OTL logfile created on: 7/6/2010 9:44:44 PM - Run 1
OTL by OldTimer - Version 3.2.7.1 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.49 Gb Total Space | 45.86 Gb Free Space | 61.57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D92CJZ11
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe (Skype Technologies S.A.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\MSK\msksrver.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
PRC - C:\Program Files\SiteAdvisor\6172\SiteAdv.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
PRC - C:\Program Files\j2 Messenger 4.2\J2GTray.exe (j2 Global Communications, Inc.)
PRC - C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe (j2 Global Communications, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\ESPNRunTime\DIGServices.exe (Walt Disney Internet Group)
PRC - C:\Program Files\DIGStream\digstream.exe (Walt Disney Internet Group)
PRC - C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
PRC - C:\WINDOWS\vsnpstd.exe ()
PRC - C:\Program Files\Lexmark X5100 Series\lxbabmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
PRC - C:\WINDOWS\SYSTEM32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Spyware Doctor\PCTGMhk.dll (PC Tools)
MOD - C:\Program Files\SiteAdvisor\6172\saHook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MBackMonitor) – C:\Program Files\McAfee\MBK\MBackMonitor.exe (McAfee)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (NMSSvc) Intel® – C:\WINDOWS\SYSTEM32\NMSSvc.Exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (WinDriver6) – C:\WINDOWS\System32\drivers\windrvr6.sys File not found
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (SSKBFD) – C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (SSIDRV) – C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSHRMD) – C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSFS0BB9) – C:\WINDOWS\SYSTEM32\Drivers\SSFS0BB9.SYS (Webroot Software Inc (www.webroot.com))
DRV - (elagopro) – C:\WINDOWS\SYSTEM32\DRIVERS\elagopro.sys (Gteko Ltd.)
DRV - (elaunidr) – C:\WINDOWS\SYSTEM32\DRIVERS\elaunidr.sys (Gteko Ltd.)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ()
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys ()
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (PortlUSB) – C:\WINDOWS\SYSTEM32\DRIVERS\SiriusUSB.sys (Sirius, Inc.)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (snpstd) – C:\WINDOWS\SYSTEM32\DRIVERS\snpstd.sys ()
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (HSFHWBS2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
DRV - (NMSCFG) – C:\WINDOWS\SYSTEM32\DRIVERS\NMSCFG.SYS (Intel Corporation)
DRV - (dvd_2K) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (cdudf_xp) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (UdfReadr_xp) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (ati2mtaa) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtaa.sys (ATI Technologies Inc.)
DRV - (emu10k) Creative SB Live! Value (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\emu10k1f.sys (Creative Technology Ltd.)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\sfman.sys (Creative Technology Ltd.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (hpt3xx) – C:\WINDOWS\System32\DRIVERS\hpt3xx.sys (HighPoint Technologies, Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (V124) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_V124.sys (Conexant)
DRV - (Tones) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_TONE.sys (Conexant)
DRV - (hsf_msft) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_MSFT.sys (Conexant)
DRV - (SpeakerPhone) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_SPKP.sys (Conexant)
DRV - (Rksample) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_SAMP.sys (Conexant)
DRV - (K56) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_K56K.sys (Conexant)
DRV - (Fallback) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FALL.sys (Conexant)
DRV - (SoftFax) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FAXX.sys (Conexant)
DRV - (Fsks) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FSKS.sys (Conexant)
DRV - (basic2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_BSC2.sys (Conexant)
DRV - (nv4) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4.SYS (NVIDIA Corporation)
DRV - (ati2mpaa) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mpaa.sys (ATI Technologies Inc.)
DRV - (ctljystk) – C:\WINDOWS\SYSTEM32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\ctlface.sys (Creative Technology Ltd.)
DRV - (ndiscm) – C:\WINDOWS\SYSTEM32\DRIVERS\Net4100.sys (Motorola Incorporated)
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PfModNT.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[2009/12/18 14:17:24 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2009/12/18 14:17:24 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
O1 HOSTS File: ([2007/12/17 05:02:10 | 000,000,022 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll ()
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\realplayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo!)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll (Yontoo Technology, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll ()
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
O4 - HKLM..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [apcqtqro] C:\Documents and Settings\User\Local Settings\Application Data\fjtqcvbiq\wfjakontssd.exe File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe (Walt Disney Internet Group)
O4 - HKLM..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe (Walt Disney Internet Group)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [j2 4.2] C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe (j2 Global Communications, Inc.)
O4 - HKLM..\Run: [kejpqqpu] C:\Documents and Settings\User\Local Settings\Application Data\oewrplgpm\caigbkatssd.exe File not found
O4 - HKLM..\Run: [Lexmark X5100 Series] C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\SYSTEM32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [sctfmran] C:\Documents and Settings\LocalService\Local Settings\Application Data\ilkaovrnf\skcbvxntssd.exe File not found
O4 - HKLM..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe ()
O4 - HKLM..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [apcqtqro] C:\Documents and Settings\User\Local Settings\Application Data\fjtqcvbiq\wfjakontssd.exe File not found
O4 - HKCU..\Run: [EasyLinkAdvisor] C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
O4 - HKCU..\Run: [kejpqqpu] C:\Documents and Settings\User\Local Settings\Application Data\oewrplgpm\caigbkatssd.exe File not found
O4 - HKCU..\Run: [Microsoft Location Finder] C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe File not found
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\j2 4.2.lnk = C:\Program Files\j2 Messenger 4.2\J2GTray.exe (j2 Global Communications, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/04/20 20:35:37 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/04/20 20:35:37 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/04/20 20:35:37 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/04/20 20:35:37 | 000,000,000 | —D | M]
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo!)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (America Online, Inc.)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab (Reg Error: Key error.)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1150326369750 (MUWebControl Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6}
http://www.nick.com/common/groove/gx/GrooveAX28.cab (Groove Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…7844.8042708333 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
http://download.mcafee.com/molbin/iss-loc/…284/mcfscan.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\siteadvisor {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll ()
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - C:\WINDOWS\System32\WRLogonNtf.dll (Webroot Software, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/11/15 08:31:14 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ctmp3 - C:\WINDOWS\SYSTEM32\ctmp3.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\MSG711.ACM (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\MSG723.ACM (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\MSGSM32.ACM (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\MSACM32.DRV (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (76293329439948800)
========== Files/Folders - Created Within 30 Days ==========
[2010/07/06 21:42:57 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/07/06 12:31:54 | 000,000,000 | —D | C] – C:\Program Files\HiJack This
[2010/07/05 20:52:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Threat Expert
[2010/07/05 20:33:15 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2010/07/05 20:33:14 | 001,652,688 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2010/07/05 20:33:14 | 000,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2010/07/05 20:26:35 | 000,233,136 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/07/05 20:26:13 | 000,218,592 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/07/05 20:26:13 | 000,088,040 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/07/05 20:26:02 | 000,063,360 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/07/05 20:25:51 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2010/07/05 20:25:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/07/05 20:25:51 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\PC Tools
[2010/07/05 20:25:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/07/05 01:46:26 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/04 22:34:54 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/07/04 21:50:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ilkaovrnf
[2010/07/04 21:49:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/07/04 14:03:21 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/02 16:24:38 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/02 16:24:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/02 15:59:22 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vfwwdm32.dll
[2010/07/02 15:59:22 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010/07/02 15:57:01 | 000,245,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\Unicows.dll
[2010/07/02 15:57:01 | 000,036,864 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd.dll
[2010/07/02 15:56:59 | 000,036,864 | —- | C] ( ) – C:\WINDOWS\System32\dsnpstd.ax
[2010/07/02 15:56:58 | 000,057,344 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd.dll
[2010/07/02 15:56:57 | 000,000,000 | —D | C] – C:\WINDOWS\Options
[2010/07/02 15:56:57 | 000,000,000 | —D | C] – C:\Program Files\GE
[2010/07/02 15:18:59 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\skypePM
[2010/07/02 15:18:04 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Skype
[2010/07/02 15:17:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/07/02 15:17:10 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/07/02 15:17:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2010/06/28 13:32:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\oewrplgpm
[2010/06/23 13:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\fjtqcvbiq
[2010/06/10 21:41:09 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/08 19:07:58 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\John L Sullivan statue
[2002/10/13 13:43:40 | 000,059,392 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[477 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[20 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/07/06 21:43:04 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/07/06 21:31:22 | 007,340,032 | —- | M] () – C:\Documents and Settings\User\ntuser.dat
[2010/07/06 21:00:14 | 000,002,491 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word (2).lnk
[2010/07/06 20:16:49 | 000,000,666 | —- | M] () – C:\WINDOWS\LEXSTAT.INI
[2010/07/06 17:04:50 | 000,002,489 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel (2).lnk
[2010/07/06 07:55:32 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/07/06 07:47:04 | 000,032,779 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/07/06 07:44:03 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/06 07:43:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/07/06 07:43:55 | 2146,508,800 | -HS- | M] () – C:\hiberfil.sys
[2010/07/06 07:42:47 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\User\NTUSER.INI
[2010/07/05 23:10:48 | 000,001,089 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/07/05 20:56:59 | 000,063,360 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/07/05 20:56:57 | 000,218,592 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/07/05 20:26:07 | 000,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/07/05 20:18:26 | 000,000,066 | —- | M] () – C:\Program Files\wp4.dat
[2010/07/05 20:18:26 | 000,000,001 | —- | M] () – C:\Program Files\wp3.dat
[2010/07/05 20:18:20 | 000,097,792 | —- | M] () – C:\Program Files\alggui.exe
[2010/07/05 20:07:10 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/07/05 04:00:00 | 000,001,626 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeper_L2D3914890E8D46FB9A1B5E99D743E0A9.job
[2010/07/05 01:46:54 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/04 22:35:16 | 000,001,100 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/07/04 12:36:50 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/02 15:19:02 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/07/01 01:00:00 | 000,000,330 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2010/06/29 21:55:30 | 000,026,102 | —- | M] () – C:\Documents and Settings\User\My Documents\flower quote.pdf
[2010/06/27 17:54:27 | 000,020,992 | —- | M] () – C:\Documents and Settings\User\My Documents\Our love is unconditional I cross my heart.doc
[2010/06/22 22:14:24 | 000,020,480 | —- | M] () – C:\Documents and Settings\User\My Documents\basketball letter.doc
[2010/06/15 01:00:00 | 000,000,338 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2010/06/11 03:26:14 | 000,299,640 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 03:11:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/07 11:37:23 | 006,393,856 | —- | M] () – C:\Documents and Settings\User\My Documents\My Money.mny
[2010/06/07 11:37:16 | 006,395,800 | R— | M] () – C:\Documents and Settings\User\My Documents\My Money Backup.mbf
[2010/06/07 11:27:43 | 000,002,399 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Money 2002 (2).lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[477 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[20 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/05 20:33:15 | 001,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2010/07/05 20:33:15 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/07/05 20:33:15 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2010/07/05 20:33:15 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2010/07/05 20:33:15 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2010/07/05 20:26:35 | 000,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/07/05 20:26:13 | 000,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/07/05 20:26:13 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctcore.cat
[2010/07/05 20:26:07 | 000,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/07/05 20:26:02 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/07/05 20:18:20 | 000,097,792 | —- | C] () – C:\Program Files\alggui.exe
[2010/07/05 19:45:35 | 000,000,066 | —- | C] () – C:\Program Files\wp4.dat
[2010/07/05 19:45:35 | 000,000,001 | —- | C] () – C:\Program Files\wp3.dat
[2010/07/04 22:35:16 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/02 15:57:01 | 000,299,776 | —- | C] () – C:\WINDOWS\System32\drivers\snpstd.sys
[2010/07/02 15:57:01 | 000,040,960 | —- | C] () – C:\WINDOWS\vsnpstd.exe
[2010/07/02 15:57:00 | 000,015,541 | —- | C] () – C:\WINDOWS\snpstd.ini
[2010/07/02 15:57:00 | 000,013,023 | —- | C] () – C:\WINDOWS\snpstd.src
[2010/07/02 15:56:59 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\dsnpstd.dll
[2010/07/02 15:56:57 | 000,040,960 | —- | C] () – C:\WINDOWS\CleanDev.exe
[2010/07/02 15:19:02 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/07/02 15:17:18 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/06/29 21:55:29 | 000,026,102 | —- | C] () – C:\Documents and Settings\User\My Documents\flower quote.pdf
[2010/06/27 17:54:25 | 000,020,992 | —- | C] () – C:\Documents and Settings\User\My Documents\Our love is unconditional I cross my heart.doc
[2010/06/21 12:54:27 | 000,020,480 | —- | C] () – C:\Documents and Settings\User\My Documents\basketball letter.doc
[2008/04/13 17:22:11 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/10/15 19:01:54 | 000,026,424 | —- | C] () – C:\WINDOWS\System32\wrlzma.dll
[2007/05/12 19:35:32 | 000,000,000 | —- | C] () – C:\WINDOWS\pcf.INI
[2007/01/09 17:16:39 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/01/08 19:50:12 | 000,000,000 | —- | C] () – C:\WINDOWS\homeDVD-Movies4.INI
[2007/01/08 19:42:09 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2007/01/08 19:37:00 | 000,001,122 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2006/12/31 21:34:34 | 000,000,000 | —- | C] () – C:\WINDOWS\iplayer.INI
[2006/10/30 00:11:25 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/05/13 21:23:14 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2006/02/26 16:53:56 | 000,001,247 | —- | C] () – C:\WINDOWS\hegames.ini
[2005/09/25 18:22:19 | 000,000,317 | —- | C] () – C:\WINDOWS\KA.INI
[2005/04/30 21:28:45 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2005/04/30 21:25:50 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS6d.DLL
[2005/01/27 19:33:31 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\Ultra.dll
[2004/07/14 20:04:34 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/03/24 20:11:08 | 000,000,072 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2004/03/20 16:13:22 | 000,000,452 | —- | C] () – C:\WINDOWS\tsac.ini
[2004/03/19 14:34:59 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/02/14 18:23:38 | 000,000,099 | —- | C] () – C:\WINDOWS\CTRec.INI
[2004/01/10 18:00:53 | 000,000,089 | —- | C] () – C:\WINDOWS\Sierra.ini
[2003/10/25 12:53:06 | 000,000,004 | —- | C] () – C:\WINDOWS\info147.sys
[2003/09/01 10:01:40 | 000,000,141 | —- | C] () – C:\WINDOWS\asym.ini
[2003/08/24 10:31:43 | 000,002,552 | —- | C] () – C:\WINDOWS\WAVEMIX.INI
[2003/08/24 10:31:40 | 000,000,225 | —- | C] () – C:\WINDOWS\QTW.INI
[2003/04/06 15:05:27 | 000,000,666 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2003/04/06 15:04:46 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\LXBALCNP.DLL
[2003/04/06 15:04:46 | 000,000,188 | —- | C] () – C:\WINDOWS\System32\lxbacoin.ini
[2003/02/17 20:46:02 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/02/11 16:44:11 | 000,000,244 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/02/11 16:43:44 | 000,001,303 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/02/11 16:43:44 | 000,000,930 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/01/01 17:05:34 | 000,000,056 | —- | C] () – C:\WINDOWS\cglp.ini
[2002/12/01 23:38:00 | 000,027,292 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2002/11/02 10:39:38 | 000,000,587 | —- | C] () – C:\WINDOWS\VTruck3.ini
[2002/11/02 10:34:53 | 000,000,549 | —- | C] () – C:\WINDOWS\VTruck2.ini
[2002/11/02 10:30:31 | 000,000,515 | —- | C] () – C:\WINDOWS\VTruck1.ini
[2002/10/13 13:55:18 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/10/13 13:43:14 | 000,000,231 | —- | C] () – C:\WINDOWS\ac3api.ini
[2002/10/13 13:42:41 | 000,000,184 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2002/10/13 13:38:03 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/10/13 12:15:38 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/02/06 10:04:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\NMSInst.dll
[2002/01/21 16:17:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PROInst.dll
[2001/11/15 09:19:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2001/08/18 07:00:00 | 000,249,270 | —- | C] () – C:\WINDOWS\System32\_006164_.tmp.dll
[2001/08/18 07:00:00 | 000,022,040 | —- | C] () – C:\WINDOWS\System32\_006132_.tmp.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/11 00:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll
[1997/11/17 17:13:16 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
========== LOP Check ==========
[2009/06/16 07:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/05/14 13:43:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/05/14 13:44:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2002/10/13 13:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/10/19 18:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2006/02/01 21:55:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESPN
[2008/03/19 17:42:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\j2 Messenger 4.2 Setup
[2006/03/31 00:02:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MCA49.tmp
[2008/07/29 14:29:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sirius
[2010/04/19 14:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2010/07/06 21:36:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/16 07:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/12/25 11:32:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/27 03:41:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/01/08 12:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\acccore
[2004/09/24 18:22:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aim
[2010/05/05 23:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Blackberry Desktop
[2004/07/29 19:12:01 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\InterVideo
[2008/03/19 17:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\j2 Messenger
[2006/03/03 09:07:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Leadertech
[2006/03/12 01:33:36 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Musicmatch
[2009/04/29 11:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Research In Motion
[2008/03/02 11:16:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sammsoft
[2007/01/09 17:31:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sirius
[2007/12/01 14:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Snapfish
[2010/05/06 07:29:13 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Uniblue
[2009/01/16 01:54:06 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Viewpoint
[2002/10/22 14:53:39 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2010/06/15 01:00:00 | 000,000,338 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2010/07/01 01:00:00 | 000,000,330 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2010/07/05 04:00:00 | 000,001,626 | —- | M] () – C:\WINDOWS\Tasks\wrSpySweeper_L2D3914890E8D46FB9A1B5E99D743E0A9.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/10/14 12:00:47 | 000,000,000 | -H– | M] () – C:\.protected
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2004/09/09 22:53:01 | 000,000,211 | RHS- | M] () – C:\BOOT.INI
[2001/11/14 17:35:22 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2007/10/16 09:42:07 | 000,000,754 | —- | M] () – C:\ComboFix-quarantined-files.txt
[2007/10/16 09:42:07 | 000,009,523 | —- | M] () – C:\ComboFix.txt
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2002/10/13 12:18:28 | 000,004,555 | RH– | M] () – C:\DELL.SDR
[2009/10/06 22:00:50 | 000,003,022 | —- | M] () – C:\devicetable.log
[2007/11/06 08:55:49 | 000,000,352 | —- | M] () – C:\firstrun2.log
[2010/07/06 07:43:55 | 2146,508,800 | -HS- | M] () – C:\hiberfil.sys
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/05/14 13:43:50 | 000,003,209 | -H– | M] () – C:\IPH.PH
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/09/09 22:42:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/11/19 11:19:32 | 000,250,032 | RHS- | M] () – C:\NTLDR
[2010/07/06 21:49:36 | 419,430,400 | -HS- | M] () – C:\pagefile.sys
[2007/11/09 21:30:12 | 000,002,090 | —- | M] () – C:\rapport.txt
[2007/11/06 08:58:46 | 000,000,497 | —- | M] () – C:\RVAXO-results.log
[2008/06/26 13:07:27 | 003,352,576 | —- | M] () – C:\S50main.mi4
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2004/06/07 01:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPD6d.DLL
[2004/06/07 01:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPP6d.DLL
[2002/11/15 09:58:04 | 000,077,824 | —- | M] (Lexmark International) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\LXBAPP5C.DLL
[2002/05/14 17:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\wfxprint2000.dll
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2001/11/15 08:30:48 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI
[12 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtrans.dll
[477 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2001/11/15 08:22:22 | 000,090,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2001/11/15 08:22:22 | 000,606,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2001/11/15 08:22:22 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 11:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\SYSTEM32\user32.dll
[477 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 03:56:46 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\SYSTEM32\ws2_32.dll
[477 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 03:56:46 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\SYSTEM32\ws2help.dll
[477 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-06-11 07:11:25
========== Alternate Data Streams ==========
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >