:\WINDOWS\24039AE7.ini
[2003/04/19 20:03:22 | 000,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2003/04/19 20:03:22 | 000,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2003/04/19 20:01:37 | 000,000,242 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/02/21 12:47:56 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/02/21 12:47:19 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\iAlmcoin.dll
[2003/02/20 20:03:14 | 000,024,548 | —- | C] () – C:\WINDOWS\MSTMON_J.INI
[2003/02/20 15:11:52 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/02/20 15:09:09 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/02/20 15:09:09 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/02/20 14:57:26 | 000,000,396 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/02/20 14:57:18 | 000,000,792 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/02/20 14:52:14 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/02/20 14:19:01 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/02/20 14:08:09 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2003/02/20 13:57:23 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/02/20 13:57:23 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/02/20 13:57:05 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/02/20 13:42:09 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/02/20 12:28:42 | 000,000,573 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/16 21:30:34 | 001,617,920 | —- | C] () – C:\WINDOWS\System32\MSTMON_J.DLL
[2003/01/07 19:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/20 22:38:22 | 000,018,130 | —- | C] () – C:\WINDOWS\MSUMLT_J.INI
[2002/12/13 22:32:52 | 000,000,141 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/09/01 02:33:58 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\VxDMDcDlg.dll
[2001/08/14 22:47:08 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== Alternate Data Streams ==========
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
ComboFix 10-03-23.03 - Owner 03/23/2010 16:52:18.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Local Settings\Application Data\010112010146111103.xxe
c:\windows\Downloaded Program Files\setup.dll
c:\windows\system\oeminfo.ini
c:\windows\system32\encapi32.dll
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\ps2.bat
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-02-23 to 2010-03-23 )))))))))))))))))))))))))))))))
.
2010-03-23 15:34 . 2010-03-23 15:34 ——– d—–w- c:\program files\ERUNT
2010-03-22 20:44 . 2010-03-22 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-03-20 21:09 . 2010-03-20 21:09 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4858230f-n\decora-sse.dll
2010-03-20 21:09 . 2010-03-20 21:09 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-457621a0-n\msvcp71.dll
2010-03-20 21:09 . 2010-03-20 21:09 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-457621a0-n\jmc.dll
2010-03-20 21:09 . 2010-03-20 21:09 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-457621a0-n\msvcr71.dll
2010-03-20 21:09 . 2010-03-20 21:09 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4858230f-n\decora-d3d.dll
2010-03-20 20:37 . 2009-11-25 17:01 1230080 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-03-20 20:32 . 2010-03-20 20:32 360584 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-03-20 20:32 . 2010-03-20 20:32 28424 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-03-20 20:32 . 2010-03-20 20:32 333192 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-03-20 20:32 . 2010-03-20 20:32 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-20 20:31 . 2010-03-20 20:22 1007896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-03-20 20:31 . 2010-03-20 20:22 800536 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-03-20 20:31 . 2010-03-20 20:22 613656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-03-20 20:31 . 2010-03-20 20:22 1658136 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-03-20 20:23 . 2010-03-20 20:35 ——– d—–w- C:\$AVG
2010-03-20 20:23 . 2010-03-20 20:32 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-20 20:23 . 2010-03-20 20:31 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-20 20:23 . 2010-03-20 20:32 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-20 20:23 . 2010-03-23 12:20 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-20 20:23 . 2010-03-20 20:26 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-03-20 20:22 . 2010-03-20 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-20 18:35 . 2010-03-20 18:35 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-03-20 18:35 . 2010-03-20 18:35 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2010-03-20 18:13 . 2010-03-20 18:13 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-03-20 18:09 . 2010-03-20 18:09 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-03-20 13:51 . 2010-03-20 13:51 ——– d—–w- c:\windows\system32\wbem\Repository
2010-03-20 03:11 . 2010-03-20 03:11 270336 —ha-w- C:\SZKGFS.dat
2010-03-19 23:37 . 2001-08-17 17:47 12928 -c–a-w- c:\windows\system32\dllcache\dot4prt.sys
2010-03-19 23:37 . 2001-08-17 17:47 12928 —-a-w- c:\windows\system32\drivers\Dot4Prt.sys
2010-03-19 23:37 . 2001-08-18 02:36 324608 -c–a-w- c:\windows\system32\dllcache\hpojwia.dll
2010-03-19 23:37 . 2001-08-18 02:36 324608 —-a-w- c:\windows\system32\hpojwia.dll
2010-03-19 23:37 . 2001-08-17 17:47 8704 -c–a-w- c:\windows\system32\dllcache\dot4scan.sys
2010-03-19 23:37 . 2001-08-17 17:47 8704 —-a-w- c:\windows\system32\drivers\Dot4scan.sys
2010-03-19 23:37 . 2001-08-17 17:47 23808 -c–a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-03-19 23:37 . 2001-08-17 17:47 23808 —-a-w- c:\windows\system32\drivers\Dot4usb.sys
2010-03-19 23:37 . 2008-04-13 18:39 206976 -c–a-w- c:\windows\system32\dllcache\dot4.sys
2010-03-19 23:37 . 2008-04-13 18:39 206976 —-a-w- c:\windows\system32\drivers\Dot4.sys
2010-03-19 23:07 . 2010-03-19 23:07 ——– d–h–w- c:\documents and settings\All Users\AVP9
2010-03-19 14:16 . 2010-03-19 14:16 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-03-19 14:16 . 2010-01-07 20:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-19 14:16 . 2010-03-19 14:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-19 14:16 . 2010-03-20 15:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-19 14:16 . 2010-01-07 20:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-18 13:47 . 2010-03-18 13:47 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2010-03-18 13:45 . 2010-03-18 13:45 ——– d—–w- c:\program files\Common Files\iS3
2010-03-18 13:45 . 2010-03-23 19:49 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-03-17 20:39 . 2010-03-17 20:39 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2010-03-17 20:08 . 2010-03-19 23:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-03-17 20:08 . 2010-03-17 20:08 ——– d—–w- c:\program files\Alwil Software
2010-03-10 13:15 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-05 22:16 . 2010-03-05 22:16 17408 —-a-r- c:\windows\system32\SZIO5.dll
2010-03-05 22:14 . 2010-03-05 22:14 442368 —-a-r- c:\windows\system32\SZBase5.dll
2010-03-05 22:13 . 2010-03-05 22:13 540672 —-a-r- c:\windows\system32\SZComp5.dll
2010-02-26 18:28 . 2010-03-18 07:33 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2010-02-24 19:06 . 2010-02-24 19:06 173328 —-a-r- c:\windows\system32\drivers\SZKGFS.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-23 20:46 . 2007-03-03 16:56 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-23 19:47 . 2010-03-23 19:28 3048 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-03-23 19:47 . 2003-02-20 18:57 ——– d—–w- c:\program files\Common Files\Intuit
2010-03-23 19:37 . 2003-02-20 18:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-23 15:01 . 2003-10-09 15:22 637024 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\program files\Spyware Doctor
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\program files\Common Files\PC Tools
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\documents and settings\Owner\Application Data\PC Tools
2010-03-23 14:25 . 2010-03-23 14:25 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-03-21 20:08 . 2007-04-20 13:20 ——– d—–w- c:\program files\e-Sword
2010-03-20 21:09 . 2008-06-04 20:53 ——– d—–w- c:\program files\Java
2010-03-20 20:40 . 2009-12-23 23:07 ——– d—–w- c:\documents and settings\Owner\Application Data\FCTB000061495
2010-03-20 20:22 . 2008-05-24 15:19 ——– d—–w- c:\program files\AVG
2010-03-20 18:59 . 2006-04-05 13:38 ——– d—–w- c:\program files\Logitech
2010-03-20 18:39 . 2008-07-19 20:11 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2010-03-19 23:07 . 2008-12-17 15:42 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-03-19 23:07 . 2003-11-06 18:14 ——– d—–w- c:\program files\McAfee
2010-03-19 23:07 . 2006-06-15 12:20 ——– d—–w- c:\program files\Google
2010-03-19 14:23 . 2008-11-25 23:03 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2010-03-18 13:19 . 2006-05-23 13:32 ——– d—–w- c:\program files\3B Software
2010-03-14 11:55 . 2007-07-25 21:08 2360 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-03-10 15:36 . 2010-03-23 14:25 217032 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-03-05 14:59 . 2007-10-03 00:14 ——– d—–w- c:\program files\AGES
2010-03-04 22:21 . 2008-12-01 19:36 ——– d—–w- c:\documents and settings\Owner\Application Data\Skype
2010-03-04 21:06 . 2007-11-28 19:36 ——– d—–w- c:\documents and settings\Owner\Application Data\skypePM
2010-02-25 22:33 . 2003-02-20 18:53 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-12 21:46 . 2010-02-12 21:45 17237488 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe
2010-02-12 21:45 . 2010-02-12 21:45 8406648 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\gtb_us\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-02-12 21:45 . 2010-02-12 21:45 10309448 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\chr\ChromeInstaller.exe
2010-02-12 21:44 . 2010-02-12 21:44 64000 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2010-02-12 21:44 . 2010-02-12 21:44 52288 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2010-02-12 21:44 . 2010-02-12 21:44 50688 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2010-02-12 21:44 . 2010-02-12 21:44 114688 —-a-w- c:\documents and settings\Owner\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2010-02-05 13:25 . 2010-03-23 14:25 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-05 13:17 . 2010-03-23 14:25 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-03 17:25 . 2009-10-17 14:26 ——– d—–w- c:\documents and settings\Owner\Application Data\dvdcss
2010-01-22 13:56 . 2010-03-23 14:25 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-01-22 13:56 . 2010-03-23 14:25 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-01-22 13:56 . 2010-03-23 14:25 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-01-22 13:55 . 2010-03-23 14:25 767952 —-a-w- c:\windows\BDTSupport.dll
2009-12-31 16:50 . 2001-08-23 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-06-04 21:10 . 2008-07-19 19:12 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-06-04 21:10 . 2008-07-19 19:12 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-06-04 21:10 . 2008-07-19 19:12 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-06-04 21:10 . 2008-07-19 19:12 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-06-04 21:10 . 2008-07-19 19:12 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
——- Sigcheck ——-
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys
[-] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys
[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys
[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys
[-] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
[-] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\kbdclass.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys
[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ndis.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys
[-] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\$NtServicePackUninstall$\ntfs.sys
[-] 2002-08-29 . E3AE9C79498210A5F39FE5A9AD62BC55 . 561920 . . [5.1.2600.1106] . . c:\windows\I386\NTFS.SYS
[-] 2001-08-23 . 70FAE0DCFDFAA0838D6778FCA028CE01 . 533504 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ315403$\ntfs.sys
[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2006-01-13 . 5562CC0A47B2AEF06D3417B733F3C195 . 360448 . . [5.1.2600.2827] . . c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2005-05-25 . 63FDFEA54EB53DE2D863EE454937CE1E . 359936 . . [5.1.2600.2685] . . c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll
[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
[-] 2004-08-04 . E3CFCCDDA4EDD1D0DC9168B2E18F27B8 . 77312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\browser.dll
[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lsass.exe
[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll
[-] 2004-08-04 . 2C69EC7E5A311334D10DD95F338FCCEA . 382464 . . [6.6.2600.2180] . . c:\windows\$NtServicePackUninstall$\qmgr.dll
[-] 2001-08-23 . 3E6ACF2CD2E8C19B16E4B42D08CA3838 . 179200 . . [6.0.2600.0] . . c:\windows\$NtUninstallQ314862$\qmgr.dll
[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll
[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-01-14 . 419899803CA479B73B02390318C787C0 . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2GDR\rpcss.dll
[-] 2005-01-14 . 94456045BEB4545B5EBE1DCC85951AFA . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\rpcss.dll
[-] 2004-03-06 . 4EA08A8BBDF8DDEE0F173BB999C153C3 . 263680 . . [5.1.2600.1361] . . c:\windows\$xpsp1hfm$\KB828741\rpcss.dll
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe
[-] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe
[-] 2004-08-04 . C6CE6EEC82F187615D1002BB3BB50ED4 . 108032 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\services.exe
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2006-08-25 . B0124CB21D28B1C9F678B566B6B57D92 . 617472 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[-] 2002-08-29 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\I386\ASMS\6000\MSFT\WINDOWS\COMMON\CONTROLS\COMCTL32.DLL
[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll
[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
[-] 2004-08-04 . 10654F9DDCEA9C46CFB77554231BE73B . 60416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll
[-] 2008-07-07 20:32 . 60D1A6342238378BFB7545C81EE3606C . 253952 . . [2001.12.4414.320] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[-] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[-] 2008-07-07 20:06 . A4AB3DCA4A383F0DF4988ABDEB84F9A4 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[-] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
[-] 2004-03-06 02:16 . B748D0ABBACD362052D4D61DCD562289 . 226816 . . [2001.12.4414.53] . . c:\windows\$xpsp1hfm$\KB828741\es.dll
[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\imm32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll
[-] 2007-04-16 . 09F7CB3687F86EDAA4CA081F7AB66C03 . 986112 . . [5.1.2600.3119] . . c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
[-] 2007-04-16 . A01F9CA902A88F7CED06884174D6419D . 984576 . . [5.1.2600.3119] . . c:\windows\$NtServicePackUninstall$\kernel32.dll
[-] 2006-07-05 . 0FDD84928A5DDE2510761B7EC76CCEC9 . 985088 . . [5.1.2600.2945] . . c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll
[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lpk.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\system32\mshtml.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2009-12-21 . E6B64C6C729BBC38AB7CC92CE33F97A5 . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[-] 2009-10-29 . C0F9AC6FAB2C788FFEE3E69585A0E93F . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[-] 2009-10-29 . CBB1EF54B86EDB78649909DD1699E5CA . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll
[-] 2009-10-22 . CDA69BC1C23B0EA033B989F67CB722FF . 5939712 . . [8.00.6001.18852] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll
[-] 2009-10-22 . A6CF28C6E0B6D10098AB601D85EE55E8 . 5943296 . . [8.00.6001.22942] . . c:\windows\$hf_mig$\KB976749-IE8\SP3QFE\mshtml.dll
[-] 2009-08-29 . 0E49677EE57A928765FC47FFBACD5326 . 5940224 . . [8.00.6001.18828] . . c:\windows\ie8updates\KB976749-IE8\mshtml.dll
[-] 2009-08-29 . B68F6E6C66D17D9EDABF3D5DA71046DA . 5942272 . . [8.00.6001.22918] . . c:\windows\$hf_mig$\KB974455-IE8\SP3QFE\mshtml.dll
[-] 2009-07-19 . 5A32B43A48D6DCA339BF24105D9A028F . 5937152 . . [8.00.6001.18812] . . c:\windows\ie8updates\KB974455-IE8\mshtml.dll
[-] 2009-07-19 . F25D866DD486AD30E05E5596CB363C3E . 5938176 . . [8.00.6001.22902] . . c:\windows\$hf_mig$\KB972260-IE8\SP3QFE\mshtml.dll
[-] 2009-05-13 . EEAADAA744B20E68CF5EB4FBB4F8AFA9 . 5936128 . . [8.00.6001.18783] . . c:\windows\ie8updates\KB972260-IE8\mshtml.dll
[-] 2009-05-13 . 1290E417BF806185CC7B2845E78A104E . 5936128 . . [8.00.6001.22873] . . c:\windows\$hf_mig$\KB969897-IE8\SP3QFE\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB969897-IE8\mshtml.dll
[-] 2009-02-21 . 1BB754AB47B327DE8DBF2FA18C36357C . 3596800 . . [7.00.6000.21015] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll
[-] 2009-02-20 . C7C3E41CC2F6EB4A629FE2184136C098 . 3595264 . . [7.00.6000.16825] . . c:\windows\ie8\mshtml.dll
[-] 2009-01-17 . 3B413267DA8AE71C20E5EF3E54F74728 . 3594752 . . [7.00.6000.16809] . . c:\windows\ie7updates\KB963027-IE7\mshtml.dll
[-] 2009-01-16 . CC9D001B7370B292C35B366CA05B12B4 . 3596288 . . [7.00.6000.20996] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
[-] 2008-12-13 . 121EC39A64D64205A88C2C45B034B455 . 3593216 . . [7.00.6000.16788] . . c:\windows\ie7updates\KB961260-IE7\mshtml.dll
[-] 2008-12-13 . 121EC39A64D64205A88C2C45B034B455 . 3593216 . . [7.00.6000.16788] . . c:\windows\SoftwareDistribution\Download\11594e7b94fdf4fa05f80f796f4cd691\SP2GDR\mshtml.dll
[-] 2008-12-13 . C79FAD61CD4A26ED5AA8C16D991C6FBD . 3594752 . . [7.00.6000.20973] . . c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
[-] 2008-12-13 . C79FAD61CD4A26ED5AA8C16D991C6FBD . 3594752 . . [7.00.6000.20973] . . c:\windows\SoftwareDistribution\Download\11594e7b94fdf4fa05f80f796f4cd691\SP2QFE\mshtml.dll
[-] 2008-10-17 . EACAEDEF6FA2A969DE5B36190D45396F . 3593216 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB960714-IE7\mshtml.dll
[-] 2008-10-16 . B74F31A4BD83797D7A083F922169287D . 3595264 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
[-] 2008-08-27 . 1AD035E04A7068EC2820B055A3131ED8 . 3593216 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\mshtml.dll
[-] 2008-08-26 . 25CC085720EE3617FD1F8AB9E2F7CAB2 . 3594752 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
[-] 2008-06-24 . EC936148284F557F19C333178768109B . 3592192 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\mshtml.dll
[-] 2008-06-23 . 28B8231CA8D55FC85E027A57C90F5C88 . 3594240 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
[-] 2008-04-24 . 8976CAB317105F7431B08EA32AB73C65 . 3591680 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\mshtml.dll
[-] 2008-04-23 . 4D612FF5D3B7EEF200595AE6F95D5E68 . 3593728 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll
[-] 2008-04-14 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2008-03-01 . AB2C88167D78D71D93558ACECB24CC7A . 3591680 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\mshtml.dll
[-] 2008-03-01 . 4EE273E2B09317C1217EF0DB91F93534 . 3593216 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
[-] 2007-12-08 . A097C36412455F0C7E42377FAF8809B7 . 3592192 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\mshtml.dll
[-] 2007-12-07 . 976C46ED4A75FC66D9C596778898CE1E . 3593216 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
[-] 2007-10-30 . 54D8B404F17AA74C666F7F3AEF2AE459 . 3593216 . . [7.00.6000.20710] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll
[-] 2007-10-30 . 8AB7ECF59D6EBBE986277B65ED4A40A1 . 3590656 . . [7.00.6000.16587] . . c:\windows\ie7updates\KB944533-IE7\mshtml.dll
[-] 2007-08-22 . 591449BD8F2C8090B9259E88C78AE61D . 3058176 . . [6.00.2900.3199] . . c:\windows\ie7\mshtml.dll
[-] 2007-08-22 . 885E3BF99EA4B2213901EBC35B34CF12 . 3064832 . . [6.00.2900.3199] . . c:\windows\$hf_mig$\KB939653\SP2QFE\mshtml.dll
[-] 2007-08-20 . E267EE248CDA7667C19001C069DE867B . 3584512 . . [7.00.6000.16544] . . c:\windows\ie7updates\KB942615-IE7\mshtml.dll
[-] 2007-08-20 . AA8A4BD78D24FCDB96DDAEE3756AA372 . 3592192 . . [7.00.6000.20661] . . c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll
[-] 2007-08-13 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . c:\windows\ie7updates\KB939653-IE7\mshtml.dll
[-] 2007-06-15 . 53F3FD772C010622346C39284C4A863B . 3064320 . . [6.00.2900.3157] . . c:\windows\$hf_mig$\KB937143\SP2QFE\mshtml.dll
[-] 2007-05-04 . 00ADCB32832A10ED9419493BCEA97526 . 3064320 . . [6.00.2900.3132] . . c:\windows\$hf_mig$\KB933566\SP2QFE\mshtml.dll
[-] 2007-02-20 . 2991727809C7AC3A33E4178CC73244D8 . 3063296 . . [6.00.2900.3086] . . c:\windows\$hf_mig$\KB931768\SP2QFE\mshtml.dll
[-] 2007-01-04 . 1C45525574EF206346FBAFCAAC7CC4A5 . 3062272 . . [6.00.2900.3059] . . c:\windows\$hf_mig$\KB928090\SP2QFE\mshtml.dll
[-] 2006-10-23 . 88E1C15BB1A9ED3CBA4D6F2F408D5010 . 3061248 . . [6.00.2900.3020] . . c:\windows\$hf_mig$\KB925454\SP2QFE\mshtml.dll
[-] 2006-09-14 . CEFEA1C301139A817931BE132F0359FE . 3058688 . . [6.00.2900.2995] . . c:\windows\$hf_mig$\KB922760\SP2QFE\mshtml.dll
[-] 2006-07-28 . D251679BD9EF0250201FB899EC40FD32 . 3058176 . . [6.00.2900.2963] . . c:\windows\$hf_mig$\KB918899\SP2QFE\mshtml.dll
[-] 2006-05-19 . 8687E029BE63C77D4919485068C54D77 . 3055104 . . [6.00.2900.2912] . . c:\windows\$hf_mig$\KB916281\SP2QFE\mshtml.dll
[-] 2006-03-23 . ABCD123F888E4E97C8751378CCCC4F26 . 3055616 . . [6.00.2900.2873] . . c:\windows\$hf_mig$\KB912812\SP2QFE\mshtml.dll
[-] 2005-11-24 . D3F037F5DA702AE9DDD7663EC9D78BA7 . 3018240 . . [6.00.2900.2802] . . c:\windows\$hf_mig$\KB905915\SP2QFE\mshtml.dll
[-] 2005-10-05 . 3394299FBF1CD0B24089FC762611360B . 3017728 . . [6.00.2900.2769] . . c:\windows\$hf_mig$\KB896688\SP2QFE\mshtml.dll
[-] 2005-07-20 . A14A7A206AE22DE4FE563E44CFC7DDF5 . 3016192 . . [6.00.2900.2722] . . c:\windows\$hf_mig$\KB896727\SP2QFE\mshtml.dll
[-] 2005-05-02 . DCC5C79B99F02EEF8C826B074DBFC222 . 3014144 . . [6.00.2900.2668] . . c:\windows\$hf_mig$\KB883939\SP2QFE\mshtml.dll
[-] 2005-03-10 . 255C2CE965543ABDC3E0A25A5DA1874A . 3011072 . . [6.00.2900.2627] . . c:\windows\$hf_mig$\KB890923\SP2QFE\mshtml.dll
[-] 2005-01-27 . 91C5ADE25BC4E3322577854FA2E7B58B . 3008000 . . [6.00.2900.2604] . . c:\windows\$hf_mig$\KB867282\SP2QFE\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\mshtml.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
[-] 2004-08-04 . B0FEFA816D61EC66AA765DDF534EAB5E . 343040 . . [7.0.2600.2180] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll
[-] 2002-08-29 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCRT.DLL
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll
[-] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
[-] 2008-06-20 . 097722F235A1FB698BF9234E01B52637 . 245248 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\mswsock.dll
[-] 2008-06-20 . 1DFCA7713EA5A70D5D93B436AEA0317A . 245248 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
[-] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
[-] 2004-08-04 . 96353FCECBA774BB8DA74A1C6507015A . 407040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\netlogon.dll
[-] 2009-12-09 . 05BE3D9A71972223AFF6A3C823BA51B1 . 2189312 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\system32\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2009-08-04 . FDE779EA1A564EBFE16F4E0F82B61BAD . 2189312 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
[-] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 . 31914172342BFF330063F343AC6958FE . 2189184 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2007-02-28 . 5A5C8DB4AA962C714C8371FBDF189FC9 . 2182144 . . [5.1.2600.3093] . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
[-] 2007-02-28 . 582A8DBAA58C3B1F176EB2817DAEE77C . 2180352 . . [5.1.2600.3093] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[-] 2006-12-19 . CEF243F6DEFD20BE4ADDE26C7ECACB54 . 2182016 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
[-] 2005-03-02 . 28187802B7C368C0D3AEF7D4C382AABB . 2179456 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
[-] 2003-04-24 . 97EC4AB4650DA6FC521CF16F8A6DDCB0 . 1925760 . . [5.1.2600.1151] . . c:\windows\$xpsp1hfm$\Q811493\ntoskrnl.exe
[-] 2002-08-29 . B9080D97DBD631AADF9128F7316958D2 . 2042240 . . [5.1.2600.1106] . . c:\windows\$NtUninstallQ811493$\ntoskrnl.exe
[-] 2002-02-25 . 257AAFD1F77990355BB6E83650D52680 . 1875584 . . [5.1.2600.31] . . c:\windows\$NtUninstallQ811493_RTM$\ntoskrnl.exe
[-] 2001-08-23 . A29222D5281056E497408FCC9062F749 . 1982208 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ317277$\ntoskrnl.exe
[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\powrprof.dll
[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll
[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\scecli.dll
[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll
[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfc.dll
[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe
[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2003-09-25 . 32173306185F603E75C477E117F3BB8D . 560128 . . [5.1.2600.1255] . . c:\windows\$xpsp1hfm$\KB824141\user32.dll
[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\system32\wininet.dll
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\system32\dllcache\wininet.dll
[-] 2009-12-21 . 5E1F666B8955FD77E65D65C4C4D882A3 . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[-] 2009-10-29 . 6AF52998B90F72FF2325D84D90EDA1CC . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[-] 2009-10-29 . 75240F6EDBCE7B85DF66874407D38A4F . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll
[-] 2009-08-29 . CF0A5FE05BF614C24950D8FAEC1BC309 . 916480 . . [8.00.6001.18828] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll
[-] 2009-08-29 . 972B226BDAD71C55F3CC9A72BBF8F1C1 . 916480 . . [8.00.6001.22918] . . c:\windows\$hf_mig$\KB974455-IE8\SP3QFE\wininet.dll
[-] 2009-07-03 . 7E8A47A2E6561274B83E257CE74803FD . 915456 . . [8.00.6001.18806] . . c:\windows\ie8updates\KB974455-IE8\wininet.dll
[-] 2009-07-03 . 38114DAB42FB2EB84D1726C42B8D80C5 . 915456 . . [8.00.6001.22896] . . c:\windows\$hf_mig$\KB972260-IE8\SP3QFE\wininet.dll
[-] 2009-05-13 . 366C72AF6970DB7BB39AB0142BF09DB5 . 915456 . . [8.00.6001.18783] . . c:\windows\ie8updates\KB972260-IE8\wininet.dll
[-] 2009-05-13 . C0EB6850C8A02A154281749DC61FAF22 . 915456 . . [8.00.6001.22873] . . c:\windows\$hf_mig$\KB969897-IE8\SP3QFE\wininet.dll
[-] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB969897-IE8\wininet.dll
[-] 2009-03-03 . 28775945CCD53DEE280EF58DEA1A94C4 . 826368 . . [7.00.6000.16827] . . c:\windows\ie8\wininet.dll
[-] 2009-03-03 . C8667854873938CA13C986F16B0CD183 . 828416 . . [7.00.6000.21020] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[-] 2008-12-20 . 044E0A4E9FE97C0FB9AFE9C89E2A82E6 . 827904 . . [7.00.6000.20978] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[-] 2008-12-20 . A82935D32D0672E8FF4E91AE398E901C . 826368 . . [7.00.6000.16791] . . c:\windows\ie7updates\KB963027-IE7\wininet.dll
[-] 2008-10-16 . 6741EAF7B7F110E803A6E38F6E5FA6B0 . 826368 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB961260-IE7\wininet.dll
[-] 2008-10-16 . 0D5B75171FF51775B630A431B6C667E8 . 827904 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[-] 2008-08-26 . 77C192FE56A70D7FA0247BA0A6201C32 . 827904 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[-] 2008-08-26 . EF8EBA98145BFA44E80D17A3B3453300 . 826368 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\wininet.dll
[-] 2008-06-23 . 8C13D4A7479FA0A026EDA8ABCE82C0ED . 826368 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\wininet.dll
[-] 2008-06-23 . C66402A06B83B036C195242C0C8CF83C . 827904 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
[-] 2008-04-23 . F6589BE784647CFDBC22EA51CCB1A57A . 826368 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\wininet.dll
[-] 2008-04-23 . 41546B396A526918DA7995A02EA04E51 . 827392 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
[-] 2008-04-14 . 7A4F775ABB2F1C97DEF3E73AFA2FAEDD . 666112 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2008-03-01 . AD21461AEF8244EDEC2EF18E55E1DCF3 . 826368 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\wininet.dll
[-] 2008-03-01 . 6316C2F0C61271C8ABDFF7429174879E . 827392 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
[-] 2007-12-07 . 806D274C9A6C3AAEA5EAE8E4AF841E04 . 824832 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\wininet.dll
[-] 2007-12-07 . B5B411BB229AE6EAD7652A32ED47BFB9 . 825344 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
[-] 2007-10-10 . 30C1E0F34AD2972C72A01DB5C74AB065 . 824832 . . [7.00.6000.16574] . . c:\windows\ie7updates\KB944533-IE7\wininet.dll
[-] 2007-10-10 . 0E5D918F87EFA7D2424D66B499C7EB04 . 825344 . . [7.00.6000.20696] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
[-] 2007-08-22 . 1901AD51DA8BE9F8B38D5D526E5D1788 . 658944 . . [6.00.2900.3199] . . c:\windows\ie7\wininet.dll
[-] 2007-08-22 . A1BC17EB3758D73C3938B2318820F5B4 . 665600 . . [6.00.2900.3199] . . c:\windows\$hf_mig$\KB939653\SP2QFE\wininet.dll
[-] 2007-08-20 . 774435E499D8E9643EC961A6103C361F . 824832 . . [7.00.6000.16544] . . c:\windows\ie7updates\KB942615-IE7\wininet.dll
[-] 2007-08-20 . 357D54BF94FE9D6D8505A96B5C2A3BCA . 825344 . . [7.00.6000.20661] . . c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
[-] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie7updates\KB939653-IE7\wininet.dll
[-] 2007-06-26 . E1A3DD68B5380B360A7310A64D9BB188 . 665600 . . [6.00.2900.3164] . . c:\windows\$hf_mig$\KB937143\SP2QFE\wininet.dll
[-] 2007-04-18 . 4261BA03AFD659DE04F0A17DFBDD454D . 665600 . . [6.00.2900.3121] . . c:\windows\$hf_mig$\KB933566\SP2QFE\wininet.dll
[-] 2007-02-20 . B258C922D22DEEC880B60720531D7627 . 665600 . . [6.00.2900.3086] . . c:\windows\$hf_mig$\KB931768\SP2QFE\wininet.dll
[-] 2007-01-04 . 3FFA1573FC274E5AA7467D03941C45EE . 665088 . . [6.00.2900.3059] . . c:\windows\$hf_mig$\KB928090\SP2QFE\wininet.dll
[-] 2006-10-23 . 231EF4179ACABE486376B5CA893F1076 . 664576 . . [6.00.2900.3020] . . c:\windows\$hf_mig$\KB925454\SP2QFE\wininet.dll
[-] 2006-09-14 . D207370287CF769AEBEBF03837784963 . 664576 . . [6.00.2900.2995] . . c:\windows\$hf_mig$\KB922760\SP2QFE\wininet.dll
[-] 2006-06-23 . 64CE26DB72810B30F7855EA51E1DF836 . 664576 . . [6.00.2900.2937] . . c:\windows\$hf_mig$\KB918899\SP2QFE\wininet.dll
[-] 2006-05-10 . D94CFFDB53E7AC867438E2DFD50E7CBC . 663552 . . [6.00.2900.2904] . . c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
[-] 2006-03-04 . C0845ECBF4F9164E618EE381B79C9032 . 663552 . . [6.00.2900.2861] . . c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
[-] 2005-10-21 . AF785C4947676A7FC1673FDC5C8D0B5B . 661504 . . [6.00.2900.2781] . . c:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll
[-] 2005-09-02 . 97A6FD7CAFD688CF2C78939EBAF0CD0C . 660480 . . [6.00.2900.2753] . . c:\windows\$hf_mig$\KB896688\SP2QFE\wininet.dll
[-] 2005-07-03 . 6E533D155B259EB2363D3E04B5BE309F . 659456 . . [6.00.2900.2713] . . c:\windows\$hf_mig$\KB896727\SP2QFE\wininet.dll
[-] 2005-05-02 . E1E18136F9DD3DF1AD9C82193A5898A6 . 658944 . . [6.00.2900.2668] . . c:\windows\$hf_mig$\KB883939\SP2QFE\wininet.dll
[-] 2005-03-10 . C8663B488996E89A84C3D17C1D12B79E . 657920 . . [6.00.2900.2627] . . c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
[-] 2005-01-27 . A8EAC5330876548E9966A7D13025D196 . 657920 . . [6.00.2900.2598] . . c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\wininet.dll
[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
[-] 2004-08-04 . 92BDF74F12D6CBEC43C94D4B7F804838 . 170496 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\srsvc.dll
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
[-] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\xmlprov.dll
[-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll
[-] 2001-08-23 . 9E415EFDF50F26BCBC97C80F4E6C30CC . 1562112 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ309521$\sfcfiles.dll
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
[-] 2004-08-04 . 3151427DB7D87107D1C5BE58FAC53960 . 59904 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regsvc.dll
[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll
[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll
[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll
[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
[-] 2004-08-04 . 4B8D61792F7175BED48859CC18CE4E38 . 71680 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll
[-] 2001-08-23 . 126D90EE937FFEBACEE30BCA13D92F97 . 39936 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ315000$\ssdpsrv.dll
[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[-] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll
[-] 2001-08-23 . 458635D2E4559526CF9C895340A38702 . 197632 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ311889$\termsrv.dll
[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\appmgmts.dll
[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll
[-] 2004-08-04 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\appmgmts.dll
[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys
[-] 2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
[-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$NtServicePackUninstall$\aec.sys
[-] 2001-08-23 . B45A744CA0A15A59D8B0307CE9741E92 . 122472 . . [5.1.2520.0] . . c:\windows\$NtUninstallQ316397$\aec.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys
[-] 2004-08-04 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\agp440.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ip6fw.sys
[-] 2008-04-14 00:11 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll
[-] 2008-04-14 00:11 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
[-] 2006-11-01 19:17 . 925F8B61ED301A317BA850EBEECBDAA0 . 927504 . . [4.1.0.61] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll
[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
[-] 2004-08-04 . 95FD808E4AC22ABA025A7B3EAC0375D2 . 33792 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll
[-] 2003-10-21 . 41C5F3B926942EBDD35C6BF4154FE5F8 . 32256 . . [5.1.2600.1309] . . c:\windows\$xpsp1hfm$\KB828035\msgsvc.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2005-01-28 18:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2005-01-28 18:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[-] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
[-] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\ServicePackFiles\i386\mspmsnsv.dll
[-] 2009-12-09 . FFDCE1EEA79C678C40237D4E031E5B51 . 2066176 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-08-04 . 363B2BBEE0AEDC9E5433616D0AD0236A . 2066176 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
[-] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 . A25E9B86EFFB2AF33BF51E676B68BFB0 . 2066048 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2007-02-28 . 4D3DBDCCBF97F5BA1E74F322B155C3BA . 2059392 . . [5.1.2600.3093] . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
[-] 2007-02-28 . 515D30E2C90A3665A2739309334C9283 . 2057600 . . [5.1.2600.3093] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[-] 2006-12-19 . BA4B97C00A437C1CC3DA365D93EE1E9D . 2059392 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
[-] 2005-03-02 . D8ABA3EAB509627E707A3B14F00FBB6B . 2056832 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
[-] 2003-04-24 . 46AE6F2D416C39FFDCFC8BCB01203EA3 . 1949440 . . [5.1.2600.1151] . . c:\windows\$xpsp1hfm$\Q811493\ntkrnlpa.exe
[-] 2002-08-29 . 0E8EFB15746878A9B256E75267337233 . 1947904 . . [5.1.2600.1106] . . c:\windows\$NtUninstallQ811493$\ntkrnlpa.exe
[-] 2002-02-25 . 01FD1F7C82B263F1667A1CEA095756C5 . 1897856 . . [5.1.2600.31] . . c:\windows\$NtUninstallQ811493_RTM$\ntkrnlpa.exe
[-] 2001-08-23 . 46E2E3DCF54B819CFB2EBFE48A22B5C9 . 1896704 . . [5.1.2600.0] . . c:\windows\$NtUninstallQ317277$\ntkrnlpa.exe
[-] 2008-04-14 00:12 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
[-] 2008-04-14 00:12 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
[-] 2004-08-04 07:56 . B62F29C00AC55A761B2E45877D85EA0F . 435200 . . [5.1.2400.2180] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll
[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll
[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
[-] 2007-02-05 . 36ACA6CDC19C95FF468A1426EB7F32F0 . 185344 . . [5.1.2600.3077] . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll
[-] 2007-02-05 . ACA5D98663D879C6BAAFCEA7E2F1B710 . 185344 . . [5.1.2600.3077] . . c:\windows\$NtServicePackUninstall$\upnphost.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 17:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2009-12-01 21:29 2166296 —-a-w- c:\program files\myBabylon_English\tbmyB1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyB1.dll" [2009-12-01 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\program files\myBabylon_English\tbmyB1.dll" [2009-12-01 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-30 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-30 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-05 630784]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-11-08 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-07-28 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CompuServe 7.0 Tray Icon.lnk]
backup=c:\windows\pss\CompuServe 7.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Corel MEDIA FOLDERS INDEXER 8.LNK]
backup=c:\windows\pss\Corel MEDIA FOLDERS INDEXER 8.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdBlocker
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
2002-06-18 07:11 69632 —-a-w- c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-03-08 18:38 48280 —-a-w- c:\program files\Common Files\AOL\1116607718\EE\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2002-10-16 14:05 114688 —-a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 07:41 49152 —-a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
2006-03-27 15:57 126104 —-a-w- c:\program files\Common Files\AOL\IPHSend\IPHSend.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JobHisInit]
2001-11-17 02:23 135168 —-a-w- c:\program files\RMClient\JobHisInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA magicolor2300WStatusDisplay]
2003-12-20 03:05 172032 —-a-w- c:\windows\system32\MSTMON_P.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\magicolor 2300WStatusDisplay]
2002-12-21 06:37 159744 —-a-w- c:\windows\system32\MSTMON_J.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaLifeService]
2005-06-03 22:09 110739 ——w- c:\program files\Logitech\MediaLife\MediaLifeService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MplSetUp]
2000-11-05 02:09 40960 —-a-w- c:\program files\RMClient\MplSetUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
2004-04-05 21:33 99480 —-a-w- c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2008-07-19 19:14 214560 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 14:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 15:01 155648 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-07-19 19:14 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WCOLOREAL]
2002-11-27 01:14 131072 —-a-w- c:\program files\Coloreal\COLOREAL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\1116607718\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\America Online 8.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ericom Software\\PowerTerm WebConnect 5.6\\151.203.99.51\\ptermX.exe"=
"c:\\Program Files\\Webs Credits\\TroubleShooter.exe"=
"c:\\Program Files\\Webs Credits\\ToolbarUpdate.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-20 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-20 242696]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-20 308064]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2009-12-24 311568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 13:23]
2010-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 13:23]
2010-03-23 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {7EC816D4-6FC3-4C58-A7DA-A770EE461602} - hxxp://151.203.99.51/Ericom/WebConnect%205.6/web/windows/ptdownloader.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{D09588AA-5560-4240-B2F2-774D78D7E917} - (no file)
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-Easy Synchronization - c:\program files\Logitech\Easy Synchronization\LogitechEasySync.exe
MSConfigStartUp-Logitech Hardware Abstraction Layer - KHALMNPR.EXE
MSConfigStartUp-MemDesktopToolApp - c:\program files\Quicken Medical Expense Manager\MemDesktopToolApp.exe
MSConfigStartUp-My Web Search Bar - c:\progra~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
MSConfigStartUp-Staples Easy Button - c:\program files\Staples Easy Button\EasyButton.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-Windows Registry Repair Pro - c:\program files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-23 16:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f7,5b,f7,aa,4f,40,df,45,94,be,02,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f7,5b,f7,aa,4f,40,df,45,94,be,02,\
[HKEY_USERS\S-1-5-21-1513334473-2246549229-786157266-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2010-03-23 17:03:41
ComboFix-quarantined-files.txt 2010-03-23 21:03
Pre-Run: 35,723,132,928 bytes free
Post-Run: 35,754,135,552 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 35C1A6297BB11C2AFEFCBF871E9E1456
I clicked on a facebook link to you tube. That infected my pc. I was able to download malewarebytes. That found koobface.trace and disabled.securitycenter. I also downloaded stopzilla which found a couple virus's. I was unable to access any anti-virus site so I copied a number of programs on a clean computer and used a flash drive to transfer them. I was able to run system restore via advanced system care. I was able to download AVG which has popped up several times saying a I have a trojan proxy virus. I've used several self help guides via you tube and tech sites. I deleted bill104.exe, ligh, fs1235.dat, brwmark.ini, and fw20.vxd. Nothing seems to be working, things seem to be getting worse.
I wanted to try turning off and on system restore, but when I open it I get a blank screen. File search opens with a blank screen in the left column, search companion. The buttons on stopzilla appear but do not work. I could not even register for this forum. I had to register on a clean computer then log on here. I cannot access my logs in the various anti-virus programs. I tried xp_taskmanager.exe, UnHookExec.inf, and GMER. I'm going to poste my OTL log:
OTL logfile created on: 3/23/2010 11:22:48 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.00 Mb Total Physical Memory | 455.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 1438 1438 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.43 Gb Total Space | 32.57 Gb Free Space | 46.24% Space Free | Partition Type: NTFS
Drive D: | 4.08 Gb Total Space | 0.16 Gb Free Space | 3.85% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 517.22 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 247.22 Mb Total Space | 211.48 Mb Free Space | 85.54% Space Free | Partition Type: FAT
Computer Name: YOUR-RVLNHR6V8D
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/03/20 12:46:00 | 000,177,600 | R— | M] (iS3, Inc.) – C:\Program Files\STOPzilla!\STOPzilla.exe
PRC - [2010/03/19 15:19:16 | 000,555,520 | —- | M] (OldTimer Tools) – C:\downloads\OTL.exe
PRC - [2010/01/07 16:07:10 | 001,394,000 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/03/19 15:19:16 | 000,555,520 | —- | M] (OldTimer Tools) – C:\downloads\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] – – (sdCoreService)
SRV - File not found [On_Demand | Stopped] – – (sdAuxService)
SRV - File not found [On_Demand | Stopped] – – (McSysmon)
SRV - File not found [Unknown | Stopped] – – (McShield)
SRV - File not found [Auto | Stopped] – – (McProxy)
SRV - File not found [On_Demand | Stopped] – – (McODS)
SRV - File not found [Auto | Stopped] – – (McNASvc)
SRV - File not found [Auto | Stopped] – – (mcmscsvc)
SRV - File not found [Auto | Stopped] – – (LBTServ)
SRV - File not found [On_Demand | Stopped] – – (gusvc)
SRV - File not found [Auto | Stopped] – – (AOL ACS)
SRV - [2010/03/20 16:31:58 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/18 15:59:36 | 000,057,344 | R— | M] (iS3, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe – (szserver)
SRV - [2010/01/22 09:56:24 | 000,112,592 | —- | M] (Threat Expert Ltd.) [Auto | Stopped] – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2009/12/24 18:02:30 | 000,311,568 | —- | M] (IObit) [Auto | Stopped] – C:\Program Files\IObit\IObit Security 360\is360srv.exe – (IS360service)
SRV - [2005/11/14 02:06:04 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2004/10/15 16:54:14 | 000,100,016 | —- | M] (America Online, Inc) [Auto | Stopped] – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor)
SRV - [2001/09/25 10:32:50 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Stopped] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2001/08/23 08:00:00 | 000,019,456 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\tcpsvcs.exe – (LPDSVC)
========== Driver Services (SafeList) ==========
DRV - [2010/03/20 16:32:07 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/03/20 16:32:03 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/03/20 16:31:50 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/03/10 11:36:36 | 000,217,032 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2010/02/24 15:06:36 | 000,173,328 | R— | M] (iS3, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\szkgfs.sys – (szkgfs)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R— | M] (iS3 Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\szkg.sys – (szkg5)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R— | M] (iS3 Inc.) [Kernel | Boot | Stopped] – C:\WINDOWS\system32\drivers\is3srv.sys – (is3srv)
DRV - [2009/05/09 01:14:20 | 000,014,736 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nuidfltr.sys – (NuidFltr)
DRV - [2008/06/04 16:54:59 | 000,102,664 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm)
DRV - [2006/04/11 09:21:50 | 000,028,256 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2006/03/22 20:22:00 | 000,328,237 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btaudio.sys – (btaudio)
DRV - [2006/03/22 20:19:04 | 000,851,402 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btkrnl.sys – (BTKRNL)
DRV - [2006/03/22 20:16:52 | 000,030,427 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btport.sys – (BTDriver)
DRV - [2006/03/22 20:16:12 | 000,065,784 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2006/03/22 20:12:12 | 000,045,683 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwhid.sys – (btwhid)
DRV - [2006/03/22 18:45:02 | 000,019,372 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\frmupgr.sys – (DFUBTUSB)
DRV - [2005/11/03 15:18:42 | 000,036,608 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LHidUsbK.sys – (LHidUsbK)
DRV - [2005/10/05 13:00:06 | 000,047,104 | —- | M] (ELTIMA Software) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\vserial.sys – (vserial)
DRV - [2005/10/05 13:00:06 | 000,018,167 | —- | M] (ELTIMA Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\vsb.sys – (vsbus)
DRV - [2004/10/22 11:41:46 | 000,413,824 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nvapu.sys – (nvnforce) Service for NVIDIA® nForce™
DRV - [2004/10/22 11:38:28 | 000,053,376 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nvax.sys – (nvax) Service for NVIDIA® nForce™
DRV - [2004/10/07 21:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2004/10/01 11:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/04 01:29:51 | 000,166,912 | —- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s3gnbm.sys – (S3Psddr)
DRV - [2004/06/10 10:08:09 | 000,010,308 | —- | M] () [Kernel | System | Stopped] – C:\WINDOWS\freedom.backup.dat – (Freedom)
DRV - [2003/07/28 15:19:00 | 001,341,339 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2003/07/09 01:52:02 | 000,020,032 | —- | M] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\MLPTDR_P.SYS – (MLPTDR_P)
DRV - [2003/06/23 12:45:34 | 000,027,650 | —- | M] (America Online) [Kernel | On_Demand | Stopped] – C:\Program Files\America Online 8.0\atwpkt2.sys – (ATWPKT2)
DRV - [2003/03/31 15:29:00 | 000,625,537 | —- | M] (LT) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/01/30 20:30:06 | 000,019,904 | —- | M] (Minolta Co., Ltd.) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\MLPTDR_J.SYS – (MLPTDR_J)
DRV - [2002/11/20 21:08:24 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2002/10/21 14:21:00 | 000,082,784 | —- | M] (VERITAS Software, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys – (drvmcdb)
DRV - [2002/10/15 16:32:16 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2002/09/23 21:37:00 | 000,080,896 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENET.sys – (NVENET)
DRV - [2002/09/06 22:24:00 | 000,013,568 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp)
DRV - [2001/06/04 17:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2010/02/18 15:44:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2010/02/18 15:44:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/20 16:34:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/20 16:23:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/17 09:58:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/18 15:44:35 | 000,000,000 | —D | M]
[2010/03/19 19:07:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions
[2009/07/12 23:23:55 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/02/13 11:29:00 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/03/19 09:41:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\szaa6gq7.default\extensions\staged-xpis
[2010/03/20 17:09:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/07/19 15:12:50 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/03/19 19:04:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/07/19 15:12:38 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/06/04 17:10:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/06/04 17:10:33 | 000,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2009/06/04 17:10:33 | 000,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2009/06/04 17:10:33 | 000,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2009/06/04 17:10:36 | 000,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2009/06/04 17:10:37 | 000,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2003/02/24 16:58:34 | 000,729,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2002/08/29 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D09588AA-5560-4240-B2F2-774D78D7E917} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Ad Blocker Pro Toolbar) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - C:\Program Files\3B Software\3B Ad Blocker Pro\AKToolbar.dll (3B Software)
O3 - HKCU\..\Toolbar\WebBrowser: (myBabylon English Toolbar) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKCU..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=67633 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (Reg Error: Value error.)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Value error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Value error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {7EC816D4-6FC3-4C58-A7DA-A770EE461602} http://151.203.99.51/Ericom/WebConnect%205…tdownloader.cab (PowerTerm Downloader Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/…-131_02-win.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/02/20 13:39:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{0a590710-3029-11da-8102-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{0a590710-3029-11da-8102-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0a590710-3029-11da-8102-00038a000015}\Shell\AutoRun\command - "" = C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\AOLTEMP\setup.exe – [2005/11/01 11:48:44 | 000,142,232 | —- | M] (America Online)
O33 - MountPoints2\{34e34bd6-6d39-11d7-93c5-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{bfd48792-3cc9-11db-8142-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{bfd48792-3cc9-11db-8142-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/03/23 10:25:43 | 001,652,688 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2010/03/23 10:25:43 | 000,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2010/03/23 10:25:43 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2010/03/23 10:25:37 | 000,233,136 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/03/23 10:25:31 | 000,217,032 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/03/23 10:25:31 | 000,088,040 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/03/23 10:25:25 | 000,070,408 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\PC Tools
[2010/03/23 10:25:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/03/22 17:19:12 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/03/22 16:44:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/03/20 17:09:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/20 17:09:08 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/03/20 17:09:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/03/20 17:09:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/03/20 16:32:04 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/20 16:23:53 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/03/20 16:23:36 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/20 16:23:27 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/20 16:23:24 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/20 16:23:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/20 16:23:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/20 16:22:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/20 16:19:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/20 16:19:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/20 16:19:12 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/20 16:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/20 14:08:35 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/03/19 23:10:04 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2010/03/19 19:37:55 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2010/03/19 19:37:50 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\hpojwia.dll
[2010/03/19 19:37:50 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2010/03/19 19:37:50 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2010/03/19 19:37:43 | 000,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2010/03/19 19:37:42 | 000,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2010/03/19 19:07:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\AVP9
[2010/03/19 10:16:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2010/03/19 10:16:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/19 10:16:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/19 10:16:29 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/19 10:16:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/18 09:47:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/03/18 09:45:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2010/03/18 09:45:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/03/17 16:39:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Threat Expert
[2010/03/17 16:08:36 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/03/17 16:08:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/03/10 09:15:58 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/03/05 18:16:42 | 000,017,408 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2010/03/05 18:14:16 | 000,442,368 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2010/03/05 18:13:44 | 000,540,672 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2010/02/26 14:28:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Temp
[2010/02/24 15:06:36 | 000,173,328 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\drivers\SZKGFS.sys
[2010/02/07 09:28:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/07 09:23:25 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/03/23 11:09:36 | 000,001,016 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/03/23 11:01:31 | 000,637,024 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/23 10:54:28 | 000,001,180 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/23 10:53:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/23 10:53:26 | 001,907,560 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/23 10:52:39 | 011,010,048 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/03/23 10:52:39 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/03/23 10:25:30 | 000,001,654 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/03/23 09:38:42 | 000,000,315 | —- | M] () – C:\Documents and Settings\Owner\Desktop\regtool.vbs
[2010/03/23 09:35:16 | 000,000,610 | —- | M] () – C:\Documents and Settings\Owner\Desktop\UnHookExec.inf
[2010/03/23 09:28:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/23 09:28:16 | 003,715,890 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/03/23 08:39:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/23 08:20:17 | 057,556,517 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/23 08:17:36 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/03/23 08:17:34 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/21 16:06:05 | 000,000,016 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2010/03/21 10:48:39 | 000,000,265 | —- | M] () – C:\Documents and Settings\Owner\Desktop\The official U.S. time - clock.url
[2010/03/20 16:32:07 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/20 16:32:04 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/20 16:32:03 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/20 16:31:50 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/20 16:23:37 | 000,001,518 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/20 16:23:23 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/20 16:23:13 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/03/20 16:23:13 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/03/20 16:23:13 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/03/20 14:04:32 | 000,001,069 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/20 11:13:48 | 000,000,725 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/20 10:45:59 | 000,536,914 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/20 10:45:59 | 000,451,342 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/20 10:45:59 | 000,075,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/19 23:11:35 | 000,270,336 | -H– | M] () – C:\SZKGFS.dat
[2010/03/19 16:13:38 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/19 16:13:38 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/03/18 21:00:22 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/03/18 10:47:00 | 000,000,270 | —- | M] () – C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2010/03/17 15:10:51 | 000,026,624 | —- | M] () – C:\Documents and Settings\Owner\My Documents\faith.doc
[2010/03/17 11:32:34 | 000,000,002 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\010112010146111103.xxe
[2010/03/14 07:55:29 | 000,002,360 | —- | M] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2010/03/10 11:36:36 | 000,217,032 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/03/06 16:28:09 | 000,113,048 | —- | M] () – C:\Documents and Settings\Owner\My Documents\brethren-we-have-met-to-worship[1].pdf
[2010/03/05 18:16:42 | 000,017,408 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2010/03/05 18:14:16 | 000,442,368 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2010/03/05 18:13:44 | 000,540,672 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2010/03/04 10:06:53 | 000,002,257 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/03/02 10:28:07 | 000,897,520 | —- | M] () – C:\Documents and Settings\Owner\My Documents\2008Platform[1].pdf
[2010/02/25 18:33:41 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/02/25 10:06:34 | 000,000,639 | —- | M] () – C:\Documents and Settings\Owner\Desktop\lighthouse stationary2.doc.lnk
[2010/02/24 19:01:08 | 000,035,840 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Local church articles of faith from other churches in New England.doc
[2010/02/24 15:15:44 | 000,026,112 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Crabby Old Man.doc
[2010/02/24 15:06:36 | 000,173,328 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\drivers\SZKGFS.sys
[2010/02/23 10:49:57 | 000,031,232 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Hotel and Restaurant Suggestions.doc
[2010/02/23 10:17:38 | 006,560,768 | —- | M] () – C:\Documents and Settings\Owner\My Documents\IIWWPhotos3eReichRevueLife1.pps
[2010/02/22 14:43:00 | 000,000,754 | —- | M] () – C:\Documents and Settings\All Users\Desktop\IObit Security 360.lnk
[2010/02/21 14:08:01 | 000,083,968 | —- | M] () – C:\Documents and Settings\Owner\My Documents\GIBF meeting letter.doc
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/23 11:08:58 | 000,001,016 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/03/23 10:25:44 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/03/23 10:25:43 | 001,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2010/03/23 10:25:43 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2010/03/23 10:25:43 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2010/03/23 10:25:43 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2010/03/23 10:25:37 | 000,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/03/23 10:25:31 | 000,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/03/23 10:25:31 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctcore.cat
[2010/03/23 10:25:30 | 000,001,654 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/03/23 10:25:25 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/03/23 09:56:50 | 000,000,610 | —- | C] () – C:\Documents and Settings\Owner\Desktop\UnHookExec.inf
[2010/03/23 09:56:46 | 000,000,315 | —- | C] () – C:\Documents and Settings\Owner\Desktop\regtool.vbs
[2010/03/20 16:23:37 | 000,001,518 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/20 16:23:23 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/20 16:23:13 | 057,556,517 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/20 16:23:13 | 006,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/03/20 16:23:13 | 000,492,629 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/03/20 16:23:13 | 000,142,495 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/03/19 23:11:35 | 000,270,336 | -H– | C] () – C:\SZKGFS.dat
[2010/03/19 19:37:50 | 000,018,411 | —- | C] () – C:\WINDOWS\System32\hpo5500a.aio
[2010/03/19 19:37:50 | 000,018,411 | —- | C] () – C:\WINDOWS\System32\hpo5400a.aio
[2010/03/19 19:37:50 | 000,018,411 | —- | C] () – C:\WINDOWS\System32\hpo5300a.aio
[2010/03/19 17:50:32 | 000,000,016 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/03/19 10:16:39 | 000,000,725 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/17 15:10:51 | 000,026,624 | —- | C] () – C:\Documents and Settings\Owner\My Documents\faith.doc
[2010/03/17 11:32:34 | 000,000,002 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\010112010146111103.xxe
[2010/03/06 16:28:08 | 000,113,048 | —- | C] () – C:\Documents and Settings\Owner\My Documents\brethren-we-have-met-to-worship[1].pdf
[2010/03/05 10:59:14 | 000,046,972 | —- | C] () – C:\WINDOWS\System32\LSBTrans.TTF
[2010/03/05 10:59:14 | 000,045,384 | —- | C] () – C:\WINDOWS\System32\LSBGreek.TTF
[2010/03/05 10:59:14 | 000,039,704 | —- | C] () – C:\WINDOWS\System32\LSBHebre.TTF
[2010/03/02 10:28:07 | 000,897,520 | —- | C] () – C:\Documents and Settings\Owner\My Documents\2008Platform[1].pdf
[2010/02/25 10:06:34 | 000,000,639 | —- | C] () – C:\Documents and Settings\Owner\Desktop\lighthouse stationary2.doc.lnk
[2010/02/24 18:14:47 | 000,035,840 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Local church articles of faith from other churches in New England.doc
[2010/02/24 15:15:43 | 000,026,112 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Crabby Old Man.doc
[2010/02/23 10:17:34 | 006,560,768 | —- | C] () – C:\Documents and Settings\Owner\My Documents\IIWWPhotos3eReichRevueLife1.pps
[2010/02/21 11:44:48 | 000,031,232 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Hotel and Restaurant Suggestions.doc
[2010/02/21 11:34:29 | 000,083,968 | —- | C] () – C:\Documents and Settings\Owner\My Documents\GIBF meeting letter.doc
[2010/02/05 14:04:41 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2009/12/10 17:51:24 | 000,000,026 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/10 17:50:51 | 000,000,229 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/10 17:50:51 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/12/10 17:48:39 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2009/12/10 17:48:39 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2009/12/10 17:48:34 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2009/12/10 17:48:32 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/12/10 17:46:03 | 000,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2009/11/04 16:04:37 | 000,000,326 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\PrimoPDFSet.xml
[2009/10/17 11:20:49 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/24 16:21:21 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\U25STORE.DLL
[2009/07/24 16:21:21 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\U25TOTAL.DLL
[2009/07/24 16:21:20 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\U25DTS.DLL
[2009/07/24 16:21:19 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\IMPLODE.DLL
[2009/05/22 16:30:08 | 000,006,910 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PrimoPDFSet.xml
[2009/05/22 16:17:16 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/04/27 00:13:36 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2008/12/09 12:34:24 | 000,004,874 | —- | C] () – C:\Documents and Settings\Owner\Application Data\SAS7_000.DAT
[2008/08/31 19:52:46 | 000,000,050 | —- | C] () – C:\WINDOWS\Winamp.ini
[2008/08/31 19:52:43 | 000,000,041 | —- | C] () – C:\WINDOWS\winampa.ini
[2007/11/28 15:36:48 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/07/25 17:08:39 | 000,002,360 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2007/07/07 12:19:19 | 000,087,808 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2007/06/27 12:18:31 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/05/29 18:03:24 | 000,000,406 | —- | C] () – C:\WINDOWS\barcode.ini
[2007/04/27 19:10:49 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/04/10 16:48:17 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\sh33w32.dll
[2006/07/31 01:59:36 | 000,000,338 | —- | C] () – C:\WINDOWS\scrub2k.ini
[2006/06/13 08:21:40 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/04/05 09:44:48 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2006/03/22 20:28:58 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/05/20 12:37:41 | 000,000,101 | —- | C] () – C:\WINDOWS\upst.ini
[2005/05/20 12:37:41 | 000,000,025 | —- | C] () – C:\WINDOWS\atid.ini
[2005/04/19 18:19:00 | 000,000,319 | —- | C] () – C:\WINDOWS\SWWATER.INI
[2005/04/09 15:22:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\RPCS.ini
[2005/04/09 15:21:46 | 000,027,489 | —- | C] () – C:\WINDOWS\RicDB.ini
[2005/04/09 15:21:34 | 000,000,226 | —- | C] () – C:\WINDOWS\PMJobCli.ini
[2005/04/09 15:21:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\PMObservps.dll
[2005/04/09 15:21:28 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\rpnv2ui.dll
[2005/04/09 15:21:28 | 000,270,336 | R— | C] () – C:\WINDOWS\System32\rpnv2job.dll
[2005/04/09 15:21:28 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RLPR.dll
[2005/04/09 15:21:28 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\rtcpf.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApisv.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApipt.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApipl.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApino.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApinl.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApiit.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApihu.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApifr.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApifi.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApies.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApide.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApida.dll
[2005/04/09 15:21:26 | 000,028,672 | —- | C] () – C:\WINDOWS\PMApics.dll
[2005/04/09 15:21:26 | 000,012,027 | —- | C] () – C:\WINDOWS\PMRicMb.ini
[2005/04/09 15:21:26 | 000,006,702 | —- | C] () – C:\WINDOWS\PMRicPMb.ini
[2005/04/09 15:21:26 | 000,005,390 | —- | C] () – C:\WINDOWS\PMPrtMb.ini
[2005/04/09 15:21:26 | 000,003,611 | —- | C] () – C:\WINDOWS\PMRicFMb.ini
[2005/04/09 15:21:26 | 000,003,005 | —- | C] () – C:\WINDOWS\PMDvPrn.ini
[2005/04/09 15:21:26 | 000,002,087 | —- | C] () – C:\WINDOWS\PMDvDev.ini
[2005/04/09 15:21:26 | 000,002,047 | —- | C] () – C:\WINDOWS\PMDIOMb.ini
[2005/04/09 15:21:26 | 000,002,036 | —- | C] () – C:\WINDOWS\PMHostMb.ini
[2005/04/09 15:21:26 | 000,001,885 | —- | C] () – C:\WINDOWS\PMPSIOMb.ini
[2005/04/09 15:21:26 | 000,001,727 | —- | C] () – C:\WINDOWS\PMRicSMb.ini
[2005/04/09 15:21:26 | 000,001,706 | —- | C] () – C:\WINDOWS\PMRicCMb.ini
[2005/04/09 15:21:26 | 000,001,494 | —- | C] () – C:\WINDOWS\PMMib2Mb.ini
[2005/04/09 15:21:26 | 000,001,143 | —- | C] () – C:\WINDOWS\PMDPIMb.ini
[2005/04/09 15:21:26 | 000,001,094 | —- | C] () – C:\WINDOWS\PMAxsMb.ini
[2005/04/09 15:21:26 | 000,000,994 | —- | C] () – C:\WINDOWS\PMDvFax.ini
[2005/04/09 15:21:26 | 000,000,842 | —- | C] () – C:\WINDOWS\PMDvScan.ini
[2005/04/09 15:21:26 | 000,000,423 | —- | C] () – C:\WINDOWS\PMDvCopy.ini
[2005/04/09 15:21:26 | 000,000,332 | —- | C] () – C:\WINDOWS\PMSnmpMb.ini
[2005/04/07 08:17:31 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\AnexBC.dll
[2005/02/17 12:41:32 | 000,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2004/06/10 09:38:49 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/06/04 19:12:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/02/03 16:30:53 | 000,108,032 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/12/23 15:58:36 | 000,002,297 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/10/08 22:58:22 | 000,025,556 | —- | C] () – C:\WINDOWS\MSTMON_P.INI
[2003/09/23 15:57:37 | 000,000,751 | —- | C] () – C:\WINDOWS\Bti.ini
[2003/09/23 15:57:35 | 000,116,640 | —- | C] () – C:\WINDOWS\System32\Ptsaci40.dll
[2003/08/21 21:51:24 | 000,018,130 | —- | C] () – C:\WINDOWS\MSUMLT_P.INI
[2003/08/08 15:40:22 | 000,000,164 | —- | C] () – C:\WINDOWS\ImportClient.INI
[2003/06/25 16:21:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/06/25 14:49:03 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS2v.DLL
[2003/05/04 10:25:28 | 000,000,070 | —- | C] () – C:\WINDOWS\24039AE7.ini
[2003/04/19 20:03:22 | 000,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2003/04/19 20:03:22 | 000,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2003/04/19 20:01:37 | 000,000,242 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/02/21 12:47:56 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/02/21 12:47:19 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\iAlmcoin.dll
[2003/02/20 20:03:14 | 000,024,548 | —- | C] () – C:\WINDOWS\MSTMON_J.INI
[2003/02/20 15:11:52 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/02/20 15:09:09 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/02/20 15:09:09 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/02/20 14:57:26 | 000,000,396 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/02/20 14:57:18 | 000,000,792 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/02/20 14:52:14 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/02/20 14:19:01 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/02/20 14:08:09 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2003/02/20 13:57:23 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/02/20 13:57:23 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/02/20 13:57:05 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/02/20 13:42:09 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/02/20 12:28:42 | 000,000,573 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/16 21:30:34 | 001,617,920 | —- | C] () – C:\WINDOWS\System32\MSTMON_J.DLL
[2003/01/07 19:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/20 22:38:22 | 000,018,130 | —- | C] () – C:\WINDOWS\MSUMLT_J.INI
[2002/12/13 22:32:52 | 000,000,141 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/09/01 02:33:58 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\VxDMDcDlg.dll
[2001/08/14 22:47:08 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== Alternate Data Streams ==========
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >