Blottedisk
I was a little confused by this. I removed and then downloaded Malwarebytes. It found no malware. I will post the log below. I downloaded Kaspersky. I ran it once and saw a report in the formerly blank square. However, when I went to save it, I could not find it. I ran it again for another few hours the next day. It did not have the report in the blank square. All it had was this which was an infected file:
C:/ProgramFiles/PowerTools/Ba…
Threats
Exploit.Java.Agent.f
I found out that Kaspersky saved the file but it kept on being saved in Opera when I was using IE since Opera is not working properly. Anyway, whenever I try to open the logfile, Opera opens up but I cannot get the logfile. I think I sent both OTL files to you. There was no Extras.txt on the desktop where I saved OTL.
Again, thanks for helping.
GB
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4638
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
9/17/2010 2:29:47 AM
mbam-log-2010-09-17 (02-29-47).txt
Scan type: Quick scan
Objects scanned: 234562
Time elapsed: 28 minute(s), 25 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 9/18/2010 3:03:39 PM - Run 6
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 31.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 15.81 Gb Free Space | 41.33% Space Free | Partition Type: NTFS
Drive D: | 1.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 3.82 Gb Total Space | 3.77 Gb Free Space | 98.59% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WIXP\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WIXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WIXP\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WIXP\System32\appmgmts.dll File not found
SRV - (0082101281009065mcinstcleanup) McAfee Application Installer Cleanup (0082101281009065) – C:\WIXP\Temp\0082101281009065mcinst.exe (McAfee, Inc.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BIOSCHK) – C:\DOCUME~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswTdi) – C:\WIXP\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WIXP\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WIXP\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WIXP\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WIXP\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WIXP\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (BANTExt) – C:\WIXP\System32\Drivers\BANTExt.sys ()
DRV - (portD) – C:\WIXP\system32\drivers\portd2k.sys (CMS Peripherals, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WIXP\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (AN983) – C:\WIXP\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (OMCI) – C:\WIXP\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/31 20:54:19 | 000,000,000 | —D | M]
[2009/12/21 14:30:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/07/14 20:21:35 | 000,000,698 | —- | M]) - C:\WIXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WIXP\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (xplorer2 Toolbar) - {DB35FDA8-77E3-4784-92C2-EE7345E91AF4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
http://download.mcafee.com/molbin/iss-loc/…094/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WIXP\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WIXP\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIXP\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WIXP\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:29:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WIXP\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WIXP\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/17 01:53:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WIXP\System32\drivers\mbamswissarmy.sys
[2010/09/17 01:53:30 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WIXP\System32\drivers\mbam.sys
[2010/09/12 19:17:34 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/04 04:38:26 | 000,000,000 | —D | C] – C:\WIXP\McAfee.com
========== Files - Modified Within 30 Days ==========
[2010/09/18 15:02:00 | 000,001,006 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
[2010/09/18 15:02:00 | 000,000,884 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/18 13:05:11 | 000,000,880 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/18 13:05:02 | 000,000,006 | -H– | M] () – C:\WIXP\tasks\SA.DAT
[2010/09/18 13:04:47 | 000,002,048 | –S- | M] () – C:\WIXP\bootstat.dat
[2010/09/18 12:02:00 | 000,000,954 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
[2010/09/18 05:50:30 | 000,002,932 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Kaspersky log sept 18.html
[2010/09/18 05:45:43 | 000,002,932 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Kaspersky log.html
[2010/09/17 01:53:36 | 000,000,714 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/17 01:53:36 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/16 08:19:35 | 000,000,610 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/09/16 08:19:35 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Opera.lnk
[2010/09/16 08:03:33 | 003,407,872 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2010/09/16 08:03:06 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2010/09/14 12:54:03 | 000,001,042 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\changes.rtf
[2010/09/13 21:25:11 | 000,000,449 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gmail - Fw North 10 … - [removed]
[2010/09/13 19:35:02 | 005,886,304 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\IconCache.db
[2010/09/13 19:31:41 | 000,002,206 | —- | M] () – C:\WIXP\System32\wpa.dbl
[2010/09/13 09:21:14 | 000,072,080 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\g2mdlhlpx.exe
[2010/09/12 20:09:58 | 000,293,376 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\74bq0e9s.exe
[2010/09/12 19:17:35 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/12 17:05:56 | 000,011,647 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/09/12 16:46:53 | 000,016,896 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\hc50 Telephone Roster July 2010.doc
[2010/09/12 15:28:15 | 000,125,491 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:11:01 | 000,021,006 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:28 | 000,018,805 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:07 | 000,010,926 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 10:11:11 | 000,011,792 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/09/10 10:03:33 | 000,011,764 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:33:58 | 140,467,400 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:23 | 000,017,261 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:54 | 000,010,875 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/29 00:21:39 | 000,024,304 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/23 19:53:15 | 000,031,855 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 12:00:31 | 000,041,472 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 11:54:59 | 000,021,991 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 10:54:11 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:09 | 000,024,576 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/08/19 20:07:29 | 000,021,141 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Karen's goals.odt
[2010/08/19 19:39:12 | 000,007,285 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\gremlin.odg
========== Files Created - No Company Name ==========
[2010/09/18 05:50:30 | 000,002,932 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Kaspersky log sept 18.html
[2010/09/18 05:41:19 | 000,002,932 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Kaspersky log.html
[2010/09/17 01:53:36 | 000,000,714 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/17 01:53:36 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users.WIXP\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/14 12:54:03 | 000,001,042 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\changes.rtf
[2010/09/13 21:25:11 | 000,000,449 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gmail - Fw North 10 … - [removed]
[2010/09/13 09:21:14 | 000,072,080 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\g2mdlhlpx.exe
[2010/09/12 20:09:56 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\74bq0e9s.exe
[2010/09/12 15:28:48 | 000,125,491 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:10:59 | 000,021,006 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:27 | 000,018,805 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:06 | 000,010,926 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:35:57 | 000,011,764 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/09 21:13:32 | 140,467,400 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:48 | 000,011,792 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/08/31 20:50:22 | 000,017,261 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:32 | 000,010,875 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/28 22:05:17 | 000,024,304 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/26 21:05:15 | 000,021,991 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 14:51:36 | 000,031,855 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 12:00:30 | 000,041,472 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 10:54:11 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:08 | 000,024,576 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/08/19 21:18:04 | 000,011,647 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/08/19 20:07:26 | 000,021,141 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Karen's goals.odt
[2010/08/19 19:39:09 | 000,007,285 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\gremlin.odg
[2010/06/30 16:40:57 | 000,000,348 | —- | C] () – C:\Program Files\rwbpg.txt
[2010/05/17 19:54:09 | 000,000,754 | —- | C] () – C:\WIXP\WORDPAD.INI
[2010/05/07 01:03:11 | 000,000,237 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\burnaware.ini
[2010/04/07 05:46:10 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/03/08 13:21:09 | 000,006,144 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 06:41:44 | 000,003,840 | —- | C] () – C:\WIXP\System32\drivers\BANTExt.sys
[2010/01/22 13:22:54 | 000,767,952 | —- | C] () – C:\WIXP\BDTSupport.dll.old
[2002/09/03 08:58:49 | 000,027,440 | —- | C] () – C:\WIXP\System32\drivers\secdrv.sys
========== LOP Check ==========
[2010/07/30 15:58:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Alwil Software
[2009/12/24 11:19:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Applications
[2010/01/25 18:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Citrix
[2009/12/27 21:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\IObit
[2010/02/23 01:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Karen's Power Tools
[2010/07/22 11:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\TEMP
[2009/12/30 16:58:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit
[2010/04/20 13:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit Software
[2010/04/05 21:06:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\IObit
[2010/02/23 01:29:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\NesterSoft
[2010/05/17 20:58:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\OpenOffice.org
[2010/01/01 22:26:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Opera
[2009/12/24 12:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Thinstall
[2010/03/24 15:08:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Uniblue
[2010/07/18 15:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\WinPatrol
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ERDNT\cache\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ServicePackFiles\i386\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\system32\drivers\agp440.sys
[2002/09/03 08:31:57 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\drivers\atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WIXP\$NtServicePackUninstall$\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ERDNT\cache\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ServicePackFiles\i386\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ERDNT\cache\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ServicePackFiles\i386\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WIXP\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\system32\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WIXP\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ERDNT\cache\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ServicePackFiles\i386\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ERDNT\cache\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ServicePackFiles\i386\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WIXP\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/12/21 21:42:44 | 000,357,888 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WIXP\system32\dxtmsft.dll
[2009/12/21 21:42:45 | 000,205,312 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WIXP\system32\dxtrans.dll
[2009/12/21 21:42:45 | 000,251,392 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WIXP\system32\iepeers.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/12/21 07:12:44 | 000,094,208 | —- | M] () – C:\WIXP\system32\config\default.sav
[2009/12/21 07:12:44 | 000,602,112 | —- | M] () – C:\WIXP\system32\config\software.sav
[2009/12/21 07:12:44 | 000,393,216 | —- | M] () – C:\WIXP\system32\config\system.sav
< %systemdrive%\*.sys /90 /md5 >
[2010/09/18 13:04:42 | 1608,515,584 | -HS- | M] ()
Unable to obtain MD5 – C:\pagefile.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 9/18/2010 3:03:39 PM - Run 6
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 31.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 15.81 Gb Free Space | 41.33% Space Free | Partition Type: NTFS
Drive D: | 1.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 3.82 Gb Total Space | 3.77 Gb Free Space | 98.59% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KHALSA-FAMILY
Current User Name: Owner