This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus-Trojah -E Mail Hijacker

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi , I have been noticing diffuclity with slow running and stalling especially when checking email for over a month.. Today I got a reply from one contact asking if I had sent the link to a advertisement, my Spam folder has 14 returned E-mails I didn't send, but my Sent Folder" shows they were sent from my Email??
I have followed all the steps your site recomends to clean and speed up the computer . I have run the antivirus Scan with McFee, with my service provider, I ran R-Kill, Combo fix, In Safe Mode and they come up clean??? I ran Malwarebytes, Adaware SE Personal and they come up clean?? I just got hit again, It sent out another lot of Spam with a link to cheap meds. What can I do??? Any help would be appreciated! Thank You!]
HiJack This 2.0.4. Log File - Note Pad is Below

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:06:31 AM, on 9/27/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\SiSAudUt.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\DOCUME~1\VERNMC~1\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SiS7012Utility] C:\WINDOWS\System32\SiSAudUt.exe -wdm
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097391139862
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1137821257890
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} - http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://energycenter.webex.com/client/T27LB…bex/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 7766 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
It would appear that you have more than one anti-virus solution on your machine. I can see both McAfee and Symantec installed. Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine. Your post seemed to indicate McAfee is your anti-virus solution and it appears to also be your firewall, before continuing on, please completely uninstall Norton using the instructions below.

Norton Removal Tool

Please click HERE and follow the instructions to download and run the Norton Removal Tool for your own version.

If you are not prompted to do so, please reboot the machine after the tool has finished running.


HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

OTL Custom Scan

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



This is very important. It is quite possible the password for your email has become compromised. I would strongly urge you to immediately change your password to your account. I do still want to check your logs to ensure any malware that may be on the machine is removed, but if it were me the very first thing I would do is change my email password.
I ran the Notton Removal, and here are the Scan.Txt and the Extras.Txt

"]Scan. Txt

OTL logfile created on: 9/28/2010 7:54:04 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Vern McKinney\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,024.00 Mb Total Physical Memory | 540.00 Mb Available Physical Memory | 53.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 57.27 Gb Total Space | 41.14 Gb Free Space | 71.83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VERN-UUSAKGC8SQ
Current User Name: Vern McKinney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\dvd43\DVD43_Tray.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
PRC - C:\WINDOWS\SYSTEM32\SISAUDUT.EXE (Silicon Integrated Systems Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (PCAMPR5) – C:\WINDOWS\System32\PCAMPR5.SYS File not found
DRV - (catchme) – C:\DOCUME~1\VERNMC~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (dvd43llh) – C:\WINDOWS\SYSTEM32\DRIVERS\dvd43llh.sys (RIF)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\SYSTEM32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (SiS315) – C:\WINDOWS\SYSTEM32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp) – C:\WINDOWS\SYSTEM32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (cdudf_xp) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (UdfReadr_xp) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (SiS7012) Service for AC'97 Sample Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\sis7012.sys (Silicon Integrated Systems Corporation)
DRV - (SISNIC) – C:\WINDOWS\SYSTEM32\DRIVERS\sisnic.sys (SiS Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/06/03 22:37:55 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/09/26 22:41:55 | 000,000,023 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SiS7012Utility] C:\WINDOWS\System32\SiSAudUt.exe (Silicon Integrated Systems Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: windows.com ([time] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1097391139862 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1137821257890 (MUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab (Reg Error: Key error.)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://energycenter.webex.com/client/T27LB…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/28 13:49:58 | 000,000,070 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/27 14:52:16 | 000,000,038 | -HS- | M] () - C:\AUTOEXEC.DOS – [ NTFS ]
O32 - AutoRun File - [2010/09/27 15:15:32 | 000,000,070 | —- | M] () - C:\AUTOEXEC.NS0 – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecx.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 90 Days ==========

[2010/10/09 20:03:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Help
[2010/10/09 19:56:50 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/10/09 19:56:49 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Designer
[2010/10/09 19:55:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft Web Folders
[2010/10/09 19:55:04 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/10/09 19:42:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Camino # 3
[2010/10/09 19:42:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\aMVC-001F.zip Turbine Pictures
[2010/10/09 19:42:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\AA
[2010/10/09 19:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\TAYLORBEFORESCHOOL
[2010/10/09 19:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\SUDCO Motorcycle Parts Distributing_files
[2010/10/09 19:42:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\stress2
[2010/10/09 19:42:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\My Albums
[2010/10/09 19:42:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Monkey1-high1
[2010/10/09 19:42:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Microsoft update down load repair
[2010/10/09 19:42:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0011
[2010/10/09 19:42:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0010
[2010/10/09 19:42:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0009
[2010/10/09 19:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0008
[2010/10/09 19:42:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0007
[2010/10/09 19:42:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0006
[2010/10/09 19:42:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0005
[2010/10/09 19:42:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0004
[2010/10/09 19:41:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0003
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0002
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0001
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complrint Form GSXR 1100 MOTOR_files
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complaint Form 1100 GSXR MOTOR_files
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Forest Gump Goes To Heaven_files
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\ebayitems001
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Dscn0027
[2010/10/09 11:50:44 | 000,000,000 | —D | C] – C:\WINDOWS\System32\trayres
[2010/10/09 11:50:43 | 000,000,000 | —D | C] – C:\Program Files\SiS Compatible VGA V2.05a.01
[2010/10/09 11:47:20 | 000,000,000 | —D | C] – C:\WINDOWS\SiSAGP
[2010/10/09 11:39:55 | 000,000,000 | –SD | C] – C:\WINDOWS\System32\Microsoft
[2010/10/09 11:39:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/10/09 11:39:16 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/10/09 11:39:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Application Data\Adobe
[2010/10/09 11:38:27 | 000,031,744 | R— | C] (SiS Corporation) – C:\WINDOWS\System32\drivers\sisnic.sys
[2010/10/09 11:38:27 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ReinstallBackups
[2010/10/09 11:37:38 | 000,078,948 | R— | C] (Aureal Semiconductor) – C:\WINDOWS\System32\a3d.dll
[2010/10/09 11:37:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\WINDOWS
[2010/10/09 11:34:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Application Data\Identities
[2010/10/09 11:34:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\My Documents\My Pictures
[2010/10/09 11:34:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\My Documents\My Music
[2010/10/09 11:34:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Microsoft
[2010/10/09 11:33:59 | 000,000,000 | –SD | C] – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft
[2010/10/09 11:33:59 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Vern McKinney\SendTo
[2010/10/09 11:33:59 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Vern McKinney\Application Data
[2010/10/09 11:33:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\Start Menu
[2010/10/09 11:33:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\My Documents
[2010/10/09 11:33:59 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Vern McKinney\Cookies
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\Templates
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\PrintHood
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\NetHood
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\Local Settings
[2010/10/09 11:33:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Favorites
[2010/10/09 11:33:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Desktop
[2010/10/09 11:32:28 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/10/09 11:32:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/10/09 11:32:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/10/09 11:32:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/10/09 11:32:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/10/09 11:29:57 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2010/10/09 11:29:57 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2010/10/09 11:28:37 | 000,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2010/10/09 11:28:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\xircom
[2010/10/09 11:28:14 | 000,000,000 | —D | C] – C:\Program Files\xerox
[2010/10/09 11:28:14 | 000,000,000 | —D | C] – C:\Program Files\microsoft frontpage
[2010/10/09 11:26:01 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users\DRM
[2010/10/09 11:25:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DirectX
[2010/10/09 11:25:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\MSSoap
[2010/10/09 11:25:07 | 000,000,000 | —D | C] – C:\WINDOWS\srchasst
[2010/10/09 11:25:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Macromed
[2010/10/09 11:25:06 | 000,000,000 | —D | C] – C:\Program Files\Movie Maker
[2010/10/09 11:25:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Restore
[2010/10/09 11:25:05 | 000,000,000 | —D | C] – C:\WINDOWS\PCHealth
[2010/10/09 11:24:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2010/10/09 11:24:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2010/10/09 11:24:08 | 000,000,000 | —D | C] – C:\WINDOWS\Registration
[2010/10/09 11:23:55 | 000,000,000 | —D | C] – C:\Program Files\Messenger
[2010/10/09 11:23:51 | 000,000,000 | —D | C] – C:\Program Files\MSN Gaming Zone
[2010/10/09 11:23:39 | 000,000,000 | —D | C] – C:\Program Files\Windows NT
[2010/10/09 11:23:39 | 000,000,000 | —D | C] – C:\Program Files\MSN
[2010/10/09 11:23:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MsDtc
[2010/10/09 11:23:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Com
[2010/10/09 11:23:35 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/10/09 04:08:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeechEngines
[2010/10/09 04:08:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu
[2010/10/09 04:08:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents
[2010/10/09 04:08:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Templates
[2010/10/09 04:08:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Favorites
[2010/10/09 04:08:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop
[2010/10/09 04:08:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot2
[2010/10/09 04:08:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot
[2010/10/09 04:07:58 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2010/10/09 04:07:58 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data
[2010/10/09 04:07:46 | 000,000,000 | —D | C] – C:\Documents and Settings
[2010/10/09 04:04:34 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\WinSxS
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wins
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wbem
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\usmt
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\twain_32
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\spool
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ShellExt
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Setup
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\security
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Resources
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\repair
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ras
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\oobe
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\npp
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\mui
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\mui
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\msapps
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\msagent
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\inetsrv
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\IME
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\ime
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\icsxml
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ias
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\export
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\etc
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Driver Cache
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\disdn
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dhcp
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Debug
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Connection Wizard
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\config
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\addins
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3com_dmi
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3076
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\2052
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1054
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1042
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1041
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1037
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1033
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1031
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1028
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1025
[2010/10/09 04:00:17 | 003,374,640 | —- | C] (Macromedia, Inc.) – C:\WINDOWS\System32\dllcache\tourW.exe
[2010/10/09 03:49:58 | 000,000,000 | —D | C] – C:\WINDOWS\setup
[2010/10/02 03:07:43 | 000,000,000 | —D | C] – C:\ASAPREP
[2010/09/28 19:38:32 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe
[2010/09/28 19:23:15 | 000,921,512 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Vern McKinney\Desktop\Norton_Removal_Tool.exe
[2010/09/28 15:39:12 | 000,000,000 | –SD | C] – C:\WINDOWS\UserData
[2010/09/28 14:59:33 | 000,000,000 | —D | C] – C:\WINDOWS\color
[2010/09/28 14:59:32 | 000,000,000 | —D | C] – C:\Program Files\HP DeskJet 820C Series
[2010/09/28 14:47:41 | 000,000,000 | —D | C] – C:\WINDOWS\Windows Update Setup Files
[2010/09/28 14:08:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\aolback
[2010/09/28 14:08:08 | 000,000,000 | –SD | C] – C:\WINDOWS\occache
[2010/09/28 14:08:08 | 000,000,000 | —D | C] – C:\Program Files\Learn2.com
[2010/09/28 14:08:05 | 000,000,000 | —D | C] – C:\Program Files\Viewpoint
[2010/09/28 14:00:37 | 000,000,000 | —D | C] – C:\WINDOWS\System\mui
[2010/09/28 13:51:59 | 000,000,000 | —D | C] – C:\WINDOWS\System\sfp
[2010/09/28 13:51:46 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/09/28 13:51:01 | 000,000,000 | —D | C] – C:\WINDOWS\System\QuickTime
[2010/09/28 13:50:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nullsoft
[2010/09/28 13:50:49 | 000,000,000 | —D | C] – C:\My Music
[2010/09/28 13:50:47 | 000,000,000 | —D | C] – C:\Program Files\Real
[2010/09/28 13:50:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Real
[2010/09/28 13:48:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AOL
[2010/09/27 16:01:31 | 000,000,000 | —D | C] – C:\WINDOWS\Options
[2010/09/27 15:58:15 | 000,000,000 | —D | C] – C:\Program Files\SiSLan
[2010/09/27 15:47:53 | 000,000,000 | —D | C] – C:\Program Files\SiS7012
[2010/09/27 15:45:36 | 000,000,000 | —D | C] – C:\WINDOWS\SiS
[2010/09/27 15:45:04 | 000,000,000 | —D | C] – C:\WINDOWS\System\trayres
[2010/09/27 15:44:57 | 000,000,000 | —D | C] – C:\Program Files\SiS_Compatible_VGA_V2.05a.01
[2010/09/27 15:25:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/09/27 15:24:57 | 000,000,000 | —D | C] – C:\Program Files\Norton SystemWorks
[2010/09/27 15:20:54 | 000,000,000 | —D | C] – C:\WINDOWS\AppPatch
[2010/09/27 15:20:51 | 000,000,000 | -HSD | C] – C:\WINDOWS\Installer
[2010/09/27 15:20:51 | 000,000,000 | -H-D | C] – C:\WINDOWS\PrintHood
[2010/09/27 15:20:30 | 000,000,000 | —D | C] – C:\WINDOWS\Local Settings
[2010/09/27 15:20:27 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2010/09/27 15:16:53 | 000,000,000 | -H-D | C] – C:\WINDOWS\NetHood
[2010/09/27 15:16:53 | 000,000,000 | —D | C] – C:\My Documents
[2010/09/27 15:15:23 | 000,000,000 | —D | C] – C:\WINDOWS\System\CatRoot
[2010/09/27 15:15:12 | 000,000,000 | –SD | C] – C:\WINDOWS\Temporary Internet Files
[2010/09/27 15:15:12 | 000,000,000 | –SD | C] – C:\WINDOWS\History
[2010/09/27 15:15:12 | 000,000,000 | –SD | C] – C:\WINDOWS\Cookies
[2010/09/27 15:15:11 | 000,000,000 | —D | C] – C:\Program Files\DirectX
[2010/09/27 15:14:31 | 000,000,000 | –SD | C] – C:\WINDOWS\Favorites
[2010/09/27 15:14:26 | 000,000,000 | –SD | C] – C:\WINDOWS\Downloaded Program Files
[2010/09/27 15:14:25 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2010/09/27 15:14:02 | 000,000,000 | —D | C] – C:\Program Files\Uninstall Information
[2010/09/27 15:13:38 | 000,000,000 | -H-D | C] – C:\WINDOWS\Recent
[2010/09/27 15:13:38 | 000,000,000 | —D | C] – C:\WINDOWS\SendTo
[2010/09/27 15:13:37 | 000,000,000 | —D | C] – C:\WINDOWS\Start Menu
[2010/09/27 15:13:32 | 000,000,000 | —D | C] – C:\WINDOWS\All Users
[2010/09/27 07:06:07 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2010/09/27 00:08:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Desktop\Hijack This
[2010/09/26 22:41:55 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/09/26 22:25:07 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/09/26 22:25:07 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/09/26 22:25:07 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/09/26 22:25:07 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/09/18 16:31:11 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/09/18 16:31:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/09/18 16:30:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/09/18 16:30:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Apple
[2010/09/18 16:30:10 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/09/18 16:30:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/09/18 16:28:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Apple Computer
[2010/09/06 16:57:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Vern McKinney\Recent
[2010/09/06 16:56:34 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/08/25 19:49:58 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/25 19:49:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/25 19:49:54 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/25 19:49:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/24 21:07:44 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/08/24 21:04:58 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/08/24 21:04:33 | 000,000,000 | —D | C] – C:\Qoobox
[2010/08/24 20:19:15 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/08/24 20:08:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/08/24 20:08:12 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/08/24 20:08:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/08/24 20:02:23 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2010/08/05 23:43:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\House Ideas
[2010/08/05 22:42:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Work Pictures
[2010/08/05 07:09:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/04 22:57:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/04 22:57:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/04 22:57:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/07/23 18:41:55 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/07/05 16:14:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Crockett Monday Night General Service
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[14 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/10/09 19:57:44 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/10/09 19:57:40 | 000,000,059 | —- | M] () – C:\WINDOWS\vbaddin.ini
[2010/10/09 12:13:03 | 000,001,789 | —- | M] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2010/10/09 11:51:24 | 000,003,917 | —- | M] () – C:\SiSSetup1.ini
[2010/10/09 11:50:42 | 000,004,981 | —- | M] () – C:\SiSUnist.ini
[2010/10/09 11:46:45 | 000,002,942 | —- | M] () – C:\WINDOWS\Ascd_tmp.ini
[2010/10/09 11:34:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/10/09 11:34:11 | 000,025,065 | —- | M] () – C:\WINDOWS\System32\wmpscheme.xml
[2010/10/09 11:31:34 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2010/10/09 11:30:49 | 000,000,658 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/10/09 11:27:53 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/10/09 11:25:49 | 000,000,488 | RH– | M] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2010/10/09 11:25:49 | 000,000,488 | RH– | M] () – C:\WINDOWS\System32\logonui.exe.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\WindowsShell.Manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/10/09 11:24:26 | 000,021,640 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/10/09 11:24:13 | 000,000,036 | —- | M] () – C:\WINDOWS\vb.ini
[2010/10/09 04:01:14 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2010/09/28 19:38:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe
[2010/09/28 19:33:57 | 000,017,399 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/09/28 19:32:51 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/28 19:32:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/28 19:32:11 | 009,699,328 | —- | M] () – C:\Documents and Settings\Vern McKinney\ntuser.dat
[2010/09/28 19:32:06 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\ntuser.ini
[2010/09/28 19:31:48 | 004,313,140 | -H– | M] () – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\IconCache.db
[2010/09/28 19:23:17 | 000,921,512 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Vern McKinney\Desktop\Norton_Removal_Tool.exe
[2010/09/28 13:49:58 | 000,000,070 | —- | M] () – C:\AUTOEXEC.BAT
[2010/09/28 13:49:58 | 000,000,040 | —- | M] () – C:\CONFIG.SYS
[2010/09/27 22:08:02 | 000,000,358 | —- | M] () – C:\WINDOWS\tasks\HP Usg Daily.job
[2010/09/27 15:16:00 | 000,049,152 | -HS- | M] () – C:\VIDEOROM.BIN
[2010/09/27 15:15:40 | 000,046,548 | -HS- | M] () – C:\BOOTLOG.PRV
[2010/09/27 15:15:32 | 000,000,070 | —- | M] () – C:\AUTOEXEC.NS0
[2010/09/27 15:15:32 | 000,000,040 | —- | M] () – C:\CONFIG.NS0
[2010/09/27 15:14:34 | 000,011,079 | —- | M] () – C:\Program Files\folder.htt
[2010/09/27 07:06:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/27 00:20:15 | 000,002,000 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\HiJackThis.lnk
[2010/09/27 00:05:00 | 000,305,771 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\HijackThis.zip
[2010/09/26 23:40:00 | 001,402,880 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\Verns Fix.msi
[2010/09/26 22:41:55 | 000,000,023 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/09/26 22:32:14 | 000,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/26 22:22:20 | 003,854,581 | R— | M] () – C:\Documents and Settings\Vern McKinney\Desktop\ComboFix.exe
[2010/09/26 15:11:00 | 000,000,845 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2010/09/26 14:49:08 | 000,000,241 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\HammerSnipe - HammerSnipe - FREE online auction site sniping software esniper ebay snipe site e snipe auctions ebay auction sniper site bid sniper free auction.url
[2010/09/25 00:54:14 | 000,021,961 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/09/18 16:32:18 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/09/18 16:19:11 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/09/18 16:19:11 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/09/15 18:27:59 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/06 16:56:36 | 000,001,552 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\CCleaner.lnk
[2010/09/05 12:14:27 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/25 19:50:01 | 000,000,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/25 18:37:20 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/25 07:38:02 | 000,311,934 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/25 07:38:02 | 000,040,196 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/25 07:38:01 | 000,356,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/24 21:07:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/08/24 20:36:30 | 000,000,791 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/24 20:36:30 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/24 20:02:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/05 23:49:48 | 014,306,443 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\DMV HearingPictures.zip
[2010/08/01 20:37:04 | 000,025,600 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\Discussion Topic.doc
[2010/07/23 18:48:00 | 000,000,819 | —- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/20 19:23:56 | 000,084,480 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\Poker%20Run[1].doc
[2010/07/15 15:18:22 | 000,120,136 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\Mpfp.sys
[2010/07/05 16:05:58 | 000,020,992 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\Crockett Monday Night.doc
[2010/07/04 03:12:17 | 000,001,455 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\WebEx Player.LNK
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[14 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/09 19:57:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/10/09 19:42:52 | 002,093,087 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\TAYLORBEFORESCHOOL.zip
[2010/10/09 19:42:52 | 001,225,216 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\System Information.nfo
[2010/10/09 19:42:52 | 000,400,775 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbirds.jpg
[2010/10/09 19:42:52 | 000,300,478 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbird diamond 6.jpg
[2010/10/09 19:42:52 | 000,252,750 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\stress2.zip
[2010/10/09 19:42:52 | 000,217,335 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\WinnieThePooh.zip
[2010/10/09 19:42:52 | 000,104,357 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbrds 6.jpg
[2010/10/09 19:42:52 | 000,101,477 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbirds cross 4.jpg
[2010/10/09 19:42:52 | 000,095,791 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbirds diamond 6.jpg
[2010/10/09 19:42:52 | 000,078,712 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbirds 5.jpg
[2010/10/09 19:42:52 | 000,078,702 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbirds-1.jpg
[2010/10/09 19:42:52 | 000,032,256 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Powersports of Vallejo.doc
[2010/10/09 19:42:52 | 000,027,136 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\WordforBlonds.doc
[2010/10/09 19:42:52 | 000,022,155 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbirds 3.jpg
[2010/10/09 19:42:52 | 000,017,454 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\vern shippin doct. gsxr engine ind..pdf
[2010/10/09 19:42:52 | 000,006,376 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Rocket Seintsist.html
[2010/10/09 19:42:52 | 000,001,655 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\SUDCO Motorcycle Parts Distributing.htm
[2010/10/09 19:42:52 | 000,000,292 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\tmb.ind
[2010/10/09 19:42:52 | 000,000,262 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Shortcut to My Documents.lnk
[2010/10/09 19:42:52 | 000,000,055 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\tmb.lst
[2010/10/09 19:42:51 | 005,034,269 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Monkey1-high1.zip
[2010/10/09 19:42:51 | 001,221,659 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\MAT-V1-1.exe Aqu, screen saver.exe
[2010/10/09 19:42:51 | 000,464,422 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\LagerPaper.wmv
[2010/10/09 19:42:51 | 000,241,035 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\image001.zip
[2010/10/09 19:42:51 | 000,189,758 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\JumpShotWA.zip
[2010/10/09 19:42:51 | 000,159,232 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\mother-in-law_1.pps
[2010/10/09 19:42:51 | 000,150,016 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\JUSTCHEC.pps
[2010/10/09 19:42:51 | 000,094,208 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\PICKFOUR.pps
[2010/10/09 19:42:51 | 000,036,864 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Power plant Chapter 2 Review.doc
[2010/10/09 19:42:51 | 000,019,456 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\My Letter01A.doc
[2010/10/09 19:42:51 | 000,019,456 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\My Letter01.doc
[2010/10/09 19:42:51 | 000,016,982 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\image001.jpgMichelin Denies Paternit Suit.jpg
[2010/10/09 19:42:51 | 000,015,359 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC-I04010122517545.pdf
[2010/10/09 19:42:51 | 000,014,650 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC-I03112400048755.pdfGSXR Complaint.pdf
[2010/10/09 19:42:51 | 000,014,650 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC-I03112400048755.pdfGSXR 1100 Complaint.pdf
[2010/10/09 19:42:51 | 000,008,931 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Jokes.html
[2010/10/09 19:42:51 | 000,003,339 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complrint Form GSXR 1100 MOTOR.htm
[2010/10/09 19:42:51 | 000,000,339 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\LagerPaper.wmv.lnk
[2010/10/09 19:42:51 | 000,000,022 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Microsoft update down load repair.zip
[2010/10/09 19:42:50 | 002,178,900 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\HOWMENSCREWUPROMANCE_1.mpg
[2010/10/09 19:42:50 | 000,884,625 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC Complaint.jpg
[2010/10/09 19:42:50 | 000,674,854 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0196.JPG
[2010/10/09 19:42:50 | 000,643,266 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0197.JPG
[2010/10/09 19:42:50 | 000,508,398 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0144.JPG
[2010/10/09 19:42:50 | 000,508,360 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0189.JPG
[2010/10/09 19:42:50 | 000,504,017 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0162.JPG
[2010/10/09 19:42:50 | 000,480,385 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0198.JPG
[2010/10/09 19:42:50 | 000,455,042 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\ebayitems001.zip
[2010/10/09 19:42:50 | 000,451,259 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0194.JPG
[2010/10/09 19:42:50 | 000,436,188 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0105.JPG
[2010/10/09 19:42:50 | 000,436,087 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0161.JPG
[2010/10/09 19:42:50 | 000,339,849 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0145.JPG
[2010/10/09 19:42:50 | 000,033,792 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC Complaint.doc Letter to Brandy Stower.doc
[2010/10/09 19:42:50 | 000,030,651 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complaint Form 1100 GSXR MOTOR.htm
[2010/10/09 19:42:50 | 000,006,510 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\HP 7960 Photo Printer.htm
[2010/10/09 19:42:50 | 000,004,177 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Forest Gump Goes To Heaven.html
[2010/10/09 19:42:50 | 000,000,831 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Hey What Happened To The Copy Machine.html
[2010/10/09 19:42:49 | 003,366,998 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Dscn0027.zip
[2010/10/09 19:42:49 | 000,884,625 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0035.JPG
[2010/10/09 19:42:49 | 000,776,443 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0049.JPG
[2010/10/09 19:42:49 | 000,730,772 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0024.JPG
[2010/10/09 19:42:49 | 000,699,833 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0023.JPG ICC Complaint Timing Cover.jpg
[2010/10/09 19:42:49 | 000,618,680 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0024.JPG IFCC Cmplaint Timing Cover.jpg
[2010/10/09 19:42:49 | 000,600,739 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0071.JPG
[2010/10/09 19:42:49 | 000,560,785 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0024.JPG IFCC Complaint.jpg
[2010/10/09 19:42:49 | 000,552,831 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0048.JPG
[2010/10/09 19:42:49 | 000,514,158 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0069.JPG
[2010/10/09 19:42:49 | 000,480,994 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0058.JPG
[2010/10/09 19:42:49 | 000,475,371 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0062.JPG
[2010/10/09 19:42:49 | 000,471,475 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0077.JPG
[2010/10/09 19:42:49 | 000,447,724 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0059.JPG
[2010/10/09 19:42:49 | 000,386,637 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0079.JPG
[2010/10/09 19:42:49 | 000,336,903 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0092.JPG
[2010/10/09 19:42:49 | 000,267,777 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0027.JPG
[2010/10/09 19:42:49 | 000,219,828 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0028.JPG
[2010/10/09 19:42:49 | 000,101,926 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0039.JPG
[2010/10/09 19:42:48 | 000,660,312 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0022.JPG IFCC Complain.jpg
[2010/10/09 19:42:48 | 000,464,941 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\cleco136glf.pdf
[2010/10/09 19:42:48 | 000,423,062 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Cleco Grinder Threaded Shaft.zip
[2010/10/09 19:42:48 | 000,353,504 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\dago red 3.jpg
[2010/10/09 19:42:48 | 000,269,719 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\coolpixsummerrebate.pdf
[2010/10/09 19:42:48 | 000,176,658 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\count_coupon.pdf
[2010/10/09 19:42:48 | 000,105,032 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Dago red.jpg
[2010/10/09 19:42:48 | 000,087,227 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\BikeClub.jpg
[2010/10/09 19:42:48 | 000,050,790 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\CD File of Pictures Air Show.cl5
[2010/10/09 19:42:48 | 000,049,152 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\archive.pst
[2010/10/09 19:42:48 | 000,039,936 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Class Paper _Radial Engines.ppt
[2010/10/09 19:42:48 | 000,015,631 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Dago red 4.jpg
[2010/10/09 19:42:48 | 000,006,510 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\ATTED50.htm HP 7960 Photo Printer.htm
[2010/10/09 19:42:47 | 012,789,900 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\aMVC-001F.zip Turbine Pictures.zip
[2010/10/09 19:42:47 | 000,027,136 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\01BOATPREP.doc
[2010/10/09 19:42:47 | 000,008,681 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\AA.zip
[2010/10/09 19:42:47 | 000,000,002 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\1992 GSXR Engine
[2010/10/09 19:41:19 | 000,124,928 | —- | C] () – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/09 11:50:41 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\setuplib.dll
[2010/10/09 11:50:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\waitwnd.exe
[2010/10/09 11:50:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis740.bin
[2010/10/09 11:50:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis650.bin
[2010/10/09 11:36:28 | 000,002,942 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/10/09 11:36:27 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/10/09 11:34:17 | 000,000,079 | —- | C] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/10/09 11:34:08 | 000,000,808 | —- | C] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/10/09 11:34:00 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Vern McKinney\ntuser.ini
[2010/10/09 11:33:59 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Vern McKinney\NTUSER.DAT.LOG
[2010/10/09 11:31:34 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2010/10/09 11:30:44 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/10/09 11:29:29 | 001,158,818 | —- | C] () – C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010/10/09 11:29:17 | 000,134,339 | —- | C] () – C:\WINDOWS\System32\dllcache\imekr.lex
[2010/10/09 11:29:07 | 013,463,552 | —- | C] () – C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010/10/09 11:29:01 | 000,108,827 | —- | C] () – C:\WINDOWS\System32\dllcache\hanja.lex
[2010/10/09 11:27:53 | 000,002,577 | —- | C] () – C:\WINDOWS\System32\CONFIG.NT
[2010/10/09 11:27:51 | 000,025,065 | —- | C] () – C:\WINDOWS\System32\wmpscheme.xml
[2010/10/09 11:27:49 | 000,299,552 | —- | C] () – C:\WINDOWS\WMSysPrx.prx
[2010/10/09 11:25:49 | 000,000,488 | RH– | C] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2010/10/09 11:25:49 | 000,000,488 | RH– | C] () – C:\WINDOWS\System32\logonui.exe.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\WindowsShell.Manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/10/09 11:25:26 | 004,399,505 | —- | C] () – C:\WINDOWS\System32\dllcache\nls302en.lex
[2010/10/09 11:25:12 | 000,048,680 | -HS- | C] () – C:\WINDOWS\winnt256.bmp
[2010/10/09 11:25:12 | 000,048,680 | -HS- | C] () – C:\WINDOWS\winnt.bmp
[2010/10/09 11:25:11 | 000,000,984 | —- | C] () – C:\WINDOWS\System32\dllcache\srframe.mmf
[2010/10/09 11:24:26 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/10/09 11:23:47 | 000,093,702 | —- | C] () – C:\WINDOWS\System32\subrange.uce
[2010/10/09 11:23:47 | 000,065,978 | —- | C] () – C:\WINDOWS\Soap Bubbles.bmp
[2010/10/09 11:23:47 | 000,065,954 | —- | C] () – C:\WINDOWS\Prairie Wind.bmp
[2010/10/09 11:23:47 | 000,065,832 | —- | C] () – C:\WINDOWS\Santa Fe Stucco.bmp
[2010/10/09 11:23:47 | 000,060,458 | —- | C] () – C:\WINDOWS\System32\ideograf.uce
[2010/10/09 11:23:47 | 000,026,680 | —- | C] () – C:\WINDOWS\River Sumida.bmp
[2010/10/09 11:23:47 | 000,026,582 | —- | C] () – C:\WINDOWS\Greenstone.bmp
[2010/10/09 11:23:47 | 000,024,006 | —- | C] () – C:\WINDOWS\System32\gb2312.uce
[2010/10/09 11:23:47 | 000,022,984 | —- | C] () – C:\WINDOWS\System32\bopomofo.uce
[2010/10/09 11:23:47 | 000,017,362 | —- | C] () – C:\WINDOWS\Rhododendron.bmp
[2010/10/09 11:23:47 | 000,017,336 | —- | C] () – C:\WINDOWS\Gone Fishing.bmp
[2010/10/09 11:23:47 | 000,017,062 | —- | C] () – C:\WINDOWS\Coffee Bean.bmp
[2010/10/09 11:23:47 | 000,016,740 | —- | C] () – C:\WINDOWS\System32\shiftjis.uce
[2010/10/09 11:23:47 | 000,012,876 | —- | C] () – C:\WINDOWS\System32\korean.uce
[2010/10/09 11:23:47 | 000,009,522 | —- | C] () – C:\WINDOWS\Zapotec.bmp
[2010/10/09 11:23:47 | 000,008,484 | —- | C] () – C:\WINDOWS\System32\kanji_2.uce
[2010/10/09 11:23:47 | 000,006,948 | —- | C] () – C:\WINDOWS\System32\kanji_1.uce
[2010/10/09 11:23:47 | 000,001,272 | —- | C] () – C:\WINDOWS\Blue Lace 16.bmp
[2010/10/09 11:23:46 | 000,003,286 | —- | C] () – C:\WINDOWS\System32\tslabels.h
[2010/10/09 11:23:46 | 000,001,161 | —- | C] () – C:\WINDOWS\System32\usrlogon.cmd
[2010/10/09 11:23:46 | 000,000,768 | —- | C] () – C:\WINDOWS\System32\msdtcprf.h
[2010/10/09 11:23:42 | 000,063,488 | —- | C] () – C:\WINDOWS\System32\wmimgmt.msc
[2010/10/09 04:08:32 | 001,685,606 | —- | C] () – C:\WINDOWS\System32\dllcache\sam.spd
[2010/10/09 04:08:32 | 000,000,888 | —- | C] () – C:\WINDOWS\System32\dllcache\sam.sdf
[2010/10/09 04:08:31 | 000,643,717 | —- | C] () – C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2010/10/09 04:08:31 | 000,605,050 | —- | C] () – C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2010/10/09 04:08:30 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_857.nls
[2010/10/09 04:08:30 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28603.nls
[2010/10/09 04:08:30 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28599.nls
[2010/10/09 04:08:30 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10081.nls
[2010/10/09 04:08:29 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\C_28595.NLS
[2010/10/09 04:08:29 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10017.nls
[2010/10/09 04:08:29 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10007.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_869.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_866.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_855.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_737.nls
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_875.nls
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\C_28597.NLS
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\C_28594.NLS
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10006.nls
[2010/10/09 04:08:27 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_852.nls
[2010/10/09 04:08:27 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10082.nls
[2010/10/09 04:08:27 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10029.nls
[2010/10/09 04:08:27 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10010.nls
[2010/10/09 04:08:26 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_20127.nls
[2010/10/09 04:08:24 | 000,001,789 | —- | C] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2010/10/09 04:08:15 | 000,797,189 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010/10/09 04:08:15 | 000,657,548 | —- | C] () – C:\WINDOWS\System32\dllcache\CLASSES.CAT
[2010/10/09 04:08:15 | 000,399,645 | —- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010/10/09 04:08:15 | 000,390,168 | —- | C] () – C:\WINDOWS\System32\dllcache\WFC.CAT
[2010/10/09 04:08:15 | 000,056,081 | —- | C] () – C:\WINDOWS\System32\dllcache\DAJAVAC.CAT
[2010/10/09 04:08:15 | 000,052,311 | —- | C] () – C:\WINDOWS\System32\dllcache\DX3.CAT
[2010/10/09 04:08:15 | 000,037,484 | —- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2010/10/09 04:08:15 | 000,022,151 | —- | C] () – C:\WINDOWS\System32\dllcache\TCLASSES.CAT
[2010/10/09 04:08:15 | 000,021,281 | —- | C] () – C:\WINDOWS\System32\dllcache\XMLDSOC.CAT
[2010/10/09 04:08:15 | 000,014,031 | —- | C] () – C:\WINDOWS\System32\dllcache\MSJDBC.CAT
[2010/10/09 04:08:15 | 000,013,472 | —- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010/10/09 04:08:15 | 000,008,574 | —- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010/10/09 04:08:15 | 000,007,382 | —- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010/10/09 04:07:45 | 000,144,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/09 04:05:56 | 000,000,658 | —- | C] () – C:\WINDOWS\System32\$winnt$.inf
[2010/10/09 04:01:12 | 000,000,512 | -HS- | C] () – C:\BOOTSECT.DOS
[2010/10/09 04:01:11 | 000,000,281 | RHS- | C] () – C:\boot.ini
[2010/10/09 04:00:06 | 000,250,048 | RHS- | C] () – C:\ntldr
[2010/10/09 04:00:06 | 000,047,564 | RHS- | C] () – C:\ntdetect.com
[2010/10/09 03:59:48 | 000,127,213 | —- | C] () – C:\WINDOWS\System32\ega.cpi
[2010/10/09 03:59:45 | 000,082,944 | —- | C] () – C:\WINDOWS\clock.avi
[2010/10/09 03:59:26 | 000,001,696 | —- | C] () – C:\WINDOWS\System32\noise.cht
[2010/10/09 03:59:26 | 000,001,696 | —- | C] () – C:\WINDOWS\System32\noise.chs
[2010/10/09 03:59:25 | 000,069,886 | —- | C] () – C:\WINDOWS\System32\edit.com
[2010/10/09 03:59:25 | 000,010,790 | —- | C] () – C:\WINDOWS\System32\edit.hlp
[2010/10/09 03:59:06 | 000,000,697 | —- | C] () – C:\WINDOWS\System32\noise.tha
[2010/10/09 03:58:38 | 000,002,206 | —- | C] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/09 03:58:23 | 000,032,674 | —- | C] () – C:\WINDOWS\System32\winhelp.hlp
[2010/10/09 03:58:21 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\dllcache\win87em.dll
[2010/10/09 03:58:20 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\wiasf.ax
[2010/10/09 03:58:20 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\dllcache\wiasf.ax
[2010/10/09 03:58:18 | 001,326,080 | —- | C] () – C:\WINDOWS\System32\webfldrs.msi
[2010/10/09 03:58:17 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\wdl.trm
[2010/10/09 03:58:14 | 001,095,680 | —- | C] () – C:\WINDOWS\System32\wbdbase.nld
[2010/10/09 03:58:14 | 000,937,984 | —- | C] () – C:\WINDOWS\System32\wbdbase.sve
[2010/10/09 03:58:14 | 000,867,840 | —- | C] () – C:\WINDOWS\System32\wbdbase.ita
[2010/10/09 03:58:14 | 000,786,944 | —- | C] () – C:\WINDOWS\System32\wbdbase.fra
[2010/10/09 03:58:13 | 001,309,184 | —- | C] () – C:\WINDOWS\System32\wbdbase.deu
[2010/10/09 03:58:13 | 000,957,440 | —- | C] () – C:\WINDOWS\System32\wbdbase.enu
[2010/10/09 03:58:13 | 000,750,080 | —- | C] () – C:\WINDOWS\System32\wbdbase.esn
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.sve
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.nld
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.ita
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.fra
[2010/10/09 03:58:12 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.esn
[2010/10/09 03:58:12 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.enu
[2010/10/09 03:58:12 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.deu
[2010/10/09 03:58:09 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\vwipxspx.exe
[2010/10/09 03:58:09 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\dllcache\vwipxspx.exe
[2010/10/09 03:58:05 | 000,018,832 | —- | C] () – C:\WINDOWS\System32\v7vga.rom
[2010/10/09 03:58:00 | 000,089,588 | —- | C] () – C:\WINDOWS\System32\unicode.nls
[2010/10/09 03:57:57 | 000,015,360 | —- | C] () – C:\WINDOWS\System32\dllcache\tsd32.dll
[2010/10/09 03:57:50 | 000,000,862 | —- | C] () – C:\WINDOWS\System32\termcap
[2010/10/09 03:57:46 | 000,000,246 | —- | C] () – C:\WINDOWS\SYSTEM.UNV
[2010/10/09 03:57:45 | 000,003,577 | —- | C] () – C:\WINDOWS\System32\sysprtj.sep
[2010/10/09 03:57:45 | 000,003,214 | —- | C] () – C:\WINDOWS\System32\sysprint.sep
[2010/10/09 03:57:35 | 000,046,133 | —- | C] () – C:\WINDOWS\System32\sqlsodbc.chm
[2010/10/09 03:57:25 | 000,262,148 | —- | C] () – C:\WINDOWS\System32\sortkey.nls
[2010/10/09 03:57:25 | 000,023,044 | —- | C] () – C:\WINDOWS\System32\sorttbls.nls
[2010/10/09 03:57:15 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\share.exe
[2010/10/09 03:57:15 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\dllcache\share.exe
[2010/10/09 03:57:14 | 000,011,753 | —- | C] () – C:\WINDOWS\System32\setver.exe
[2010/10/09 03:57:13 | 000,240,120 | —- | C] () – C:\WINDOWS\System32\setup.bmp
[2010/10/09 03:57:13 | 000,059,167 | —- | C] () – C:\WINDOWS\System\setup.inf
[2010/10/09 03:57:12 | 000,033,464 | —- | C] () – C:\WINDOWS\System32\services.msc
[2010/10/09 03:57:12 | 000,007,116 | —- | C] () – C:\WINDOWS\System32\drivers\etc\services
[2010/10/09 03:57:10 | 000,036,364 | —- | C] () – C:\WINDOWS\System32\secpol.msc
[2010/10/09 03:57:09 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\scriptpw.dll
[2010/10/09 03:57:02 | 000,044,451 | R— | C] () – C:\WINDOWS\System32\rsop.msc
[2010/10/09 03:57:02 | 000,003,178 | —- | C] () – C:\WINDOWS\System32\rsvpcnts.h
[2010/10/09 03:57:01 | 000,003,167 | —- | C] () – C:\WINDOWS\System32\rsaci.rat
[2010/10/09 03:56:56 | 000,003,338 | —- | C] () – C:\WINDOWS\System32\redir.exe
[2010/10/09 03:56:52 | 000,001,818 | —- | C] () – C:\WINDOWS\System32\rasctrnm.h
[2010/10/09 03:56:44 | 000,003,708 | —- | C] () – C:\WINDOWS\System32\pubprn.vbs
[2010/10/09 03:56:44 | 000,003,708 | —- | C] () – C:\WINDOWS\System32\dllcache\pubprn.vbs
[2010/10/09 03:56:43 | 000,003,010 | —- | C] () – C:\WINDOWS\System32\pschdcnt.h
[2010/10/09 03:56:43 | 000,000,051 | —- | C] () – C:\WINDOWS\System32\pscript.sep
[2010/10/09 03:56:42 | 000,000,799 | —- | C] () – C:\WINDOWS\System32\drivers\etc\protocol
[2010/10/09 03:56:41 | 000,035,755 | —- | C] () – C:\WINDOWS\System32\prncnfg.vbs
[2010/10/09 03:56:41 | 000,035,755 | —- | C] () – C:\WINDOWS\System32\dllcache\prncnfg.vbs
[2010/10/09 03:56:41 | 000,032,546 | —- | C] () – C:\WINDOWS\System32\prnmngr.vbs
[2010/10/09 03:56:41 | 000,032,546 | —- | C] () – C:\WINDOWS\System32\dllcache\prnmngr.vbs
[2010/10/09 03:56:41 | 000,029,454 | —- | C] () – C:\WINDOWS\System32\prnport.vbs
[2010/10/09 03:56:41 | 000,029,454 | —- | C] () – C:\WINDOWS\System32\dllcache\prnport.vbs
[2010/10/09 03:56:41 | 000,025,415 | —- | C] () – C:\WINDOWS\System32\prndrvr.vbs
[2010/10/09 03:56:41 | 000,025,415 | —- | C] () – C:\WINDOWS\System32\dllcache\prndrvr.vbs
[2010/10/09 03:56:41 | 000,021,527 | —- | C] () – C:\WINDOWS\System32\prnjobs.vbs
[2010/10/09 03:56:41 | 000,021,527 | —- | C] () – C:\WINDOWS\System32\dllcache\prnjobs.vbs
[2010/10/09 03:56:41 | 000,015,860 | —- | C] () – C:\WINDOWS\System32\prnqctl.vbs
[2010/10/09 03:56:41 | 000,015,860 | —- | C] () – C:\WINDOWS\System32\dllcache\prnqctl.vbs
[2010/10/09 03:56:35 | 000,000,435 | —- | C] () – C:\WINDOWS\System32\perfwci.h
[2010/10/09 03:56:34 | 000,311,934 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/09 03:56:34 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2010/10/09 03:56:34 | 000,058,273 | R— | C] () – C:\WINDOWS\System32\perfmon.msc
[2010/10/09 03:56:34 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2010/10/09 03:56:34 | 000,000,140 | —- | C] () – C:\WINDOWS\System32\perffilt.h
[2010/10/09 03:56:33 | 000,040,196 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/09 03:56:33 | 000,000,427 | —- | C] () – C:\WINDOWS\System32\perfci.h
[2010/10/09 03:56:31 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\pcl.sep
[2010/10/09 03:56:26 | 000,167,219 | —- | C] () – C:\WINDOWS\System32\pagefileconfig.vbs
[2010/10/09 03:56:26 | 000,167,219 | —- | C] () – C:\WINDOWS\System32\dllcache\pagefile.vbs
[2010/10/09 03:56:19 | 000,006,761 | —- | C] () – C:\WINDOWS\System32\oembios.sig
[2010/10/09 03:56:19 | 000,006,761 | —- | C] () – C:\WINDOWS\System32\dllcache\oembios.sig
[2010/10/09 03:56:19 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2010/10/09 03:56:19 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\dllcache\oembios.dat
[2010/10/09 03:56:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2010/10/09 03:56:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\dllcache\oembios.bin
[2010/10/09 03:56:05 | 000,004,310 | —- | C] () – C:\WINDOWS\System32\odbcconf.rsp
[2010/10/09 03:56:03 | 000,003,252 | —- | C] () – C:\WINDOWS\System32\nw16.exe
[2010/10/09 03:56:03 | 000,003,252 | —- | C] () – C:\WINDOWS\System32\dllcache\nw16.exe
[2010/10/09 03:56:00 | 000,032,968 | —- | C] () – C:\WINDOWS\System32\ntmsoprq.msc
[2010/10/09 03:56:00 | 000,026,209 | —- | C] () – C:\WINDOWS\System32\ntmsmgr.msc
[2010/10/09 03:55:59 | 000,048,794 | —- | C] () – C:\WINDOWS\System32\ntimage.gif
[2010/10/09 03:55:58 | 000,029,146 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos804.sys
[2010/10/09 03:55:57 | 000,029,370 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos411.sys
[2010/10/09 03:55:57 | 000,029,274 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos412.sys
[2010/10/09 03:55:57 | 000,029,146 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos404.sys
[2010/10/09 03:55:57 | 000,027,866 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos.sys
[2010/10/09 03:55:54 | 000,149,848 | —- | C] () – C:\WINDOWS\System32\noise.deu
[2010/10/09 03:55:54 | 000,049,196 | —- | C] () – C:\WINDOWS\System32\noise.fra
[2010/10/09 03:55:54 | 000,019,684 | —- | C] () – C:\WINDOWS\System32\noise.esn
[2010/10/09 03:55:54 | 000,019,618 | —- | C] () – C:\WINDOWS\System32\noise.ita
[2010/10/09 03:55:54 | 000,013,730 | —- | C] () – C:\WINDOWS\System32\noise.sve
[2010/10/09 03:55:54 | 000,013,256 | —- | C] () – C:\WINDOWS\System32\noise.nld
[2010/10/09 03:55:54 | 000,000,751 | —- | C] () – C:\WINDOWS\System32\noise.enu
[2010/10/09 03:55:54 | 000,000,751 | —- | C] () – C:\WINDOWS\System32\noise.eng
[2010/10/09 03:55:54 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2010/10/09 03:55:53 | 000,007,052 | —- | C] () – C:\WINDOWS\System32\nlsfunc.exe
[2010/10/09 03:55:53 | 000,007,052 | —- | C] () – C:\WINDOWS\System32\dllcache\nlsfunc.exe
[2010/10/09 03:55:51 | 000,000,407 | —- | C] () – C:\WINDOWS\System32\drivers\etc\networks
[2010/10/09 03:55:46 | 000,102,446 | —- | C] () – C:\WINDOWS\System32\net.hlp
[2010/10/09 03:55:24 | 000,844,314 | —- | C] () – C:\WINDOWS\System32\msdxm.ocx
[2010/10/09 03:55:22 | 000,000,817 | —- | C] () – C:\WINDOWS\System32\mscdexnt.exe
[2010/10/09 03:55:22 | 000,000,817 | —- | C] () – C:\WINDOWS\System32\dllcache\mscdexnt.exe
[2010/10/09 03:55:16 | 000,002,755 | —- | C] () – C:\WINDOWS\System32\mqprfsym.h
[2010/10/09 03:55:15 | 000,148,992 | —- | C] () – C:\WINDOWS\System32\mpg2splt.ax
[2010/10/09 03:55:11 | 000,001,492 | —- | C] () – C:\WINDOWS\System32\mmdriver.inf
[2010/10/09 03:55:10 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2010/10/09 03:55:09 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2010/10/09 03:55:06 | 000,039,274 | —- | C] () – C:\WINDOWS\System32\mem.exe
[2010/10/09 03:55:06 | 000,039,274 | —- | C] () – C:\WINDOWS\System32\dllcache\mem.exe
[2010/10/09 03:54:59 | 000,042,166 | —- | C] () – C:\WINDOWS\System32\lusrmgr.msc
[2010/10/09 03:54:57 | 000,265,948 | —- | C] () – C:\WINDOWS\System32\locale.nls
[2010/10/09 03:54:57 | 000,000,487 | —- | C] () – C:\WINDOWS\System32\login.cmd
[2010/10/09 03:54:56 | 000,003,683 | —- | C] () – C:\WINDOWS\System32\drivers\etc\lmhosts.sam
[2010/10/09 03:54:56 | 000,001,131 | —- | C] () – C:\WINDOWS\System32\loadfix.com
[2010/10/09 03:54:54 | 000,007,046 | —- | C] () – C:\WINDOWS\System32\l_intl.nls
[2010/10/09 03:54:54 | 000,000,168 | —- | C] () – C:\WINDOWS\System32\l_except.nls
[2010/10/09 03:54:53 | 000,042,809 | —- | C] () – C:\WINDOWS\System32\dllcache\key01.sys
[2010/10/09 03:54:53 | 000,042,537 | —- | C] () – C:\WINDOWS\System32\dllcache\keyboard.sys
[2010/10/09 03:54:50 | 000,014,710 | —- | C] () – C:\WINDOWS\System32\kb16.com
[2010/10/09 03:54:43 | 000,956,990 | —- | C] () – C:\WINDOWS\System32\instcat.sql
[2010/10/09 03:54:29 | 000,000,929 | —- | C] () – C:\WINDOWS\System32\homepage.inf
[2010/10/09 03:54:27 | 000,004,768 | —- | C] () – C:\WINDOWS\System32\dllcache\himem.sys
[2010/10/09 03:54:23 | 000,021,232 | —- | C] () – C:\WINDOWS\System32\graphics.pro
[2010/10/09 03:54:23 | 000,019,694 | —- | C] () – C:\WINDOWS\System32\graphics.com
[2010/10/09 03:54:22 | 000,034,871 | —- | C] () – C:\WINDOWS\System32\gpedit.msc
[2010/10/09 03:54:20 | 003,440,660 | —- | C] () – C:\WINDOWS\System32\drivers\gm.dls
[2010/10/09 03:54:20 | 000,024,772 | —- | C] () – C:\WINDOWS\System32\geo.nls
[2010/10/09 03:54:15 | 000,152,844 | —- | C] () – C:\WINDOWS\System32\dllcache\framdit.ttf
[2010/10/09 03:54:15 | 000,135,984 | —- | C] () – C:\WINDOWS\System32\dllcache\framd.ttf
[2010/10/09 03:54:15 | 000,032,760 | —- | C] () – C:\WINDOWS\System32\fsmgmt.msc
[2010/10/09 03:54:09 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\fastopen.exe
[2010/10/09 03:54:09 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\dllcache\fastopen.exe
[2010/10/09 03:54:08 | 000,000,080 | —- | C] () – C:\WINDOWS\explorer.scf
[2010/10/09 03:54:04 | 000,097,965 | —- | C] () – C:\WINDOWS\System32\dllcache\evtquery.vbs
[2010/10/09 03:54:04 | 000,097,965 | —- | C] () – C:\WINDOWS\System32\eventquery.vbs
[2010/10/09 03:54:04 | 000,008,424 | —- | C] () – C:\WINDOWS\System32\exe2bin.exe
[2010/10/09 03:54:04 | 000,008,424 | —- | C] () – C:\WINDOWS\System32\dllcache\exe2bin.exe
[2010/10/09 03:54:03 | 000,056,678 | —- | C] () – C:\WINDOWS\System32\eventvwr.msc
[2010/10/09 03:54:01 | 000,006,708 | —- | C] () – C:\WINDOWS\System32\esentprf.hxx
[2010/10/09 03:53:59 | 000,012,642 | —- | C] () – C:\WINDOWS\System32\edlin.exe
[2010/10/09 03:53:59 | 000,012,642 | —- | C] () – C:\WINDOWS\System32\dllcache\edlin.exe
[2010/10/09 03:53:53 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2010/10/09 03:53:52 | 000,000,081 | —- | C] () – C:\WINDOWS\System32\dsound.vxd
[2010/10/09 03:53:18 | 000,053,840 | —- | C] () – C:\WINDOWS\System32\dosx.exe
[2010/10/09 03:53:16 | 000,033,673 | —- | C] () – C:\WINDOWS\System32\diskmgmt.msc
[2010/10/09 03:53:13 | 000,041,397 | —- | C] () – C:\WINDOWS\System32\dfrg.msc
[2010/10/09 03:53:13 | 000,033,079 | —- | C] () – C:\WINDOWS\System32\devmgmt.msc
[2010/10/09 03:53:13 | 000,020,634 | —- | C] () – C:\WINDOWS\System32\dllcache\debug.exe
[2010/10/09 03:53:13 | 000,020,634 | —- | C] () – C:\WINDOWS\System32\debug.exe
[2010/10/09 03:53:12 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2010/10/09 03:53:10 | 000,008,386 | —- | C] () – C:\WINDOWS\System32\ctype.nls
[2010/10/09 03:53:08 | 000,027,097 | —- | C] () – C:\WINDOWS\System32\dllcache\country.sys
[2010/10/09 03:53:06 | 000,038,302 | —- | C] () – C:\WINDOWS\System32\compmgmt.msc
[2010/10/09 03:53:05 | 000,050,620 | —- | C] () – C:\WINDOWS\System32\command.com
[2010/10/09 03:53:04 | 000,061,172 | —- | C] () – C:\WINDOWS\System32\cmmgr32.hlp
[2010/10/09 03:53:04 | 000,040,505 | —- | C] () – C:\WINDOWS\System32\cmdlib.wsc
[2010/10/09 03:53:04 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\cmos.ram
[2010/10/09 03:53:03 | 000,071,859 | —- | C] () – C:\WINDOWS\System32\cliconf.chm
[2010/10/09 03:53:01 | 000,041,762 | —- | C] () – C:\WINDOWS\System32\ciadv.msc
[2010/10/09 03:53:00 | 000,042,339 | —- | C] () – C:\WINDOWS\System32\certmgr.msc
[2010/10/09 03:53:00 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\View Channels.scf
[2010/10/09 03:52:57 | 000,196,642 | —- | C] () – C:\WINDOWS\System32\c_950.nls
[2010/10/09 03:52:57 | 000,196,642 | —- | C] () – C:\WINDOWS\System32\c_949.nls
[2010/10/09 03:52:57 | 000,196,642 | —- | C] () – C:\WINDOWS\System32\c_936.nls
[2010/10/09 03:52:57 | 000,162,850 | —- | C] () – C:\WINDOWS\System32\c_932.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_874.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_865.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_863.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_861.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_860.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_850.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_775.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_437.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_500.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28605.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28598.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28593.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28592.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28591.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_21866.nls
[2010/10/09 03:52:56 | 000,139,810 | —- | C] () – C:\WINDOWS\System32\c_20261.nls
[2010/10/09 03:52:56 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_20905.nls
[2010/10/09 03:52:56 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_20866.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1258.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1257.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1256.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1255.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1254.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1253.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1252.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1251.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1250.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1026.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10079.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10000.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_037.nls
[2010/10/09 03:52:53 | 000,028,420 | —- | C] () – C:\WINDOWS\System32\bios1.rom
[2010/10/09 03:52:53 | 000,008,191 | —- | C] () – C:\WINDOWS\System32\bios4.rom
[2010/10/09 03:52:47 | 000,012,498 | —- | C] () – C:\WINDOWS\System32\dllcache\append.exe
[2010/10/09 03:52:47 | 000,012,498 | —- | C] () – C:\WINDOWS\System32\append.exe
[2010/10/09 03:52:47 | 000,009,029 | —- | C] () – C:\WINDOWS\System32\dllcache\ansi.sys
[2010/10/09 03:52:43 | 000,002,233 | —- | C] () – C:\WINDOWS\System32\dllcache\12520850.cpx
[2010/10/09 03:52:43 | 000,002,233 | —- | C] () – C:\WINDOWS\System32\12520850.cpx
[2010/10/09 03:52:43 | 000,002,151 | —- | C] () – C:\WINDOWS\System32\dllcache\12520437.cpx
[2010/10/09 03:52:43 | 000,002,151 | —- | C] () – C:\WINDOWS\System32\12520437.cpx
[2010/10/09 03:52:43 | 000,000,707 | —- | C] () – C:\WINDOWS\_default.pif
[2010/09/28 13:49:56 | 000,000,070 | —- | C] () – C:\AUTOEXEC.BAT
[2010/09/28 13:49:56 | 000,000,040 | —- | C] () – C:\CONFIG.SYS
[2010/09/27 15:45:49 | 000,004,981 | —- | C] () – C:\SiSUnist.ini
[2010/09/27 15:45:49 | 000,003,917 | —- | C] () – C:\SiSSetup1.ini
[2010/09/27 15:44:58 | 000,049,152 | —- | C] () – C:\OEMROM.BIN
[2010/09/27 15:24:57 | 000,000,070 | —- | C] () – C:\AUTOEXEC.NS0
[2010/09/27 15:24:57 | 000,000,040 | —- | C] () – C:\CONFIG.NS0
[2010/09/27 15:16:00 | 000,049,152 | -HS- | C] () – C:\VIDEOROM.BIN
[2010/09/27 15:15:40 | 000,046,548 | -HS- | C] () – C:\BOOTLOG.PRV
[2010/09/27 15:14:32 | 000,011,079 | —- | C] () – C:\Program Files\folder.htt
[2010/09/27 00:20:15 | 000,002,000 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\HiJackThis.lnk
[2010/09/27 00:04:56 | 000,305,771 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\HijackThis.zip
[2010/09/26 23:17:36 | 001,402,880 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\Verns Fix.msi
[2010/09/26 22:25:07 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/09/26 22:25:07 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/09/26 22:25:07 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/09/26 22:25:07 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/09/26 22:25:07 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/09/26 22:22:12 | 003,854,581 | R— | C] () – C:\Documents and Settings\Vern McKinney\Desktop\ComboFix.exe
[2010/09/26 15:11:00 | 000,000,845 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2010/09/18 16:32:18 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/09/18 16:30:16 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/18 16:19:11 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/09/18 16:19:11 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/09/15 18:25:16 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/09/06 16:56:36 | 000,001,552 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\CCleaner.lnk
[2010/08/25 19:50:01 | 000,000,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/24 21:07:48 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/08/24 21:07:45 | 000,260,272 | —- | C] () – C:\cmldr
[2010/08/05 23:53:21 | 014,306,443 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DMV HearingPictures.zip
[2010/08/01 20:37:03 | 000,025,600 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Discussion Topic.doc
[2010/07/20 19:23:56 | 000,084,480 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Poker%20Run[1].doc
[2010/07/05 16:05:57 | 000,020,992 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Crockett Monday Night.doc
[2010/07/04 03:12:17 | 000,001,455 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\WebEx Player.LNK
[2010/05/22 15:22:13 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/13 00:55:04 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/03/22 17:05:18 | 000,000,102 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2008/04/10 19:47:59 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2007/10/28 14:01:06 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\TVModeLib.dll
[2007/10/28 14:01:05 | 000,034,915 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2007/10/28 14:01:05 | 000,016,819 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2007/10/28 13:59:58 | 000,000,000 | —- | C] () – C:\WINDOWS\khooker.INI
[2007/07/25 21:49:33 | 000,000,051 | —- | C] () – C:\WINDOWS\ASAPrep.ini
[2006/12/18 21:08:58 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/04/14 17:09:47 | 000,005,147 | —- | C] () – C:\Documents and Settings\Vern McKinney\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/04/14 17:09:47 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/02/20 18:10:02 | 000,000,008 | —- | C] () – C:\WINDOWS\sdcomchk.ini
[2006/01/17 12:34:37 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/01/16 02:03:25 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2006/01/16 01:13:18 | 000,023,847 | —- | C] () – C:\WINDOWS\stub14.ini
[2006/01/15 07:13:37 | 000,025,035 | —- | C] () – C:\WINDOWS\stub41.ini
[2006/01/15 07:13:37 | 000,024,667 | —- | C] () – C:\WINDOWS\stub50.ini
[2006/01/05 10:20:09 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\bxquv.dll
[2006/01/03 22:51:43 | 000,022,742 | —- | C] () – C:\WINDOWS\stub91.ini
[2006/01/03 22:51:08 | 000,025,728 | —- | C] () – C:\WINDOWS\stub90.ini
[2006/01/03 22:35:28 | 000,025,441 | —- | C] () – C:\WINDOWS\stub89.ini
[2006/01/03 22:34:26 | 000,025,543 | —- | C] () – C:\WINDOWS\stub88.ini
[2006/01/03 22:30:11 | 000,025,695 | —- | C] () – C:\WINDOWS\stub87.ini
[2006/01/03 22:30:09 | 000,025,438 | —- | C] () – C:\WINDOWS\stub86.ini
[2006/01/02 23:54:39 | 000,025,197 | —- | C] () – C:\WINDOWS\stub85.ini
[2006/01/02 23:52:42 | 000,025,684 | —- | C] () – C:\WINDOWS\stub84.ini
[2006/01/02 23:51:26 | 000,026,118 | —- | C] () – C:\WINDOWS\stub83.ini
[2006/01/02 23:50:52 | 000,025,882 | —- | C] () – C:\WINDOWS\stub82.ini
[2006/01/02 23:49:30 | 000,026,444 | —- | C] () – C:\WINDOWS\stub81.ini
[2006/01/02 23:48:14 | 000,025,840 | —- | C] () – C:\WINDOWS\stub80.ini
[2006/01/02 23:44:42 | 000,025,314 | —- | C] () – C:\WINDOWS\stub79.ini
[2006/01/02 23:44:16 | 000,025,812 | —- | C] () – C:\WINDOWS\stub78.ini
[2006/01/02 23:43:51 | 000,025,329 | —- | C] () – C:\WINDOWS\stub77.ini
[2006/01/02 23:42:56 | 000,026,785 | —- | C] () – C:\WINDOWS\stub76.ini
[2006/01/02 23:42:32 | 000,026,386 | —- | C] () – C:\WINDOWS\stub75.ini
[2006/01/02 23:42:18 | 000,026,446 | —- | C] () – C:\WINDOWS\stub74.ini
[2006/01/02 23:41:17 | 000,026,417 | —- | C] () – C:\WINDOWS\stub73.ini
[2006/01/02 23:40:57 | 000,026,300 | —- | C] () – C:\WINDOWS\stub72.ini
[2006/01/02 23:40:25 | 000,026,413 | —- | C] () – C:\WINDOWS\stub71.ini
[2006/01/02 23:39:36 | 000,025,626 | —- | C] () – C:\WINDOWS\stub70.ini
[2006/01/02 23:39:11 | 000,025,949 | —- | C] () – C:\WINDOWS\stub69.ini
[2006/01/02 23:37:46 | 000,026,241 | —- | C] () – C:\WINDOWS\stub67.ini
[2006/01/02 23:36:24 | 000,026,472 | —- | C] () – C:\WINDOWS\stub66.ini
[2006/01/02 15:02:42 | 000,024,410 | —- | C] () – C:\WINDOWS\stub31.ini
[2006/01/02 15:02:42 | 000,022,711 | —- | C] () – C:\WINDOWS\stub2.ini
[2006/01/01 23:27:05 | 000,026,174 | —- | C] () – C:\WINDOWS\stub65.ini
[2006/01/01 22:54:32 | 000,024,912 | —- | C] () – C:\WINDOWS\stub64.ini
[2006/01/01 22:38:50 | 000,025,074 | —- | C] () – C:\WINDOWS\stub63.ini
[2006/01/01 22:38:16 | 000,025,293 | —- | C] () – C:\WINDOWS\stub62.ini
[2006/01/01 22:34:30 | 000,025,066 | —- | C] () – C:\WINDOWS\stub61.ini
[2006/01/01 06:36:49 | 000,024,565 | —- | C] () – C:\WINDOWS\stub27.ini
[2005/12/31 23:11:39 | 000,025,594 | —- | C] () – C:\WINDOWS\stub60.ini
[2005/12/31 23:11:26 | 000,025,271 | —- | C] () – C:\WINDOWS\stub59.ini
[2005/12/31 23:11:11 | 000,026,307 | —- | C] () – C:\WINDOWS\stub58.ini
[2005/12/31 23:10:59 | 000,025,008 | —- | C] () – C:\WINDOWS\stub57.ini
[2005/12/31 23:10:20 | 000,025,293 | —- | C] () – C:\WINDOWS\stub55.ini
[2005/12/31 23:09:40 | 000,025,311 | —- | C] () – C:\WINDOWS\stub54.ini
[2005/12/31 23:09:20 | 000,025,635 | —- | C] () – C:\WINDOWS\stub53.ini
[2005/12/31 23:09:07 | 000,025,546 | —- | C] () – C:\WINDOWS\stub52.ini
[2005/12/31 23:08:50 | 000,025,592 | —- | C] () – C:\WINDOWS\stub51.ini
[2005/12/31 23:06:55 | 000,024,795 | —- | C] () – C:\WINDOWS\stub49.ini
[2005/12/31 22:58:54 | 000,024,921 | —- | C] () – C:\WINDOWS\stub47.ini
[2005/12/31 22:58:30 | 000,025,352 | —- | C] () – C:\WINDOWS\stub46.ini
[2005/12/31 22:58:13 | 000,024,766 | —- | C] () – C:\WINDOWS\stub45.ini
[2005/12/31 22:57:57 | 000,024,710 | —- | C] () – C:\WINDOWS\stub44.ini
[2005/12/31 22:57:48 | 000,025,043 | —- | C] () – C:\WINDOWS\stub43.ini
[2005/12/31 22:57:24 | 000,024,914 | —- | C] () – C:\WINDOWS\stub42.ini
[2005/12/31 22:56:49 | 000,024,703 | —- | C] () – C:\WINDOWS\stub40.ini
[2005/12/31 22:54:59 | 000,024,420 | —- | C] () – C:\WINDOWS\stub39.ini
[2005/12/31 22:50:21 | 000,024,711 | —- | C] () – C:\WINDOWS\stub38.ini
[2005/12/31 22:49:58 | 000,024,442 | —- | C] () – C:\WINDOWS\stub37.ini
[2005/12/31 06:56:46 | 000,024,305 | —- | C] () – C:\WINDOWS\stub35.ini
[2005/12/31 06:56:28 | 000,024,912 | —- | C] () – C:\WINDOWS\stub34.ini
[2005/12/31 06:56:01 | 000,024,391 | —- | C] () – C:\WINDOWS\stub33.ini
[2005/12/31 06:54:49 | 000,024,809 | —- | C] () – C:\WINDOWS\stub30.ini
[2005/12/31 06:54:16 | 000,024,364 | —- | C] () – C:\WINDOWS\stub29.ini
[2005/12/31 06:54:01 | 000,024,101 | —- | C] () – C:\WINDOWS\stub28.ini
[2005/12/31 06:53:11 | 000,023,818 | —- | C] () – C:\WINDOWS\stub26.ini
[2005/12/31 06:52:53 | 000,023,904 | —- | C] () – C:\WINDOWS\stub25.ini
[2005/12/31 06:52:41 | 000,023,580 | —- | C] () – C:\WINDOWS\stub24.ini
[2005/12/31 06:52:24 | 000,024,085 | —- | C] () – C:\WINDOWS\stub23.ini
[2005/12/31 06:52:06 | 000,023,060 | —- | C] () – C:\WINDOWS\stub22.ini
[2005/12/31 06:51:20 | 000,023,219 | —- | C] () – C:\WINDOWS\stub21.ini
[2005/12/31 06:50:55 | 000,023,685 | —- | C] () – C:\WINDOWS\stub20.ini
[2005/12/31 06:50:45 | 000,022,835 | —- | C] () – C:\WINDOWS\stub19.ini
[2005/12/31 06:50:30 | 000,022,118 | —- | C] () – C:\WINDOWS\stub18.ini
[2005/12/31 06:48:51 | 000,023,395 | —- | C] () – C:\WINDOWS\stub17.ini
[2005/12/31 06:48:29 | 000,023,622 | —- | C] () – C:\WINDOWS\stub16.ini
[2005/12/31 06:48:02 | 000,023,264 | —- | C] () – C:\WINDOWS\stub15.ini
[2005/12/31 06:25:39 | 000,023,745 | —- | C] () – C:\WINDOWS\stub13.ini
[2005/12/31 06:25:14 | 000,023,567 | —- | C] () – C:\WINDOWS\stub12.ini
[2005/12/31 06:17:39 | 000,023,501 | —- | C] () – C:\WINDOWS\stub11.ini
[2005/12/31 06:12:33 | 000,023,416 | —- | C] () – C:\WINDOWS\stub10.ini
[2005/12/31 06:11:41 | 000,023,496 | —- | C] () – C:\WINDOWS\stub9.ini
[2005/12/29 23:44:51 | 000,023,318 | —- | C] () – C:\WINDOWS\stub8.ini
[2005/12/29 23:42:15 | 000,023,344 | —- | C] () – C:\WINDOWS\stub7.ini
[2005/12/29 23:41:23 | 000,023,619 | —- | C] () – C:\WINDOWS\stub6.ini
[2005/12/29 23:40:29 | 000,023,500 | —- | C] () – C:\WINDOWS\stub5.ini
[2005/12/29 23:29:43 | 000,023,246 | —- | C] () – C:\WINDOWS\stub4.ini
[2005/12/29 23:22:39 | 000,023,166 | —- | C] () – C:\WINDOWS\stub3.ini
[2005/12/26 04:34:50 | 000,025,914 | —- | C] () – C:\WINDOWS\stub68.ini
[2005/12/26 04:34:50 | 000,025,158 | —- | C] () – C:\WINDOWS\stub56.ini
[2005/12/22 13:35:45 | 000,024,735 | —- | C] () – C:\WINDOWS\stub36.ini
[2005/12/22 13:14:17 | 000,024,864 | —- | C] () – C:\WINDOWS\stub48.ini
[2005/12/20 11:39:42 | 000,000,000 | —- | C] () – C:\WINDOWS\logs2.ini
[2005/12/18 12:32:22 | 000,024,500 | —- | C] () – C:\WINDOWS\stub32.ini
[2005/08/08 18:01:14 | 000,000,363 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/07/06 23:46:19 | 000,000,695 | —- | C] () – C:\WINDOWS\GARMINWT.INI
[2005/04/01 16:16:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/03/26 12:30:29 | 000,000,090 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/01/16 13:09:56 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/12/11 16:42:01 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2004/10/18 23:03:52 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2004/10/09 23:20:36 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/10/09 23:20:36 | 000,000,023 | —- | C] () – C:\WINDOWS\mid.ini
[2004/10/09 22:14:10 | 000,000,196 | —- | C] () – C:\WINDOWS\aeirem.ini
[2004/03/30 00:15:02 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\ThriXXX010205PNG.dll
[2004/03/30 00:15:01 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\ThriXXX015003JP2.dll
[2004/03/30 00:15:01 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\ThriXXX010104Z.dll
[2003/07/14 12:30:28 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2003/05/23 03:08:52 | 000,107,008 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2003/05/23 03:08:52 | 000,020,992 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/12/05 18:51:00 | 000,059,392 | R— | C] () – C:\WINDOWS\streamhlp.dll
[1999/01/22 11:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2005/03/26 12:33:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2006/12/15 00:01:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2007/08/19 22:08:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/02/04 00:52:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2004/12/11 16:44:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2005/05/10 23:15:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Vern McKinney\Application Data\Leadertech
[2004/10/18 23:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Vern McKinney\Application Data\Nikon
[2007/02/04 00:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Vern McKinney\Application Data\Viewpoint
[2009/12/15 02:17:42 | 000,000,356 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/12/01 02:00:12 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/03/31 03:41:45 | 000,006,754 | —- | M] () – C:\artpdbg.log
[2010/09/28 13:49:58 | 000,000,070 | —- | M] () – C:\AUTOEXEC.BAT
[2004/09/27 14:52:16 | 000,000,038 | -HS- | M] () – C:\AUTOEXEC.DOS
[2010/09/27 15:15:32 | 000,000,070 | —- | M] () – C:\AUTOEXEC.NS0
[2010/08/24 20:36:30 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/24 21:07:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2006/11/19 22:46:01 | 000,012,504 | —- | M] () – C:\bootex.log
[2010/09/27 15:15:40 | 000,046,548 | -HS- | M] () – C:\BOOTLOG.PRV
[2010/09/27 15:28:12 | 000,050,892 | -HS- | M] () – C:\BOOTLOG.TXT
[2010/10/09 04:01:14 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2006/10/29 17:08:34 | 000,007,624 | —- | M] () – C:\caavsetup.log
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/09/26 22:35:30 | 000,023,139 | —- | M] () – C:\ComboFix.txt
[1999/04/23 15:22:00 | 000,093,890 | -HS- | M] () – C:\COMMAND.COM
[2005/12/24 14:52:29 | 000,002,855 | —- | M] () – C:\COMMAND.PIF
[2004/09/27 14:52:16 | 000,000,040 | -HS- | M] () – C:\CONFIG.DOS
[2010/09/27 15:15:32 | 000,000,040 | —- | M] () – C:\CONFIG.NS0
[2010/09/28 13:49:58 | 000,000,040 | —- | M] () – C:\CONFIG.SYS
[2004/09/27 15:08:38 | 000,072,494 | -HS- | M] () – C:\DETLOG.TXT
[2007/08/24 22:10:27 | 000,007,019 | —- | M] () – C:\dnsbak.reg
[2010/01/16 15:00:21 | 000,000,471 | —- | M] () – C:\FRONTPG.LOG
[2004/09/27 15:07:06 | 000,001,012 | —- | M] () – C:\FRUNLOG.TXT
[2007/08/26 05:40:57 | 000,001,268 | —- | M] () – C:\fsbl-20070826120353.log
[2007/09/01 00:34:59 | 000,000,920 | —- | M] () – C:\fsbl-20070901072420.log
[2007/09/01 00:49:39 | 000,000,920 | —- | M] () – C:\fsbl-20070901073754.log
[2007/09/01 01:00:34 | 000,000,920 | —- | M] () – C:\fsbl-20070901075045.log
[2007/09/01 10:47:19 | 000,000,920 | —- | M] () – C:\fsbl-20070901172824.log
[2007/09/02 11:02:11 | 000,000,920 | —- | M] () – C:\fsbl-20070902175050.log
[2007/09/02 12:19:18 | 000,000,920 | —- | M] () – C:\fsbl-20070902190259.log
[2007/09/03 09:18:36 | 000,000,922 | —- | M] () – C:\fsbl-20070903160204.log
[2007/08/26 05:02:53 | 000,904,048 | —- | M] (F-Secure Corporation) – C:\fsbl.exe
[1999/04/23 15:22:00 | 000,222,390 | RHS- | M] () – C:\IO.SYS
[2004/09/27 14:54:34 | 000,000,009 | -HS- | M] () – C:\MSDOS.—
[2004/09/27 15:09:34 | 000,001,685 | RHS- | M] () – C:\MSDOS.SYS
[2010/03/17 21:39:32 | 015,132,878 | —- | M] () – C:\NASA-2010 Blower & Gear Box- Compressed (zipped) Folder.zip
[2010/09/27 15:15:16 | 000,006,064 | -HS- | M] () – C:\NETLOG.TXT
[2004/10/10 11:47:59 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2010/08/24 20:02:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2001/12/07 04:04:30 | 000,049,152 | —- | M] () – C:\OEMROM.BIN
[2010/09/28 19:32:43 | 352,321,536 | -HS- | M] () – C:\pagefile.sys
[2008/09/05 16:53:36 | 000,003,650 | —- | M] () – C:\rapport.txt
[2010/09/26 22:24:17 | 000,000,385 | —- | M] () – C:\rkill.log
[2009/12/09 19:31:11 | 000,030,208 | —- | M] () – C:\San Mateo Bridge Pier # 1 Compressor Valve Temps.12-21-09.xls
[2010/09/27 15:22:44 | 000,000,436 | —- | M] () – C:\SCANDISK.LOG
[2010/09/27 15:15:16 | 000,120,590 | -HS- | M] () – C:\SETUPLOG.TXT
[2010/10/09 11:51:36 | 000,000,340 | —- | M] () – C:\SiSSetup.txt
[2010/10/09 11:51:24 | 000,003,917 | —- | M] () – C:\SiSSetup1.ini
[2010/10/09 11:50:42 | 000,004,981 | —- | M] () – C:\SiSUnist.ini
[2004/09/27 15:04:02 | 000,005,166 | -HS- | M] () – C:\SUHDLOG.DAT
[2004/09/27 15:04:02 | 000,585,760 | -HS- | M] () – C:\SYSTEM.1ST
[2010/09/27 15:16:00 | 000,049,152 | -HS- | M] () – C:\VIDEOROM.BIN
[2006/01/17 23:13:33 | 000,000,061 | —- | M] () – C:\vundofix.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/10/09 11:26:52 | 000,000,067 | -HS- | M] () – C:\WINDOWS\FONTS\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/09/27 15:14:34 | 000,000,266 | -HS- | M] () – C:\Program Files\desktop.ini
[2010/09/27 15:14:34 | 000,011,079 | —- | M] () – C:\Program Files\folder.htt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/10/09 04:06:00 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\config\default.sav
[2010/10/09 04:06:00 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\config\software.sav
[2010/10/09 04:06:00 | 000,397,312 | —- | M] () – C:\WINDOWS\SYSTEM32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/24 20:10:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/10/03 10:54:39 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/09 11:34:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/01/21 16:42:11 | 002,855,080 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\aawsepersonal.exe
[2007/08/26 04:50:38 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Vern McKinney\Desktop\ATF-Cleaner.exe
[2010/09/26 22:22:20 | 003,854,581 | R— | M] () – C:\Documents and Settings\Vern McKinney\Desktop\ComboFix.exe
[2006/01/19 18:27:03 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Vern McKinney\Desktop\cwshredder.exe
[2007/08/24 22:07:17 | 000,486,349 | —- | M] ( ) – C:\Documents and Settings\Vern McKinney\Desktop\Fixwareout.exe
[2010/09/28 19:23:17 | 000,921,512 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Vern McKinney\Desktop\Norton_Removal_Tool.exe
[2010/09/28 19:38:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >
[2010/09/28 13:51:56 | 008,028,298 | RH– | M] () – C:\Program Files\Internet Explorer\ie6bak.DAT

< %USERPROFILE%\My Documents\*.exe >
[2005/02/02 21:10:13 | 002,662,400 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\B&T Spindles.exe
[2010/07/23 18:27:35 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Vern McKinney\My Documents\IE 8.exe
[2003/10/15 08:47:24 | 001,221,659 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\MAT-V1-1.exe Aqu, screen saver.exe
[2007/07/25 20:51:31 | 000,196,608 | —- | M] ( ) – C:\Documents and Settings\Vern McKinney\My Documents\Prepware Updater.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2004/10/10 12:20:38 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/09/28 19:48:48 | 000,081,920 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >
[2005/01/28 13:44:28 | 000,192,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\INF\unregmp2.exe

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.exe >
[2008/04/13 17:12:28 | 001,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
[2002/08/20 15:08:38 | 000,069,663 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgsin.exe

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< %USERPROFILE%\Templates\*.tmp >

< %SYSTEMDRIVE%\explorexxx.exe\*.* >

< %Windir%\Installer\*.tmp >
[6 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]

< %systemroot%\System32\*.xco >

< %ProgramFiles%\system32\*.* >

< %systemroot%\System32\windos\*.* >

< %SystemRoot%\system32\sandbox\*.* >

< %SystemRoot%\system32\*.amo >

< %SystemRoot%\system32\Windows Live\*.* >

< %ProgramFiles%\logs\*.* >

< %ProgramFiles%\Bifrost\*.* >

< %SystemRoot%\system32\*.goo >

< %systemroot%\system32\IME\*.* >

< %systemroot%\BackUp\*.* >

< %systemroot%\system32\*.ico >

< %systemroot%\system\*.dat >

< %systemroot%\system\*.exe >

< %AppData%\Macromedia\Common\*.* >

< %SYSTEMDRIVE%\dir\*.* /s >

< %systemroot%\system32\ras\*.exe >

< %SYSTEMDRIVE%\MFILES\*.* >

< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >

< %systemroot%\system32\services\*.* >

< %systemroot%\Spooler\*.* >

< %ProgramFiles%\system32\*.* >

< %systemroot%\system32\Setup\*.dll /x >

< %systemroot%\system32\*.mine >

< %SYSTEMDRIVE%\cleansweep.exe\*.* >

< %systemroot%\system32\ras\*.dll >

< %systemroot%\system32\ras\*.drv >

< %systemroot%\*.iq >

< %systemroot%\system32\XP\*.* >

< %SYSTEMDRIVE%\Extracted\*.* >

< %systemroot%\system32\windows\*.* >

< %systemroot%\logs\*.* >

< %SYSTEMDRIVE%\Win.Msi\*.* >

< %systemroot%\regedit\*.* >

< %systemroot%\system32\skype\*.* >

< %AppData%\Adobe\dlluplwin25\*.* >

< %UserProfile%\*.dat >
[2010/09/28 19:32:11 | 009,699,328 | —- | M] () – C:\Documents and Settings\Vern McKinney\ntuser.dat

< %UserProfile%\*.dll >
[2006/05/30 23:01:09 | 000,229,376 | —- | M] () – C:\Documents and Settings\Vern McKinney\cwshredder.dll

< %systemroot%\system32\*.sxo >

< %SYSTEMDRIVE%\Gazma\*.* /s >

< %systemroot%\system32\spynet\*.* >

< %systemroot%\system32\System\*.* >

< %appdata%\Microsoft\Windows\*.* >

< %systemroot%\system32\WinDir\*.* >

< %systemroot%\_\*.* >

< %systemroot%\system32\windows32\*.* >

< %ProgramFiles%\win\*.* >

< %AppData%\Microsoft\CD Burning\*.* >

< %systemroot%\*.cab >

< %systemroot%\K.Backup\*.* >

< %ProgramFiles%\Massenger\*.* >

< %systemroot%\System32\*.doc >

< %systemroot%\Office12\*.* >

< %systemroot%\System32\Rundl32.exe\*.* >

< %ProgramFiles%\yahoo.net\*.* >

< %systemroot%\system32\*.igo >

< %systemroot%\*.rew >

< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2003/12/04 05:18:34 | 000,233,472 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzcfg09.exe
[2003/12/04 05:03:20 | 000,634,880 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzeng09.exe
[2006/03/02 18:49:14 | 000,069,632 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\HPZIPM12.EXE
[2003/12/04 05:27:46 | 000,323,584 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzpre09.exe
[2003/12/04 05:42:04 | 000,364,544 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzstc09.exe
[2003/12/04 05:10:38 | 000,163,840 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzstw09.exe
[2003/12/04 05:44:34 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpztbu09.exe
[2003/12/04 05:35:58 | 000,430,080 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpztbx09.exe
[2003/12/04 05:44:34 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpztsb09.exe

< %USERPROFILE%\.COMMgr\*.* >

< %USERPROFILE%\Desktop\*.bat >

< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
[2010/04/25 15:32:13 | 000,043,008 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv
[2010/04/25 15:32:13 | 000,080,384 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\CosmicBelt.rpv
[2010/04/25 15:32:14 | 000,007,168 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\Fire.rpv
[2010/04/25 15:32:14 | 000,007,680 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\FreqBands.rpv
[2010/04/25 15:32:14 | 000,069,632 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\Nebula.rpv
[2005/06/23 20:34:51 | 000,000,168 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\viz.ini

< %PROGRAMFILES%\Internet Explorer\*.Jmp >

< %PROGRAMFILES%\Windows NT\system\*.dll >

< %systemroot%\system32\*.ext >

< %systemroot%\system32\Com\*.cfg >

< %systemroot%\system32\btz\*.* >

< %systemroot%\system32\EMP\*.* >

< %systemroot%\system32\expo\*.* >

< %systemroot%\system32\inet2\*.* >

< %systemroot%\system32\xrem\*.* >

< %ProgramFiles%\Microsoft\*.* >

< %systemroot%\usgwmt\*.* >

< %ProgramFiles%\B\*.* >

< %SYSTEMDRIVE%\lspp\*.* >

< %systemroot%\Kral\*.* >

< %SYSTEMDRIVE%\windowsdvd.exe\*.* >

< %systemroot%\system32\*.ipo >

< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >

< %systemroot%\system32\*.mof >

< %systemroot%\*.atm >

< %systemroot%\system32\svhost\*.* >

< %ProgramFiles%\system32\*.* >

< %ProgramFiles%\Docmentt\*.* >

< %systemroot%\Help\*.vbs >

< %ProgramFiles%\Windows WinSxs\*.* /s >

< %ProgramFiles%\Outlook Express\IDT\*.* /s >

< %ProgramFiles%\Microsoft Office\365\*.* /s >

< %ProgramFiles%\Windows Live\*.* >

< %systemroot%\system32\win32\*.* >

< %SYSTEMDRIVE%\RECYCLER\*.* >

< %systemroot%\Fresh1\*.* >

< %ProgramFiles%\Kekj\*.* /s >

< %systemroot%\GDU\*.* >

< %systemroot%\KA\*.* >

< %systemroot%\R\*.* >

< %systemroot%\system32\*.fyo >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-29 00:47:43

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Vern McKinney\My Documents\Insurgent- The Last Campfire.dat:SummaryInformation
< End of report >
**************************************************************************
******************************************


Extras. Txt


OTL Extras logfile created on: 9/28/2010 7:54:04 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Vern McKinney\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,024.00 Mb Total Physical Memory | 540.00 Mb Available Physical Memory | 53.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 57.27 Gb Total Space | 41.14 Gb Free Space | 71.83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VERN-UUSAKGC8SQ
Current User Name: Vern McKinney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0a\waol.exe" = C:\Program Files\America Online 9.0a\waol.exe:*:Enabled:AMERIC~1.0A – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\SYSTEM32\mmc.exe" = C:\WINDOWS\SYSTEM32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{04AA1207-D8C6-45DC-A96D-48358EBE09F3}" = PSShortcuts
"{097346E0-6A51-11D1-AD16-00A0C95E0503}(SBC)" = Visual IP InSight(SBC)
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35AC130A-B7B4-4AA7-85EB-D0A7E10B927E}" = PS7900
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{517B8FB2-26EE-43B0-AE1B-07408860AA69}" = DigitImg
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5CB34832-06F1-4511-AFA6-DB1271C3F0EC}" = Actiontec USB/Ethernet Home DSL Monitor
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{779C40FF-9211-427B-A5C4-2026B85A1033}" = Nero 7 Essentials
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec USB/Ethernet Home DSL Modem
"{9DE006A5-B384-4EDE-A760-0F217136B9EA}" = Microsoft IntelliType Pro 2.2
"{AAB84E83-C8DF-4752-9DFC-2E2A48EE5E9F}" = Nikon View 6
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}" = Photosmart 140,240,7200,7600,7700,7900 Series
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EFE26D3B-2789-4068-A5BB-77E389FAEB98}" = PSUsage
"{F55C2350-0EEA-11D3-8257-00C04F6843FE}" = Customizable Alerts
"ActiveTouchMeetingClient" = WebEx
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"ArcSoft Software Suite" = ArcSoft Software Suite
"ASA - Prepware! GENERAL - AIRFRAME - POWERPLANT" = ASA - Prepware! GENERAL - AIRFRAME - POWERPLANT
"CCleaner" = CCleaner (remove only)
"DVD43_is1" = DVD43 v4.0.0
"hp instant support" = hp instant support
"ie8" = Windows Internet Explorer 8
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mavis Beacon Teaches Typing 16" = Mavis Beacon Teaches Typing 16
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"RealPlayer 12.0" = RealPlayer
"SiS 650" = SiS 650
"SiS7012" = SiS Audio Driver
"SiSLan" = SiS 900 PCI Fast Ethernet Adapter Driver
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SystemRequirementsLab" = System Requirements Lab
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Applications" = AT&T Yahoo! Applications

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/12/2004 6:23:18 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Error | ID = 1001
Description = Fault bucket 129432672.

Error - 12/17/2004 12:23:59 AM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/17/2004 12:24:05 AM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Hang | ID = 1001
Description = Fault bucket 126906962.

Error - 12/19/2004 6:13:07 PM | Computer Name = VERN-UUSAKGC8SQ | Source = MsiInstaller | ID = 1013
Description = Product: Adobe Acrobat - Reader 6.0.2 Update – This installer requires
Adobe Reader 6.0.1 or Adobe Acrobat 6.0.1 installed on your system. Please install
Reader 6.0.1 or Acrobat 6.0.1 before running this installer.

Error - 12/31/2004 8:26:40 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Error | ID = 1000
Description = Faulting application motivesb.exe, version 5.6.7.42730, faulting module
motivesb.exe, version 5.6.7.42730, fault address 0x000200c2.

Error - 12/31/2004 8:26:50 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Error | ID = 1001
Description = Fault bucket 83244579.

Error - 1/1/2005 4:49:12 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Hang | ID = 1002
Description = Hanging application ybrowser.exe, version 2003.7.14.2, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/1/2005 4:49:18 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Hang | ID = 1001
Description = Fault bucket 62666584.

Error - 1/1/2005 4:50:46 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Hang | ID = 1002
Description = Hanging application ybrowser.exe, version 2003.7.14.2, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/1/2005 4:51:11 PM | Computer Name = VERN-UUSAKGC8SQ | Source = Application Hang | ID = 1001
Description = Fault bucket 62666584.

[ System Events ]
Error - 10/16/2004 12:46:43 PM | Computer Name = VERN-UUSAKGC8SQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 10/16/2004 12:46:43 PM | Computer Name = VERN-UUSAKGC8SQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

Error - 10/16/2004 12:46:52 PM | Computer Name = VERN-UUSAKGC8SQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/16/2004 12:50:49 PM | Computer Name = VERN-UUSAKGC8SQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

Error - 10/16/2004 12:59:31 PM | Computer Name = VERN-UUSAKGC8SQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/29/2004 1:58:52 AM | Computer Name = VERN-UUSAKGC8SQ | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 968a001d, parameter2 00000000, parameter3
bf8408c4, parameter4 00000000.

Error - 11/2/2004 1:45:46 AM | Computer Name = VERN-UUSAKGC8SQ | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 11/2/2004 1:45:46 AM | Computer Name = VERN-UUSAKGC8SQ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 11/11/2004 2:14:15 AM | Computer Name = VERN-UUSAKGC8SQ | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 11/11/2004 2:14:15 AM | Computer Name = VERN-UUSAKGC8SQ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.


< End of report >
Thank you for the OTL logs. I do still need the GMER log. Please review the above directions for running DeFogger and GMER and post the results of the GMER scan in your next reply.

Also, since you recently ran Combofix can you please use Notepad to open the file C:\ComboFix.txt and copy and paste the contents in your reply as well.
(Note: If you are unable to retrieve this information please DO NOT re-run Combofix. It is a program that should only be run if you are directed to do so.)

Can you please check the date and time on your computer and let me know if they are correct? If you have to adjust either of them, can you please let me know how far off it was?

It appears this computer may have been stored for a few years and then brought back out. Can you please confirm?
Sorry for forgetting the Logs!
I also got a message after a scan before contacting you , That Said if I was having Internet Connection Problems to let my helper know that- "Double Left Click Registery File - dnsbak.reg - Located in the root of Drive Windows is installed (NormalC:) I did have Internet Connection problems ?
I hope you know what this means if anything?

One other issue, Befor running scans I dissable McAfee AntiVirus, and Restart in Safe Mode run. The last few times Combo Fix Starts to run and then Dissepears from the computer, Destop Icon and all, I restart in Safe Mode with Networking Download and install, and it will run fine untill the next time I try to run it ??? I thought it was McAfee but it is turned off and I can reinstall and run it??? I just thought this might be connected to a virus????

I did run ComboFix again by Mistake , Sorry I wasen't sure where the file was, and I didn't see your instructions Not To untill after ,. All the other scans put it on the Desktop! I ran it Before GMER or DeFogger. I hope this will not cause a big mess!

The Date and Time are Correct! And no the Computer has not been stored for several years or any amouant of time?
I hope this helps! Thanks For thr Help!!!!

I had already changed my Email Password and disconnected the links to Face Book ( Ididn't know there was such a link before)

Combo Fix Log

ComboFix 10-09-29.01 - Vern McKinney 09/29/2010 15:37:56.10.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1024.792 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.

2010-10-10 03:03 . 2010-10-10 03:03 ——– d—–w- c:\documents and settings\Vern McKinney\Local Settings\Application Data\Help
2010-10-10 03:03 . 2001-08-10 06:50 24848 —-a-w- c:\windows\system32\MSJTER35.DLL
2010-10-10 03:03 . 2001-08-10 06:50 123664 —-a-w- c:\windows\system32\MSJINT35.DLL
2010-10-10 03:03 . 2000-02-25 00:07 252176 —-a-w- c:\windows\system32\MSRD2X35.DLL
2010-10-10 03:03 . 1998-04-24 07:00 368912 —-a-w- c:\windows\system32\VBAR332.DLL
2010-10-10 03:03 . 1999-09-29 13:42 1050896 ——w- c:\windows\system32\msjet35.dll
2010-10-10 02:55 . 2010-10-10 02:55 ——– d—–w- c:\documents and settings\Vern McKinney\Application Data\Microsoft Web Folders
2010-10-09 18:51 . 2001-09-28 11:52 27008 -c–a-w- c:\windows\system32\dllcache\sisagp.sys
2010-10-09 18:51 . 2001-09-28 11:52 27008 —-a-w- c:\windows\system32\drivers\SISAGP.SYS
2010-10-09 18:47 . 2010-10-09 18:51 ——– d—–w- c:\windows\SiSAGP
2010-10-09 18:45 . 2001-08-17 20:57 16128 -c–a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-10-09 18:45 . 2001-08-17 20:57 16128 —-a-w- c:\windows\system32\drivers\MODEMCSA.sys
2010-10-09 18:39 . 2010-10-09 18:39 ——– d-s—w- c:\windows\system32\Microsoft
2010-10-09 18:39 . 2008-05-11 06:28 ——– d—–w- c:\program files\Common Files\Adobe
2010-10-09 18:38 . 2001-09-28 20:16 31744 —-a-r- c:\windows\system32\drivers\sisnic.sys
2010-10-09 18:38 . 2008-04-13 18:45 6272 —-a-w- c:\windows\system32\drivers\splitter.sys
2010-10-09 18:38 . 2008-04-13 19:17 83072 —-a-w- c:\windows\system32\drivers\wdmaud.sys
2010-10-09 18:38 . 2008-04-13 18:45 52864 —-a-w- c:\windows\system32\drivers\dmusic.sys
2010-10-09 18:38 . 2008-04-13 18:45 56576 —-a-w- c:\windows\system32\drivers\swmidi.sys
2010-10-09 18:36 . 2000-03-29 14:17 5824 —-a-w- c:\windows\system32\drivers\ASUSHWIO.SYS
2010-10-09 18:34 . 2010-09-21 13:59 ——– d—–w- c:\documents and settings\Vern McKinney\Local Settings\Application Data\Microsoft
2010-10-09 18:32 . 2004-10-10 19:22 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Microsoft
2010-10-09 18:32 . 2010-09-27 06:46 ——– d-sh–w- c:\documents and settings\LocalService
2010-10-09 18:32 . 2005-09-16 07:05 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Microsoft
2010-10-09 18:32 . 2010-09-27 14:06 ——– d-sh–w- c:\documents and settings\NetworkService
2010-10-09 18:29 . 2001-08-18 05:36 26112 -c–a-w- c:\windows\system32\dllcache\EXCH_seos.dll
2010-10-09 18:28 . 2001-08-23 12:00 132608 -c–a-w- c:\windows\system32\dllcache\fxsclntr.dll
2010-10-09 18:26 . 2007-02-12 04:00 ——– d-sh–w- c:\documents and settings\All Users\DRM
2010-10-09 18:24 . 2010-08-25 14:38 ——– d—–w- c:\windows\system32\wbem\Performance
2010-10-09 18:24 . 2010-09-29 22:09 ——– d—–w- c:\windows\system32\wbem\Logs
2010-10-09 18:24 . 2010-10-09 18:24 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-10-09 11:10 . 2001-08-17 13:59 3072 —-a-w- c:\windows\system32\drivers\audstub.sys
2010-10-09 11:10 . 2008-04-13 18:40 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2010-10-09 11:09 . 2008-04-13 18:45 10624 —-a-w- c:\windows\system32\drivers\gameenum.sys
2010-10-09 11:09 . 2008-04-14 00:12 74240 —-a-w- c:\windows\system32\usbui.dll
2010-10-09 11:07 . 2010-10-09 18:33 ——– d—–w- C:\Documents and Settings
2010-10-09 11:07 . 2010-10-09 18:33 ——– d–h–w- c:\documents and settings\Default User
2010-10-09 11:07 . 2005-01-15 17:03 ——– d—–w- c:\documents and settings\All Users
2010-10-09 11:00 . 2001-08-23 12:00 40448 -c–a-w- c:\windows\system32\dllcache\osuninst.exe
2010-10-09 10:59 . 2008-03-25 04:50 355104 —-a-w- c:\windows\system32\msxbde40.dll
2010-10-09 10:58 . 2008-04-14 00:12 338432 —-a-w- c:\windows\system32\zipfldr.dll
2010-10-09 10:57 . 2008-04-14 00:12 35840 —-a-w- c:\windows\system32\umandlg.dll
2010-10-09 10:56 . 2008-05-08 14:02 203136 —-a-w- c:\windows\system32\drivers\rmcast.sys
2010-10-09 10:55 . 2008-04-14 00:12 8192 —-a-w- c:\windows\system32\ntlsapi.dll
2010-10-09 10:54 . 2008-04-14 00:11 150528 —-a-w- c:\windows\system32\keymgr.dll
2010-10-09 10:53 . 2008-04-14 00:11 20480 —-a-w- c:\windows\system32\encapi.dll
2010-10-09 10:52 . 2009-08-07 02:24 96480 -c–a-w- c:\windows\system32\dllcache\cdm.dll
2010-10-09 10:49 . 2010-10-09 10:50 ——– d—–w- c:\windows\setup
2010-10-02 10:07 . 2007-12-19 05:49 ——– d—–w- C:\ASAPREP
2010-09-28 22:39 . 2010-09-28 22:39 ——– d-s—w- c:\windows\UserData
2010-09-28 21:59 . 2010-09-28 21:59 ——– d—–w- c:\windows\color
2010-09-28 21:59 . 2010-09-28 21:59 ——– d—–w- c:\program files\HP DeskJet 820C Series
2010-09-28 21:47 . 2010-09-28 21:47 ——– d—–w- c:\windows\Windows Update Setup Files
2010-09-28 21:08 . 2010-09-28 21:08 ——– d—–w- c:\program files\Common Files\aolback
2010-09-28 21:08 . 2010-09-28 21:08 ——– d—–w- c:\program files\Learn2.com
2010-09-28 21:08 . 2004-10-10 04:36 ——– d-s—w- c:\windows\occache
2010-09-28 21:08 . 2010-09-28 21:08 ——– d—–w- c:\program files\Viewpoint
2010-09-28 21:00 . 2010-09-28 21:00 ——– d—–w- c:\windows\system\mui
2010-09-28 20:51 . 2010-09-28 20:52 ——– d—–w- c:\windows\system\sfp
2010-09-28 20:51 . 2007-03-31 10:33 ——– d–h–w- c:\windows\msdownld.tmp
2010-09-28 20:51 . 2010-09-28 20:51 ——– d—–w- c:\windows\system\QuickTime
2010-09-28 20:50 . 2010-09-28 20:50 ——– d—–w- c:\program files\Common Files\Nullsoft
2010-09-28 20:50 . 2010-09-28 20:50 ——– d—–w- C:\My Music
2010-09-28 20:50 . 2010-04-25 22:29 ——– d—–w- c:\program files\Real
2010-09-28 20:50 . 2009-05-13 07:51 ——– d—–w- c:\program files\Common Files\Real
2010-09-28 20:48 . 2005-01-16 20:10 ——– d—–w- c:\program files\Common Files\AOL
2010-09-27 23:01 . 2010-09-27 23:01 ——– d—–w- c:\windows\Options
2010-09-27 22:58 . 2010-10-09 18:38 ——– d—–w- c:\program files\SiSLan
2010-09-27 22:47 . 2010-09-27 22:47 ——– d—–w- c:\program files\SiS7012
2010-09-27 22:45 . 2010-09-27 22:45 ——– d—–w- c:\windows\SiS
2010-09-27 22:45 . 2010-09-27 22:45 ——– d—–w- c:\windows\system\trayres
2010-09-27 22:44 . 2001-12-07 11:04 49152 —-a-w- C:\OEMROM.BIN
2010-09-27 22:44 . 2010-09-27 22:44 ——– d—–w- c:\program files\SiS_Compatible_VGA_V2.05a.01
2010-09-27 22:25 . 2010-09-29 02:31 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-09-27 22:24 . 2005-12-23 10:34 ——– d—–w- c:\program files\Norton SystemWorks
2010-09-27 22:20 . 2010-09-29 22:41 ——– d—–w- c:\windows\AppPatch
2010-09-27 22:20 . 2010-09-29 02:29 ——– d-sh–w- c:\windows\Installer
2010-09-27 22:20 . 2010-09-27 22:20 ——– d–h–w- c:\windows\PrintHood
2010-09-27 22:20 . 2010-09-27 22:20 ——– d—–w- c:\windows\Local Settings
2010-09-27 22:20 . 2004-10-10 03:31 ——– d—–w- c:\program files\Roxio
2010-09-27 22:16 . 2010-09-27 22:16 ——– d–h–w- c:\windows\NetHood
2010-09-27 22:16 . 2009-04-28 02:19 ——– d—–w- C:\My Documents
2010-09-27 22:16 . 2010-09-27 22:16 49152 –sha-w- C:\VIDEOROM.BIN
2010-09-27 22:15 . 2010-09-27 22:15 ——– d—–w- c:\windows\system\CatRoot
2010-09-27 22:15 . 2010-09-27 22:15 ——– d-s—w- c:\windows\Cookies
2010-09-27 22:15 . 2010-09-27 22:15 ——– d—–w- c:\program files\DirectX
2010-09-27 22:14 . 2010-09-27 22:14 ——– d-s—w- c:\windows\Favorites
2010-09-27 22:14 . 2010-07-04 10:12 ——– d-s—w- c:\windows\Downloaded Program Files
2010-09-27 22:13 . 2010-09-27 22:13 ——– d–h–w- c:\windows\Recent
2010-09-27 22:13 . 2010-09-27 22:13 ——– d—–w- c:\windows\SendTo
2010-09-27 22:13 . 2010-09-27 22:13 ——– d—–w- c:\windows\Start Menu
2010-09-27 22:13 . 2010-09-27 22:13 ——– d—–w- c:\windows\All Users
2010-09-27 14:06 . 2010-09-27 14:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-09-27 07:20 . 2010-09-27 07:20 388096 —-a-r- c:\documents and settings\Vern McKinney\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-18 23:31 . 2010-09-18 23:32 ——– d—–w- c:\program files\QuickTime
2010-09-18 23:31 . 2010-09-18 23:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-09-18 23:30 . 2010-09-18 23:30 ——– d—–w- c:\program files\Common Files\Apple
2010-09-18 23:30 . 2010-09-18 23:30 ——– d—–w- c:\documents and settings\Vern McKinney\Local Settings\Application Data\Apple
2010-09-18 23:30 . 2010-09-18 23:30 ——– d—–w- c:\program files\Apple Software Update
2010-09-18 23:30 . 2010-09-18 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-09-18 23:28 . 2010-09-18 23:28 ——– d—–w- c:\documents and settings\Vern McKinney\Local Settings\Application Data\Apple Computer
2010-09-06 23:56 . 2010-09-06 23:56 ——– d—–w- c:\program files\CCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-10 02:57 . 2010-10-10 02:57 5058 —-a-w- c:\windows\help\hhcolreg.dat
2010-10-10 02:54 . 2010-10-09 18:28 ——– d—–w- c:\program files\microsoft frontpage
2010-10-09 18:50 . 2010-10-09 18:50 ——– d—–w- c:\program files\SiS Compatible VGA V2.05a.01
2010-10-09 18:27 . 2010-10-09 18:27 558142 —-a-w- c:\windows\java\Packages\8LN9F7X7.ZIP
2010-10-09 18:27 . 2010-10-09 18:27 155995 —-a-w- c:\windows\java\Packages\YVPBZBXJ.ZIP
2010-09-27 22:14 . 2010-09-27 22:14 11079 —-a-w- c:\program files\folder.htt
2010-09-27 07:20 . 2006-01-17 19:34 ——– d—–w- c:\program files\Trend Micro
2010-09-25 04:13 . 2010-08-26 02:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-26 02:49 . 2010-08-26 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-26 02:44 . 2008-09-04 23:31 ——– d—–w- c:\documents and settings\Vern McKinney\Application Data\Malwarebytes
2010-08-25 03:12 . 2010-10-09 18:26 86327 —-a-w- c:\windows\pchealth\HelpCtr\OfflineCache\index.dat
2010-08-17 13:17 . 2010-10-09 10:57 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-05 14:09 . 2010-08-05 14:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-07-22 15:49 . 2004-10-10 08:41 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-01-30 13:53 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-07-15 22:18 . 2009-02-02 09:53 120136 —-a-w- c:\windows\system32\drivers\Mpfp.sys
.

((((((((((((((((((((((((((((( SnapShot_2010-08-27_06.32.24 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-01-29 08:58 . 2010-04-21 13:28 46080 c:\windows\SYSTEM32\tzchange.exe
+ 2007-01-29 08:58 . 2010-06-21 14:46 46080 c:\windows\SYSTEM32\tzchange.exe
+ 2010-08-17 13:17 . 2010-08-17 13:17 58880 c:\windows\SYSTEM32\dllcache\spoolsv.exe
- 2010-10-09 18:30 . 2010-08-27 05:39 32768 c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-10-09 18:30 . 2010-09-29 22:17 32768 c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-09-27 08:44 . 2010-09-29 22:17 32768 c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2010-09-18 23:30 . 2010-09-18 23:30 27136 c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2009-07-12 08:12 . 2009-07-12 08:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 08:09 . 2009-07-12 08:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 08:08 . 2009-07-12 08:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
- 2010-10-09 10:58 . 2008-04-14 00:12 293376 c:\windows\SYSTEM32\winsrv.dll
+ 2010-10-09 10:58 . 2010-06-18 17:45 293376 c:\windows\SYSTEM32\winsrv.dll
+ 2010-10-09 10:58 . 2010-04-16 15:36 406016 c:\windows\SYSTEM32\usp10.dll
- 2010-10-09 10:58 . 2008-04-14 00:12 406016 c:\windows\SYSTEM32\usp10.dll
- 2006-10-19 05:47 . 2006-10-19 05:47 317440 c:\windows\SYSTEM32\MP4SDECD.dll
+ 2006-10-19 05:47 . 2010-03-30 19:24 317440 c:\windows\SYSTEM32\mp4sdecd.dll
+ 2010-10-09 18:25 . 2010-06-09 07:43 692736 c:\windows\SYSTEM32\inetcomm.dll
+ 2010-06-18 17:45 . 2010-06-18 17:45 293376 c:\windows\SYSTEM32\dllcache\winsrv.dll
+ 2010-04-16 15:36 . 2010-04-16 15:36 406016 c:\windows\SYSTEM32\dllcache\usp10.dll
+ 2009-04-15 14:51 . 2010-07-22 15:49 590848 c:\windows\SYSTEM32\dllcache\rpcrt4.dll
+ 2010-03-30 19:24 . 2010-03-30 19:24 317440 c:\windows\SYSTEM32\dllcache\mp4sdecd.dll
+ 2008-09-04 23:48 . 2010-06-09 07:43 692736 c:\windows\SYSTEM32\dllcache\inetcomm.dll
+ 2010-04-25 20:33 . 2010-09-29 22:17 262144 c:\windows\SYSTEM32\config\systemprofile\IETldCache\index.dat
- 2010-04-25 20:33 . 2010-08-27 00:44 262144 c:\windows\SYSTEM32\config\systemprofile\IETldCache\index.dat
+ 2010-09-18 23:30 . 2010-09-18 23:30 807936 c:\windows\Installer\8e9a90.msi
+ 2010-09-18 23:32 . 2010-09-18 23:32 9472000 c:\windows\Installer\8e9ac1.msi
+ 2010-09-18 23:30 . 2010-09-18 23:30 1549312 c:\windows\Installer\8e9a8b.msi
+ 2010-09-27 07:20 . 2010-09-27 07:20 1094656 c:\windows\Installer\12d52d.msi
+ 2005-08-18 14:12 . 2010-09-16 01:25 35552200 c:\windows\SYSTEM32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS7012Utility"="c:\windows\System32\SiSAudUt.exe" [2001-11-21 294912]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-08-01 684032]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2007-11-21 731136]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T; Self Support Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AT&T; Self Support Tool.lnk
backup=c:\windows\pss\AT&T; Self Support Tool.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
1 [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2005-03-04 19:01 88209 —-a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2006-12-29 05:25 241664 ——w- c:\program files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 06:11 49152 —-a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2003-12-04 12:44 176128 —-a-w- c:\windows\SYSTEM32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
2004-02-02 08:41 495616 —-a-w- c:\windows\SYSTEM32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
2003-11-12 13:23 49152 —-a-w- c:\program files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliType]
2002-03-22 04:41 94208 —-a-w- c:\program files\Microsoft Hardware\Keyboard\type32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2005-04-01 23:16 86016 —-a-w- c:\windows\SYSTEM32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 18:17 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS KHooker]
2001-12-13 16:27 290816 —-a-w- c:\windows\SYSTEM32\khooker.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
2003-06-26 18:35 303104 —-a-w- c:\windows\SYSTEM32\SISTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-05-13 07:50 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 23:45 313472 —-a-r- c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2/2/2009 2:58 AM 93320]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\SYSTEM32\DRIVERS\sis7012.sys [10/9/2010 11:37 AM 165760]
.
Contents of the 'Scheduled Tasks' folder

2010-09-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-09-29 c:\windows\Tasks\HP Usg Daily.job
- c:\program files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\pexpress\hphped05.exe [2004-01-06 18:05]

2009-12-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-02 19:22]

2009-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-02 19:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://att.yahoo.com/
uInternet Settings,ProxyOverride = 127.0.0.1
uCustomizeSearch =
IE: Add Auction Item - Bayside Sniper
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: windows.com\time
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-29 15:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-602162358-329068152-839522115-1003\0*" ¨*!*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"WriteErrorLog"="No"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(484)
c:\windows\system32\l3codecx.acm

- - - - - - - > 'explorer.exe'(1692)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
.
Completion time: 2010-09-29 15:45:37
ComboFix-quarantined-files.txt 2010-09-29 22:45
ComboFix2.txt 2010-09-27 05:35
ComboFix3.txt 2010-09-25 10:14
ComboFix4.txt 2010-09-07 00:54
ComboFix5.txt 2010-09-29 22:35

Pre-Run: 44,121,272,320 bytes free
Post-Run: 44,124,938,240 bytes free

- - End Of File - - 19215FC976F77C451E473417B1716E8C

================================================================================
==================================





GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-29 23:01:53
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\VERNMC~1\LOCALS~1\Temp\kwndaaob.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF503A78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xF503A821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF503A738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF503A74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF503A835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF503A861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF503A8CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF503A8B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF503A7CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF503A8FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xF503A80D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF503A710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF503A724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF503A79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF503A937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF503A8A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF503A88D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF503A84B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF503A923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF503A90F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF503A776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF503A762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF503A877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF503A7F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF503A8E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF503A7E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF503A7B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwYieldExecution 804F0EB6 7 Bytes JMP F503A7B8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80568D48 5 Bytes JMP F503A811 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 8056A1F9 7 Bytes JMP F503A891 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056CF98 5 Bytes JMP F503A78E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056DDD9 5 Bytes JMP F503A766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 80570833 5 Bytes JMP F503A825 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 80570C4A 7 Bytes JMP F503A93B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 80570F41 7 Bytes JMP F503A8D3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 805719AC 5 Bytes JMP F503A714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80571E96 7 Bytes JMP F503A7A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 80572A6E 7 Bytes JMP F503A87B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 805738C6 5 Bytes JMP F503A7E4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80573D41 7 Bytes JMP F503A7CE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FE4C 7 Bytes JMP F503A750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805824CC 5 Bytes JMP F503A7FD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 80589A67 7 Bytes JMP F503A8BD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058E5C4 5 Bytes JMP F503A728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 8058EA94 5 Bytes JMP F503A8FF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80592D64 7 Bytes JMP F503A865 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 80595316 7 Bytes JMP F503A839 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B14AC 5 Bytes JMP F503A73C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062E057 5 Bytes JMP F503A77A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 8064DD32 7 Bytes JMP F503A8E9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 8064E66B 7 Bytes JMP F503A8A7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064EAEA 7 Bytes JMP F503A84F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8064EFDD 5 Bytes JMP F503A913 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8064F446 5 Bytes JMP F503A927 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- User code sections - GMER 1.0.15 —-

.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[204] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[204] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FE5
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0007006E
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0007005D
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070042
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00070025
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00070F9E
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00070F43
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0007007F
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00070EFC
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00070F21
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00070EEB
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00070F83
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00070F5E
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00070FB9
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00070FCA
.text C:\WINDOWS\system32\services.exe[592] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00070F32
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00060033
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00060FA5
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00060022
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00060011
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00060FB6
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00060FC7
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [26, 88]
.text C:\WINDOWS\system32\services.exe[592] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0006004E
.text C:\WINDOWS\system32\services.exe[592] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00050FDE
.text C:\WINDOWS\system32\services.exe[592] msvcrt.dll!system 77C293C7 5 Bytes JMP 0005005F
.text C:\WINDOWS\system32\services.exe[592] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00050044
.text C:\WINDOWS\system32\services.exe[592] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[592] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[592] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0005001D
.text C:\WINDOWS\system32\services.exe[592] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BA005B
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BA0F70
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BA004A
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BA0F8D
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BA0FB9
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BA0F41
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BA0089
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BA00D0
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BA00B5
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BA0F12
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BA0FA8
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BA0011
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BA006C
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BA0FCA
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BA0FDB
.text C:\WINDOWS\system32\lsass.exe[604] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BA00A4
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B9001B
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B90FA5
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B90FD4
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B9000A
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B90062
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B90FE5
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B90047
.text C:\WINDOWS\system32\lsass.exe[604] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B90036
.text C:\WINDOWS\system32\lsass.exe[604] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B80F8B
.text C:\WINDOWS\system32\lsass.exe[604] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B80F9C
.text C:\WINDOWS\system32\lsass.exe[604] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B80FD2
.text C:\WINDOWS\system32\lsass.exe[604] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B80FEF
.text C:\WINDOWS\system32\lsass.exe[604] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B80FB7
.text C:\WINDOWS\system32\lsass.exe[604] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B8000C
.text C:\WINDOWS\system32\lsass.exe[604] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02420FEF
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02420F1F
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02420F3A
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02420F4B
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02420F68
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02420F9E
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02420EE7
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02420039
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02420EB8
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0242005B
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02420E9D
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02420F83
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02420FDE
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02420F0E
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02420014
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02420FC3
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0242004A
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02410014
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0241005E
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02410FCD
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02410FDE
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02410F97
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02410FEF
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02410039
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02410FA8
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0FCD
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF0FDE
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0029
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0044
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[760] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FC0FEF
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D30FEF
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D30F88
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D3007D
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D30FA3
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D3006C
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D30047
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D30F49
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D30F66
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D30F1D
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D30F2E
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D30F0C
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D30FC0
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D3000A
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D30F77
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D3002C
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D3001B
.text C:\WINDOWS\system32\svchost.exe[816] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D300AC
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D20FE5
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D20F97
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D20036
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D20025
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D20FA8
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D20000
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D20FB9
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F2, 88]
.text C:\WINDOWS\system32\svchost.exe[816] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D20FD4
.text C:\WINDOWS\system32\svchost.exe[816] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D10FA1
.text C:\WINDOWS\system32\svchost.exe[816] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D10FB2
.text C:\WINDOWS\system32\svchost.exe[816] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D10022
.text C:\WINDOWS\system32\svchost.exe[816] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D10000
.text C:\WINDOWS\system32\svchost.exe[816] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D10FCD
.text C:\WINDOWS\system32\svchost.exe[816] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D10011
.text C:\WINDOWS\system32\svchost.exe[816] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D00000
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 037F0000
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 037F0F7C
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 037F0071
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 037F004A
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 037F0F8D
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 037F0FAF
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 037F0F46
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 037F008E
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 037F00CB
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 037F00BA
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 037F00F0
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 037F0F9E
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 037F0FDB
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 037F0F57
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 037F0FC0
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 037F0011
.text C:\WINDOWS\System32\svchost.exe[880] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 037F009F
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 037E0FC3
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 037E0FA1
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 037E0FDE
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 037E000A
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 037E0054
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 037E0FEF
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 037E0FB2
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [9E, 8B]
.text C:\WINDOWS\System32\svchost.exe[880] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 037E002F
.text C:\WINDOWS\System32\svchost.exe[880] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 037D0038
.text C:\WINDOWS\System32\svchost.exe[880] msvcrt.dll!system 77C293C7 5 Bytes JMP 037D0FB7
.text C:\WINDOWS\System32\svchost.exe[880] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 037D0FE3
.text C:\WINDOWS\System32\svchost.exe[880] msvcrt.dll!_open 77C2F566 5 Bytes JMP 037D000C
.text C:\WINDOWS\System32\svchost.exe[880] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 037D0FC8
.text C:\WINDOWS\System32\svchost.exe[880] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 037D001D
.text C:\WINDOWS\System32\svchost.exe[880] WS2_32.dll!socket 71AB4211 5 Bytes JMP 037C0FEF
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenA 3D95D690 3 Bytes JMP 02210FEF
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenA + 4 3D95D694 1 Byte [C4]
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenW 3D95DB09 3 Bytes JMP 02210FDE
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenW + 4 3D95DB0D 1 Byte [C4]
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenUrlA 3D95F3A4 3 Bytes JMP 02210FCD
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenUrlA + 4 3D95F3A8 1 Byte [C4]
.text C:\WINDOWS\System32\svchost.exe[880] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 02210FB2
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B1000A
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B10F5E
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B10053
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B10F79
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B10F94
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B10FC0
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B10084
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B10F3C
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B10EFC
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B10095
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B10EEB
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B10FAF
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B1001B
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B10F4D
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B10036
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B10FE5
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B10F21
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B00FCD
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B0004A
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B00FDE
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B00FEF
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B00039
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B0000A
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B00F97
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D0, 88]
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B00FB2
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00AF0F92
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!system 77C293C7 5 Bytes JMP 00AF0FAD
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00AF001D
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00AF0FEF
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00AF0FBE
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00AF000C
.text C:\WINDOWS\system32\svchost.exe[984] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00AE0000
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BA000A
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BA00B0
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BA0FBB
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BA0095
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BA0084
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BA0058
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BA0FA0
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BA00DC
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BA0F7E
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BA0F8F
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BA0132
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BA0069
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BA001B
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BA00C1
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BA0047
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BA002C
.text C:\WINDOWS\System32\svchost.exe[1260] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BA0103
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0093003D
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00930080
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0093002C
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00930011
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00930FB9
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00930000
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00930FCA
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [B3, 88] {MOV BL, 0x88}
.text C:\WINDOWS\System32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00930FDB
.text C:\WINDOWS\System32\svchost.exe[1260] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00920027
.text C:\WINDOWS\System32\svchost.exe[1260] msvcrt.dll!system 77C293C7 5 Bytes JMP 00920FA6
.text C:\WINDOWS\System32\svchost.exe[1260] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00920FD2
.text C:\WINDOWS\System32\svchost.exe[1260] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0092000C
.text C:\WINDOWS\System32\svchost.exe[1260] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00920FB7
.text C:\WINDOWS\System32\svchost.exe[1260] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00920FE3
.text C:\WINDOWS\System32\svchost.exe[1260] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 0090000A
.text C:\WINDOWS\System32\svchost.exe[1260] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00900FEF
.text C:\WINDOWS\System32\svchost.exe[1260] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00900FDE
.text C:\WINDOWS\System32\svchost.exe[1260] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 00900FC3
.text C:\WINDOWS\System32\svchost.exe[1260] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00910FEF
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00260FE5
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 002600A4
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00260093
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00260078
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0026005B
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00260036
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 002600D0
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 002600BF
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00260110
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00260F77
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0026012B
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00260FAF
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0026000A
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00260F94
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00260FCA
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0026001B
.text C:\Program Files\internet explorer\iexplore.exe[1536] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 002600F5
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00350039
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00350087
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00350FDE
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00350FEF
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0035006C
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0035000A
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0035005B
.text C:\Program Files\internet explorer\iexplore.exe[1536] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0035004A
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD135 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254666 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00360053
.text C:\Program Files\internet explorer\iexplore.exe[1536] msvcrt.dll!system 77C293C7 5 Bytes JMP 00360FBE
.text C:\Program Files\internet explorer\iexplore.exe[1536] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0036002E
.text C:\Program Files\internet explorer\iexplore.exe[1536] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00360000
.text C:\Program Files\internet explorer\iexplore.exe[1536] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00360FD9
.text C:\Program Files\internet explorer\iexplore.exe[1536] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00360011
.text C:\Program Files\internet explorer\iexplore.exe[1536] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4EF0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1536] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 01170FE5
.text C:\Program Files\internet explorer\iexplore.exe[1536] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 01170FD4
.text C:\Program Files\internet explorer\iexplore.exe[1536] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 0117000A
.text C:\Program Files\internet explorer\iexplore.exe[1536] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 01170FC3
.text C:\Program Files\internet explorer\iexplore.exe[1536] ws2_32.dll!socket 71AB4211 5 Bytes JMP 01ED0000
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0189000A
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0189009D
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01890082
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01890FA8
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01890FB9
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01890040
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 018900CB
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01890F83
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01890112
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01890101
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01890F5E
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0189005B
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0189001B
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 018900AE
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01890FD4
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01890FEF
.text C:\WINDOWS\Explorer.EXE[1552] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 018900E6
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F90036
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F90F9B
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F90FDB
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F9001B
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F90058
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F9000A
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00F90047
.text C:\WINDOWS\Explorer.EXE[1552] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F90FC0
.text C:\WINDOWS\Explorer.EXE[1552] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F8007F
.text C:\WINDOWS\Explorer.EXE[1552] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F80064
.text C:\WINDOWS\Explorer.EXE[1552] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F8002E
.text C:\WINDOWS\Explorer.EXE[1552] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F80000
.text C:\WINDOWS\Explorer.EXE[1552] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F80053
.text C:\WINDOWS\Explorer.EXE[1552] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F80011
.text C:\WINDOWS\Explorer.EXE[1552] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00F60FE5
.text C:\WINDOWS\Explorer.EXE[1552] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00F60000
.text C:\WINDOWS\Explorer.EXE[1552] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00F6001B
.text C:\WINDOWS\Explorer.EXE[1552] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 00F60FCA
.text C:\WINDOWS\Explorer.EXE[1552] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F70FEF
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00260FEF
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00260F41
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00260F52
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00260F63
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00260F80
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0026002C
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0026006E
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00260F26
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00260F0B
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0026009A
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00260EE6
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00260FA5
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00260FD4
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00260051
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0026001B
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0026000A
.text C:\Program Files\internet explorer\iexplore.exe[3460] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0026007F
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00350040
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00350FA8
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00350025
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00350FEF
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00350FC3
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0035000A
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00350FD4
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [55, 88]
.text C:\Program Files\internet explorer\iexplore.exe[3460] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0035005B
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3460] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0036006E
.text C:\Program Files\internet explorer\iexplore.exe[3460] msvcrt.dll!system 77C293C7 5 Bytes JMP 00360053
.text C:\Program Files\internet explorer\iexplore.exe[3460] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00360FE3
.text C:\Program Files\internet explorer\iexplore.exe[3460] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00360000
.text C:\Program Files\internet explorer\iexplore.exe[3460] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00360042
.text C:\Program Files\internet explorer\iexplore.exe[3460] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0036001D
.text C:\Program Files\internet explorer\iexplore.exe[3460] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 009D0000
.text C:\Program Files\internet explorer\iexplore.exe[3460] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 009D0FEF
.text C:\Program Files\internet explorer\iexplore.exe[3460] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 009D001B
.text C:\Program Files\internet explorer\iexplore.exe[3460] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 009D0FCA
.text C:\Program Files\internet explorer\iexplore.exe[3460] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00A2000A
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00260FE5
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00260F74
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00260069
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00260058
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00260047
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00260FAF
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00260F3C
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00260F59
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 002600B0
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00260F21
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002600D5
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0026002C
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00260FD4
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0026007A
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0026001B
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00260000
.text C:\Program Files\internet explorer\iexplore.exe[3752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00260095
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00350FA8
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00350028
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00350FC3
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00350FDE
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00350F6B
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00350FEF
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00350F7C
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [55, 88]
.text C:\Program Files\internet explorer\iexplore.exe[3752] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00350F97
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD135 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254666 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00360049
.text C:\Program Files\internet explorer\iexplore.exe[3752] msvcrt.dll!system 77C293C7 5 Bytes JMP 0036002E
.text C:\Program Files\internet explorer\iexplore.exe[3752] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00360FD2
.text C:\Program Files\internet explorer\iexplore.exe[3752] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00360FEF
.text C:\Program Files\internet explorer\iexplore.exe[3752] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0036001D
.text C:\Program Files\internet explorer\iexplore.exe[3752] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00360000
.text C:\Program Files\internet explorer\iexplore.exe[3752] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4EF0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3752] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 01170000
.text C:\Program Files\internet explorer\iexplore.exe[3752] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 01170FE5
.text C:\Program Files\internet explorer\iexplore.exe[3752] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 0117001B
.text C:\Program Files\internet explorer\iexplore.exe[3752] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 01170FCA
.text C:\Program Files\internet explorer\iexplore.exe[3752] ws2_32.dll!socket 71AB4211 5 Bytes JMP 01ED0FEF

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdePort0 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdePort1 dvd43llh.sys (dvd43llh.sys/RIF)

AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-



================================================================================
=================================





]Defogger Log.

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 15:52 on 29/09/2010 (Vern McKinney)

Checking for autostart values…
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers…


-=E.O.F=
Please do not bold, enlarge or color the information that you are posting from the log files as this makes it more difficult to analyze them.


Please answer the following questions:

1. Can you please check the date and time on your computer and let me know if they are correct? If you have to adjust either of them, can you please let me know how far off it was?

2. It appears this computer may have been stored for a few years and then brought back out. Can you please confirm?

3. Did you change the password on your email account as suggested? If so, have you seen any improvement in the spam being sent out?



Download CWShredder to your desktop.

  • Open CWShredder
  • Check for Updates
  • Close out the program. <– Dont run it yet

    Boot your computer into Safemode
    • Go to Start> Shut Off your Computer> Restart
    • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
    • This will bring up a menu.
    • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
    • Then press the Enter on your Keyboard
    Tutorial if you need it How to boot into Safemode


    Open CWShredder
  • Double-click on CWShredder.exe.
  • Click Fix and click OK at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click Next and then Exit .


In your next reply, please include the answers to the above questions and confirm you were able to successfuly run CWShredder.
Sorry about the bold and enlarged type. I was just trying to enlarge the Title and it went wrong and I could not fix it . I did answere the questions in the previous post. But hear they are again 1) The Date and time are Correct and always have been. 2) My computer has never been stored even for a short period of time, The Battery on the Mother Board went dead, for how long I don't remember? 3) I did change the pass word, and cut off any links to Face Book, and there has not been any spam sent since. 4) I downloaded CWSchreader, When I tried to check for updates it said it was unable to update? I started in Safe Mode, opened CW ,I was not sure what CWShredder.exe. so I ran a scan? No Cool Web Search Were Found, Was the message at the end. Let me know if this was correct.
I would like to get a fresh OTL log from you. There appear to be some leftover files from an old infection on the machine and I'd like to ensure we get rid of them all.

  • Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
I have been trying to add the OLT TXT. but it says the reply is too long please reduce it??? How do I reduce it?? Or how do I post it ?? I was not able to find the Extras TXT. Just the OLT TXT. I ran everthing twice??? Where would I find it? it didn't open on my Screen??
Whenever the contents of a log are too long to fit in a single post, please post part of the log in one post and then create another post to continue with the rest of the log. Don't worry about the Extras log just now. Please go ahead and post what you have.
OTL logfile created on: 10/2/2010 1:36:48 AM - Run 5
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Vern McKinney\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,024.00 Mb Total Physical Memory | 554.00 Mb Available Physical Memory | 54.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 57.27 Gb Total Space | 41.08 Gb Free Space | 71.73% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VERN-UUSAKGC8SQ
Current User Name: Vern McKinney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\dvd43\DVD43_Tray.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
PRC - C:\WINDOWS\SYSTEM32\SISAUDUT.EXE (Silicon Integrated Systems Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (PCAMPR5) – C:\WINDOWS\System32\PCAMPR5.SYS File not found
DRV - (catchme) – C:\DOCUME~1\VERNMC~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (dvd43llh) – C:\WINDOWS\SYSTEM32\DRIVERS\dvd43llh.sys (RIF)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\SYSTEM32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (SiS315) – C:\WINDOWS\SYSTEM32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp) – C:\WINDOWS\SYSTEM32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (cdudf_xp) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (UdfReadr_xp) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (SiS7012) Service for AC'97 Sample Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\sis7012.sys (Silicon Integrated Systems Corporation)
DRV - (SISNIC) – C:\WINDOWS\SYSTEM32\DRIVERS\sisnic.sys (SiS Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/09/30 22:25:11 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/09/26 22:41:55 | 000,000,023 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SiS7012Utility] C:\WINDOWS\System32\SiSAudUt.exe (Silicon Integrated Systems Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: windows.com ([time] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1097391139862 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1137821257890 (MUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab (Reg Error: Key error.)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://energycenter.webex.com/client/T27LB…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/28 13:49:58 | 000,000,070 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/27 14:52:16 | 000,000,038 | -HS- | M] () - C:\AUTOEXEC.DOS – [ NTFS ]
O32 - AutoRun File - [2010/09/27 15:15:32 | 000,000,070 | —- | M] () - C:\AUTOEXEC.NS0 – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecx.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 90 Days ==========

[2010/10/09 20:03:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Help
[2010/10/09 19:56:50 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/10/09 19:56:49 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Designer
[2010/10/09 19:55:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft Web Folders
[2010/10/09 19:55:04 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/10/09 19:42:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Camino # 3
[2010/10/09 19:42:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\aMVC-001F.zip Turbine Pictures
[2010/10/09 19:42:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\AA
[2010/10/09 19:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\TAYLORBEFORESCHOOL
[2010/10/09 19:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\SUDCO Motorcycle Parts Distributing_files
[2010/10/09 19:42:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\stress2
[2010/10/09 19:42:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\My Albums
[2010/10/09 19:42:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Monkey1-high1
[2010/10/09 19:42:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Microsoft update down load repair
[2010/10/09 19:42:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0011
[2010/10/09 19:42:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0010
[2010/10/09 19:42:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0009
[2010/10/09 19:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0008
[2010/10/09 19:42:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0007
[2010/10/09 19:42:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0006
[2010/10/09 19:42:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0005
[2010/10/09 19:42:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0004
[2010/10/09 19:41:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0003
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0002
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Img0001
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complrint Form GSXR 1100 MOTOR_files
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complaint Form 1100 GSXR MOTOR_files
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Forest Gump Goes To Heaven_files
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\ebayitems001
[2010/10/09 19:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Dscn0027
[2010/10/09 11:50:44 | 000,000,000 | —D | C] – C:\WINDOWS\System32\trayres
[2010/10/09 11:50:43 | 000,000,000 | —D | C] – C:\Program Files\SiS Compatible VGA V2.05a.01
[2010/10/09 11:47:20 | 000,000,000 | —D | C] – C:\WINDOWS\SiSAGP
[2010/10/09 11:39:55 | 000,000,000 | –SD | C] – C:\WINDOWS\System32\Microsoft
[2010/10/09 11:39:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/10/09 11:39:16 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/10/09 11:39:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Application Data\Adobe
[2010/10/09 11:38:27 | 000,031,744 | R— | C] (SiS Corporation) – C:\WINDOWS\System32\drivers\sisnic.sys
[2010/10/09 11:38:27 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ReinstallBackups
[2010/10/09 11:37:38 | 000,078,948 | R— | C] (Aureal Semiconductor) – C:\WINDOWS\System32\a3d.dll
[2010/10/09 11:37:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\WINDOWS
[2010/10/09 11:34:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Application Data\Identities
[2010/10/09 11:34:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\My Documents\My Pictures
[2010/10/09 11:34:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\My Documents\My Music
[2010/10/09 11:34:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Microsoft
[2010/10/09 11:33:59 | 000,000,000 | –SD | C] – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft
[2010/10/09 11:33:59 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Vern McKinney\SendTo
[2010/10/09 11:33:59 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Vern McKinney\Application Data
[2010/10/09 11:33:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\Start Menu
[2010/10/09 11:33:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\Vern McKinney\My Documents
[2010/10/09 11:33:59 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Vern McKinney\Cookies
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\Templates
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\PrintHood
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\NetHood
[2010/10/09 11:33:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Vern McKinney\Local Settings
[2010/10/09 11:33:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Favorites
[2010/10/09 11:33:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Desktop
[2010/10/09 11:32:28 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/10/09 11:32:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/10/09 11:32:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/10/09 11:32:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/10/09 11:32:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/10/09 11:29:57 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2010/10/09 11:29:57 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2010/10/09 11:28:37 | 000,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2010/10/09 11:28:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\xircom
[2010/10/09 11:28:14 | 000,000,000 | —D | C] – C:\Program Files\xerox
[2010/10/09 11:28:14 | 000,000,000 | —D | C] – C:\Program Files\microsoft frontpage
[2010/10/09 11:26:01 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users\DRM
[2010/10/09 11:25:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DirectX
[2010/10/09 11:25:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\MSSoap
[2010/10/09 11:25:07 | 000,000,000 | —D | C] – C:\WINDOWS\srchasst
[2010/10/09 11:25:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Macromed
[2010/10/09 11:25:06 | 000,000,000 | —D | C] – C:\Program Files\Movie Maker
[2010/10/09 11:25:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Restore
[2010/10/09 11:25:05 | 000,000,000 | —D | C] – C:\WINDOWS\PCHealth
[2010/10/09 11:24:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2010/10/09 11:24:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2010/10/09 11:24:08 | 000,000,000 | —D | C] – C:\WINDOWS\Registration
[2010/10/09 11:23:55 | 000,000,000 | —D | C] – C:\Program Files\Messenger
[2010/10/09 11:23:51 | 000,000,000 | —D | C] – C:\Program Files\MSN Gaming Zone
[2010/10/09 11:23:39 | 000,000,000 | —D | C] – C:\Program Files\Windows NT
[2010/10/09 11:23:39 | 000,000,000 | —D | C] – C:\Program Files\MSN
[2010/10/09 11:23:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MsDtc
[2010/10/09 11:23:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Com
[2010/10/09 11:23:35 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/10/09 04:08:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeechEngines
[2010/10/09 04:08:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu
[2010/10/09 04:08:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents
[2010/10/09 04:08:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Templates
[2010/10/09 04:08:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Favorites
[2010/10/09 04:08:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop
[2010/10/09 04:08:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot2
[2010/10/09 04:08:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot
[2010/10/09 04:07:58 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2010/10/09 04:07:58 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data
[2010/10/09 04:07:46 | 000,000,000 | —D | C] – C:\Documents and Settings
[2010/10/09 04:04:34 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\WinSxS
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wins
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wbem
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\usmt
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\twain_32
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\spool
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ShellExt
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Setup
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\security
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Resources
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\repair
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ras
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\oobe
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\npp
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\mui
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\mui
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\msapps
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\msagent
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\inetsrv
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\IME
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\ime
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\icsxml
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ias
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\export
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\etc
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Driver Cache
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\disdn
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dhcp
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Debug
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\Connection Wizard
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\config
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\addins
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3com_dmi
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3076
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\2052
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1054
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1042
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1041
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1037
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1033
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1031
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1028
[2010/10/09 04:04:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1025
[2010/10/09 04:00:17 | 003,374,640 | —- | C] (Macromedia, Inc.) – C:\WINDOWS\System32\dllcache\tourW.exe
[2010/10/09 03:49:58 | 000,000,000 | —D | C] – C:\WINDOWS\setup
[2010/10/02 03:07:43 | 000,000,000 | —D | C] – C:\ASAPREP
[2010/09/30 17:24:46 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/09/29 15:35:47 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/09/29 15:35:47 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/09/29 15:35:47 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/09/29 15:35:47 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/09/28 19:38:32 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe
[2010/09/28 19:23:15 | 000,921,512 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Vern McKinney\Desktop\Norton_Removal_Tool.exe
[2010/09/28 15:39:12 | 000,000,000 | –SD | C] – C:\WINDOWS\UserData
[2010/09/28 14:59:33 | 000,000,000 | —D | C] – C:\WINDOWS\color
[2010/09/28 14:59:32 | 000,000,000 | —D | C] – C:\Program Files\HP DeskJet 820C Series
[2010/09/28 14:47:41 | 000,000,000 | —D | C] – C:\WINDOWS\Windows Update Setup Files
[2010/09/28 14:08:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\aolback
[2010/09/28 14:08:08 | 000,000,000 | –SD | C] – C:\WINDOWS\occache
[2010/09/28 14:08:08 | 000,000,000 | —D | C] – C:\Program Files\Learn2.com
[2010/09/28 14:08:05 | 000,000,000 | —D | C] – C:\Program Files\Viewpoint
[2010/09/28 14:00:37 | 000,000,000 | —D | C] – C:\WINDOWS\System\mui
[2010/09/28 13:51:59 | 000,000,000 | —D | C] – C:\WINDOWS\System\sfp
[2010/09/28 13:51:46 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/09/28 13:51:01 | 000,000,000 | —D | C] – C:\WINDOWS\System\QuickTime
[2010/09/28 13:50:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nullsoft
[2010/09/28 13:50:49 | 000,000,000 | —D | C] – C:\My Music
[2010/09/28 13:50:47 | 000,000,000 | —D | C] – C:\Program Files\Real
[2010/09/28 13:50:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Real
[2010/09/28 13:48:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AOL
[2010/09/27 16:01:31 | 000,000,000 | —D | C] – C:\WINDOWS\Options
[2010/09/27 15:58:15 | 000,000,000 | —D | C] – C:\Program Files\SiSLan
[2010/09/27 15:47:53 | 000,000,000 | —D | C] – C:\Program Files\SiS7012
[2010/09/27 15:45:36 | 000,000,000 | —D | C] – C:\WINDOWS\SiS
[2010/09/27 15:45:04 | 000,000,000 | —D | C] – C:\WINDOWS\System\trayres
[2010/09/27 15:44:57 | 000,000,000 | —D | C] – C:\Program Files\SiS_Compatible_VGA_V2.05a.01
[2010/09/27 15:25:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/09/27 15:24:57 | 000,000,000 | —D | C] – C:\Program Files\Norton SystemWorks
[2010/09/27 15:20:54 | 000,000,000 | —D | C] – C:\WINDOWS\AppPatch
[2010/09/27 15:20:51 | 000,000,000 | -HSD | C] – C:\WINDOWS\Installer
[2010/09/27 15:20:51 | 000,000,000 | -H-D | C] – C:\WINDOWS\PrintHood
[2010/09/27 15:20:30 | 000,000,000 | —D | C] – C:\WINDOWS\Local Settings
[2010/09/27 15:20:27 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2010/09/27 15:16:53 | 000,000,000 | -H-D | C] – C:\WINDOWS\NetHood
[2010/09/27 15:16:53 | 000,000,000 | —D | C] – C:\My Documents
[2010/09/27 15:15:23 | 000,000,000 | —D | C] – C:\WINDOWS\System\CatRoot
[2010/09/27 15:15:12 | 000,000,000 | –SD | C] – C:\WINDOWS\Temporary Internet Files
[2010/09/27 15:15:12 | 000,000,000 | –SD | C] – C:\WINDOWS\History
[2010/09/27 15:15:12 | 000,000,000 | –SD | C] – C:\WINDOWS\Cookies
[2010/09/27 15:15:11 | 000,000,000 | —D | C] – C:\Program Files\DirectX
[2010/09/27 15:14:31 | 000,000,000 | –SD | C] – C:\WINDOWS\Favorites
[2010/09/27 15:14:26 | 000,000,000 | –SD | C] – C:\WINDOWS\Downloaded Program Files
[2010/09/27 15:14:25 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2010/09/27 15:14:02 | 000,000,000 | —D | C] – C:\Program Files\Uninstall Information
[2010/09/27 15:13:38 | 000,000,000 | -H-D | C] – C:\WINDOWS\Recent
[2010/09/27 15:13:38 | 000,000,000 | —D | C] – C:\WINDOWS\SendTo
[2010/09/27 15:13:37 | 000,000,000 | —D | C] – C:\WINDOWS\Start Menu
[2010/09/27 15:13:32 | 000,000,000 | —D | C] – C:\WINDOWS\All Users
[2010/09/27 07:06:07 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2010/09/27 00:08:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Desktop\Hijack This
[2010/09/18 16:31:11 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/09/18 16:31:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/09/18 16:30:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/09/18 16:30:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Apple
[2010/09/18 16:30:10 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/09/18 16:30:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/09/18 16:28:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\Apple Computer
[2010/09/06 16:57:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Vern McKinney\Recent
[2010/09/06 16:56:34 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/08/25 19:49:58 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/25 19:49:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/25 19:49:54 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/25 19:49:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/24 21:07:44 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/08/24 21:04:58 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/08/24 21:04:33 | 000,000,000 | —D | C] – C:\Qoobox
[2010/08/24 20:19:15 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/08/24 20:08:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/08/24 20:08:12 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/08/24 20:08:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/08/24 20:02:23 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2010/08/05 23:43:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\House Ideas
[2010/08/05 22:42:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Work Pictures
[2010/08/05 07:09:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/04 22:57:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/04 22:57:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/04 22:57:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/04 22:57:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/07/23 18:41:55 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/07/05 16:14:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Vern McKinney\My Documents\Crockett Monday Night General Service
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[14 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/10/09 19:57:44 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/10/09 19:57:40 | 000,000,059 | —- | M] () – C:\WINDOWS\vbaddin.ini
[2010/10/09 12:13:03 | 000,001,789 | —- | M] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2010/10/09 11:51:24 | 000,003,917 | —- | M] () – C:\SiSSetup1.ini
[2010/10/09 11:50:42 | 000,004,981 | —- | M] () – C:\SiSUnist.ini
[2010/10/09 11:46:45 | 000,002,942 | —- | M] () – C:\WINDOWS\Ascd_tmp.ini
[2010/10/09 11:34:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/10/09 11:34:11 | 000,025,065 | —- | M] () – C:\WINDOWS\System32\wmpscheme.xml
[2010/10/09 11:31:34 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2010/10/09 11:30:49 | 000,000,658 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/10/09 11:27:53 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/10/09 11:25:49 | 000,000,488 | RH– | M] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2010/10/09 11:25:49 | 000,000,488 | RH– | M] () – C:\WINDOWS\System32\logonui.exe.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\WindowsShell.Manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | M] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/10/09 11:24:26 | 000,021,640 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/10/09 11:24:13 | 000,000,036 | —- | M] () – C:\WINDOWS\vb.ini
[2010/10/09 04:01:14 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2010/10/02 00:20:42 | 000,021,961 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/10/02 00:19:01 | 000,017,721 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/10/02 00:18:29 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/10/02 00:18:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/01 14:17:07 | 009,699,328 | —- | M] () – C:\Documents and Settings\Vern McKinney\ntuser.dat
[2010/10/01 14:16:50 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\ntuser.ini
[2010/10/01 14:08:01 | 000,000,358 | —- | M] () – C:\WINDOWS\tasks\HP Usg Daily.job
[2010/09/30 22:46:10 | 004,312,340 | -H– | M] () – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\IconCache.db
[2010/09/30 03:43:45 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Vern McKinney\Desktop\cwshredder.exe
[2010/09/29 15:52:12 | 000,000,000 | —- | M] () – C:\Documents and Settings\Vern McKinney\defogger_reenable
[2010/09/29 15:42:47 | 000,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/29 15:34:02 | 003,858,327 | R— | M] () – C:\Documents and Settings\Vern McKinney\Desktop\ComboFix.exe
[2010/09/29 15:17:30 | 000,284,915 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\gmer.zip
[2010/09/29 15:16:54 | 000,050,477 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\Defogger.exe
[2010/09/28 19:38:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe
[2010/09/28 19:23:17 | 000,921,512 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Vern McKinney\Desktop\Norton_Removal_Tool.exe
[2010/09/28 13:49:58 | 000,000,070 | —- | M] () – C:\AUTOEXEC.BAT
[2010/09/28 13:49:58 | 000,000,040 | —- | M] () – C:\CONFIG.SYS
[2010/09/27 15:16:00 | 000,049,152 | -HS- | M] () – C:\VIDEOROM.BIN
[2010/09/27 15:15:40 | 000,046,548 | -HS- | M] () – C:\BOOTLOG.PRV
[2010/09/27 15:15:32 | 000,000,070 | —- | M] () – C:\AUTOEXEC.NS0
[2010/09/27 15:15:32 | 000,000,040 | —- | M] () – C:\CONFIG.NS0
[2010/09/27 15:14:34 | 000,011,079 | —- | M] () – C:\Program Files\folder.htt
[2010/09/27 07:06:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/27 00:20:15 | 000,002,000 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\HiJackThis.lnk
[2010/09/27 00:05:00 | 000,305,771 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\HijackThis.zip
[2010/09/26 23:40:00 | 001,402,880 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\Verns Fix.msi
[2010/09/26 22:41:55 | 000,000,023 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/09/26 15:11:00 | 000,000,845 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2010/09/26 14:49:08 | 000,000,241 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\HammerSnipe - HammerSnipe - FREE online auction site sniping software esniper ebay snipe site e snipe auctions ebay auction sniper site bid sniper free auction.url
[2010/09/18 16:32:18 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/09/18 16:19:11 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/09/18 16:19:11 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/09/15 18:27:59 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/06 16:56:36 | 000,001,552 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\CCleaner.lnk
[2010/09/05 12:14:27 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/25 19:50:01 | 000,000,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/25 18:37:20 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/25 07:38:02 | 000,311,934 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/25 07:38:02 | 000,040,196 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/25 07:38:01 | 000,356,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/24 21:07:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/08/24 20:36:30 | 000,000,791 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/24 20:36:30 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/24 20:02:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/05 23:49:48 | 014,306,443 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\DMV HearingPictures.zip
[2010/08/01 20:37:04 | 000,025,600 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\Discussion Topic.doc
[2010/07/23 18:48:00 | 000,000,819 | —- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/20 19:23:56 | 000,084,480 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\Poker%20Run[1].doc
[2010/07/15 15:18:22 | 000,120,136 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\Mpfp.sys
[2010/07/05 16:05:58 | 000,020,992 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\Crockett Monday Night.doc
[2010/07/04 03:12:17 | 000,001,455 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\WebEx Player.LNK
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[14 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/09 19:57:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/10/09 19:42:52 | 002,093,087 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\TAYLORBEFORESCHOOL.zip
[2010/10/09 19:42:52 | 001,225,216 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\System Information.nfo
[2010/10/09 19:42:52 | 000,400,775 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbirds.jpg
[2010/10/09 19:42:52 | 000,300,478 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbird diamond 6.jpg
[2010/10/09 19:42:52 | 000,252,750 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\stress2.zip
[2010/10/09 19:42:52 | 000,217,335 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\WinnieThePooh.zip
[2010/10/09 19:42:52 | 000,104,357 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbrds 6.jpg
[2010/10/09 19:42:52 | 000,101,477 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbirds cross 4.jpg
[2010/10/09 19:42:52 | 000,095,791 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Thunderbirds diamond 6.jpg
[2010/10/09 19:42:52 | 000,078,712 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbirds 5.jpg
[2010/10/09 19:42:52 | 000,078,702 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbirds-1.jpg
[2010/10/09 19:42:52 | 000,032,256 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Powersports of Vallejo.doc
[2010/10/09 19:42:52 | 000,027,136 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\WordforBlonds.doc
[2010/10/09 19:42:52 | 000,022,155 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\thunderbirds 3.jpg
[2010/10/09 19:42:52 | 000,017,454 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\vern shippin doct. gsxr engine ind..pdf
[2010/10/09 19:42:52 | 000,006,376 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Rocket Seintsist.html
[2010/10/09 19:42:52 | 000,001,655 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\SUDCO Motorcycle Parts Distributing.htm
[2010/10/09 19:42:52 | 000,000,292 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\tmb.ind
[2010/10/09 19:42:52 | 000,000,262 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Shortcut to My Documents.lnk
[2010/10/09 19:42:52 | 000,000,055 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\tmb.lst
[2010/10/09 19:42:51 | 005,034,269 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Monkey1-high1.zip
[2010/10/09 19:42:51 | 001,221,659 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\MAT-V1-1.exe Aqu, screen saver.exe
[2010/10/09 19:42:51 | 000,464,422 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\LagerPaper.wmv
[2010/10/09 19:42:51 | 000,241,035 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\image001.zip
[2010/10/09 19:42:51 | 000,189,758 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\JumpShotWA.zip
[2010/10/09 19:42:51 | 000,159,232 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\mother-in-law_1.pps
[2010/10/09 19:42:51 | 000,150,016 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\JUSTCHEC.pps
[2010/10/09 19:42:51 | 000,094,208 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\PICKFOUR.pps
[2010/10/09 19:42:51 | 000,036,864 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Power plant Chapter 2 Review.doc
[2010/10/09 19:42:51 | 000,019,456 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\My Letter01A.doc
[2010/10/09 19:42:51 | 000,019,456 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\My Letter01.doc
[2010/10/09 19:42:51 | 000,016,982 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\image001.jpgMichelin Denies Paternit Suit.jpg
[2010/10/09 19:42:51 | 000,015,359 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC-I04010122517545.pdf
[2010/10/09 19:42:51 | 000,014,650 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC-I03112400048755.pdfGSXR Complaint.pdf
[2010/10/09 19:42:51 | 000,014,650 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC-I03112400048755.pdfGSXR 1100 Complaint.pdf
[2010/10/09 19:42:51 | 000,008,931 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Jokes.html
[2010/10/09 19:42:51 | 000,003,339 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complrint Form GSXR 1100 MOTOR.htm
[2010/10/09 19:42:51 | 000,000,339 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\LagerPaper.wmv.lnk
[2010/10/09 19:42:51 | 000,000,022 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Microsoft update down load repair.zip
[2010/10/09 19:42:50 | 002,178,900 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\HOWMENSCREWUPROMANCE_1.mpg
[2010/10/09 19:42:50 | 000,884,625 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC Complaint.jpg
[2010/10/09 19:42:50 | 000,674,854 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0196.JPG
[2010/10/09 19:42:50 | 000,643,266 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0197.JPG
[2010/10/09 19:42:50 | 000,508,398 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0144.JPG
[2010/10/09 19:42:50 | 000,508,360 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0189.JPG
[2010/10/09 19:42:50 | 000,504,017 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0162.JPG
[2010/10/09 19:42:50 | 000,480,385 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0198.JPG
[2010/10/09 19:42:50 | 000,455,042 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\ebayitems001.zip
[2010/10/09 19:42:50 | 000,451,259 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0194.JPG
[2010/10/09 19:42:50 | 000,436,188 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0105.JPG
[2010/10/09 19:42:50 | 000,436,087 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0161.JPG
[2010/10/09 19:42:50 | 000,339,849 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0145.JPG
[2010/10/09 19:42:50 | 000,033,792 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC Complaint.doc Letter to Brandy Stower.doc
[2010/10/09 19:42:50 | 000,030,651 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\IFCC.Complaint Form 1100 GSXR MOTOR.htm
[2010/10/09 19:42:50 | 000,006,510 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\HP 7960 Photo Printer.htm
[2010/10/09 19:42:50 | 000,004,177 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Forest Gump Goes To Heaven.html
[2010/10/09 19:42:50 | 000,000,831 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Hey What Happened To The Copy Machine.html
[2010/10/09 19:42:49 | 003,366,998 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Dscn0027.zip
[2010/10/09 19:42:49 | 000,884,625 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0035.JPG
[2010/10/09 19:42:49 | 000,776,443 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0049.JPG
[2010/10/09 19:42:49 | 000,730,772 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0024.JPG
[2010/10/09 19:42:49 | 000,699,833 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0023.JPG ICC Complaint Timing Cover.jpg
[2010/10/09 19:42:49 | 000,618,680 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0024.JPG IFCC Cmplaint Timing Cover.jpg
[2010/10/09 19:42:49 | 000,600,739 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0071.JPG
[2010/10/09 19:42:49 | 000,560,785 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0024.JPG IFCC Complaint.jpg
[2010/10/09 19:42:49 | 000,552,831 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0048.JPG
[2010/10/09 19:42:49 | 000,514,158 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0069.JPG
[2010/10/09 19:42:49 | 000,480,994 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0058.JPG
[2010/10/09 19:42:49 | 000,475,371 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0062.JPG
[2010/10/09 19:42:49 | 000,471,475 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0077.JPG
[2010/10/09 19:42:49 | 000,447,724 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0059.JPG
[2010/10/09 19:42:49 | 000,386,637 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0079.JPG
[2010/10/09 19:42:49 | 000,336,903 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0092.JPG
[2010/10/09 19:42:49 | 000,267,777 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0027.JPG
[2010/10/09 19:42:49 | 000,219,828 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0028.JPG
[2010/10/09 19:42:49 | 000,101,926 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0039.JPG
[2010/10/09 19:42:48 | 000,660,312 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DSCN0022.JPG IFCC Complain.jpg
[2010/10/09 19:42:48 | 000,464,941 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\cleco136glf.pdf
[2010/10/09 19:42:48 | 000,423,062 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Cleco Grinder Threaded Shaft.zip
[2010/10/09 19:42:48 | 000,353,504 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\dago red 3.jpg
[2010/10/09 19:42:48 | 000,269,719 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\coolpixsummerrebate.pdf
[2010/10/09 19:42:48 | 000,176,658 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\count_coupon.pdf
[2010/10/09 19:42:48 | 000,105,032 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Dago red.jpg
[2010/10/09 19:42:48 | 000,087,227 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\BikeClub.jpg
[2010/10/09 19:42:48 | 000,050,790 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\CD File of Pictures Air Show.cl5
[2010/10/09 19:42:48 | 000,049,152 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\archive.pst
[2010/10/09 19:42:48 | 000,039,936 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Class Paper _Radial Engines.ppt
[2010/10/09 19:42:48 | 000,015,631 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Dago red 4.jpg
[2010/10/09 19:42:48 | 000,006,510 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\ATTED50.htm HP 7960 Photo Printer.htm
[2010/10/09 19:42:47 | 012,789,900 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\aMVC-001F.zip Turbine Pictures.zip
[2010/10/09 19:42:47 | 000,027,136 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\01BOATPREP.doc
[2010/10/09 19:42:47 | 000,008,681 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\AA.zip
[2010/10/09 19:42:47 | 000,000,002 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\1992 GSXR Engine
[2010/10/09 19:41:19 | 000,124,928 | —- | C] () – C:\Documents and Settings\Vern McKinney\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/09 11:50:41 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\setuplib.dll
[2010/10/09 11:50:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\waitwnd.exe
[2010/10/09 11:50:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis740.bin
[2010/10/09 11:50:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis650.bin
[2010/10/09 11:36:28 | 000,002,942 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/10/09 11:36:27 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/10/09 11:34:17 | 000,000,079 | —- | C] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/10/09 11:34:08 | 000,000,808 | —- | C] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/10/09 11:34:00 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Vern McKinney\ntuser.ini
[2010/10/09 11:33:59 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Vern McKinney\NTUSER.DAT.LOG
[2010/10/09 11:31:34 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2010/10/09 11:30:44 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/10/09 11:29:29 | 001,158,818 | —- | C] () – C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010/10/09 11:29:17 | 000,134,339 | —- | C] () – C:\WINDOWS\System32\dllcache\imekr.lex
[2010/10/09 11:29:07 | 013,463,552 | —- | C] () – C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010/10/09 11:29:01 | 000,108,827 | —- | C] () – C:\WINDOWS\System32\dllcache\hanja.lex
[2010/10/09 11:27:53 | 000,002,577 | —- | C] () – C:\WINDOWS\System32\CONFIG.NT
[2010/10/09 11:27:51 | 000,025,065 | —- | C] () – C:\WINDOWS\System32\wmpscheme.xml
[2010/10/09 11:27:49 | 000,299,552 | —- | C] () – C:\WINDOWS\WMSysPrx.prx
[2010/10/09 11:25:49 | 000,000,488 | RH– | C] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2010/10/09 11:25:49 | 000,000,488 | RH– | C] () – C:\WINDOWS\System32\logonui.exe.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\WindowsShell.Manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/10/09 11:25:43 | 000,000,749 | RH– | C] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/10/09 11:25:26 | 004,399,505 | —- | C] () – C:\WINDOWS\System32\dllcache\nls302en.lex
[2010/10/09 11:25:12 | 000,048,680 | -HS- | C] () – C:\WINDOWS\winnt256.bmp
[2010/10/09 11:25:12 | 000,048,680 | -HS- | C] () – C:\WINDOWS\winnt.bmp
[2010/10/09 11:25:11 | 000,000,984 | —- | C] () – C:\WINDOWS\System32\dllcache\srframe.mmf
[2010/10/09 11:24:26 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/10/09 11:23:47 | 000,093,702 | —- | C] () – C:\WINDOWS\System32\subrange.uce
[2010/10/09 11:23:47 | 000,065,978 | —- | C] () – C:\WINDOWS\Soap Bubbles.bmp
[2010/10/09 11:23:47 | 000,065,954 | —- | C] () – C:\WINDOWS\Prairie Wind.bmp
[2010/10/09 11:23:47 | 000,065,832 | —- | C] () – C:\WINDOWS\Santa Fe Stucco.bmp
[2010/10/09 11:23:47 | 000,060,458 | —- | C] () – C:\WINDOWS\System32\ideograf.uce
[2010/10/09 11:23:47 | 000,026,680 | —- | C] () – C:\WINDOWS\River Sumida.bmp
[2010/10/09 11:23:47 | 000,026,582 | —- | C] () – C:\WINDOWS\Greenstone.bmp
[2010/10/09 11:23:47 | 000,024,006 | —- | C] () – C:\WINDOWS\System32\gb2312.uce
[2010/10/09 11:23:47 | 000,022,984 | —- | C] () – C:\WINDOWS\System32\bopomofo.uce
[2010/10/09 11:23:47 | 000,017,362 | —- | C] () – C:\WINDOWS\Rhododendron.bmp
[2010/10/09 11:23:47 | 000,017,336 | —- | C] () – C:\WINDOWS\Gone Fishing.bmp
[2010/10/09 11:23:47 | 000,017,062 | —- | C] () – C:\WINDOWS\Coffee Bean.bmp
[2010/10/09 11:23:47 | 000,016,740 | —- | C] () – C:\WINDOWS\System32\shiftjis.uce
[2010/10/09 11:23:47 | 000,012,876 | —- | C] () – C:\WINDOWS\System32\korean.uce
[2010/10/09 11:23:47 | 000,009,522 | —- | C] () – C:\WINDOWS\Zapotec.bmp
[2010/10/09 11:23:47 | 000,008,484 | —- | C] () – C:\WINDOWS\System32\kanji_2.uce
[2010/10/09 11:23:47 | 000,006,948 | —- | C] () – C:\WINDOWS\System32\kanji_1.uce
[2010/10/09 11:23:47 | 000,001,272 | —- | C] () – C:\WINDOWS\Blue Lace 16.bmp
[2010/10/09 11:23:46 | 000,003,286 | —- | C] () – C:\WINDOWS\System32\tslabels.h
[2010/10/09 11:23:46 | 000,001,161 | —- | C] () – C:\WINDOWS\System32\usrlogon.cmd
[2010/10/09 11:23:46 | 000,000,768 | —- | C] () – C:\WINDOWS\System32\msdtcprf.h
[2010/10/09 11:23:42 | 000,063,488 | —- | C] () – C:\WINDOWS\System32\wmimgmt.msc
[2010/10/09 04:08:32 | 001,685,606 | —- | C] () – C:\WINDOWS\System32\dllcache\sam.spd
[2010/10/09 04:08:32 | 000,000,888 | —- | C] () – C:\WINDOWS\System32\dllcache\sam.sdf
[2010/10/09 04:08:31 | 000,643,717 | —- | C] () – C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2010/10/09 04:08:31 | 000,605,050 | —- | C] () – C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2010/10/09 04:08:30 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_857.nls
[2010/10/09 04:08:30 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28603.nls
[2010/10/09 04:08:30 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28599.nls
[2010/10/09 04:08:30 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10081.nls
[2010/10/09 04:08:29 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\C_28595.NLS
[2010/10/09 04:08:29 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10017.nls
[2010/10/09 04:08:29 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10007.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_869.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_866.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_855.nls
[2010/10/09 04:08:28 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_737.nls
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_875.nls
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\C_28597.NLS
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\C_28594.NLS
[2010/10/09 04:08:28 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10006.nls
[2010/10/09 04:08:27 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_852.nls
[2010/10/09 04:08:27 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10082.nls
[2010/10/09 04:08:27 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10029.nls
[2010/10/09 04:08:27 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10010.nls
[2010/10/09 04:08:26 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_20127.nls
[2010/10/09 04:08:24 | 000,001,789 | —- | C] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2010/10/09 04:08:15 | 000,797,189 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010/10/09 04:08:15 | 000,657,548 | —- | C] () – C:\WINDOWS\System32\dllcache\CLASSES.CAT
[2010/10/09 04:08:15 | 000,399,645 | —- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010/10/09 04:08:15 | 000,390,168 | —- | C] () – C:\WINDOWS\System32\dllcache\WFC.CAT
[2010/10/09 04:08:15 | 000,056,081 | —- | C] () – C:\WINDOWS\System32\dllcache\DAJAVAC.CAT
[2010/10/09 04:08:15 | 000,052,311 | —- | C] () – C:\WINDOWS\System32\dllcache\DX3.CAT
[2010/10/09 04:08:15 | 000,037,484 | —- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2010/10/09 04:08:15 | 000,022,151 | —- | C] () – C:\WINDOWS\System32\dllcache\TCLASSES.CAT
[2010/10/09 04:08:15 | 000,021,281 | —- | C] () – C:\WINDOWS\System32\dllcache\XMLDSOC.CAT
[2010/10/09 04:08:15 | 000,014,031 | —- | C] () – C:\WINDOWS\System32\dllcache\MSJDBC.CAT
[2010/10/09 04:08:15 | 000,013,472 | —- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010/10/09 04:08:15 | 000,008,574 | —- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010/10/09 04:08:15 | 000,007,382 | —- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010/10/09 04:07:45 | 000,144,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/09 04:05:56 | 000,000,658 | —- | C] () – C:\WINDOWS\System32\$winnt$.inf
[2010/10/09 04:01:12 | 000,000,512 | -HS- | C] () – C:\BOOTSECT.DOS
[2010/10/09 04:01:11 | 000,000,281 | RHS- | C] () – C:\boot.ini
[2010/10/09 04:00:06 | 000,250,048 | RHS- | C] () – C:\ntldr
[2010/10/09 04:00:06 | 000,047,564 | RHS- | C] () – C:\ntdetect.com
[2010/10/09 03:59:48 | 000,127,213 | —- | C] () – C:\WINDOWS\System32\ega.cpi
[2010/10/09 03:59:45 | 000,082,944 | —- | C] () – C:\WINDOWS\clock.avi
[2010/10/09 03:59:26 | 000,001,696 | —- | C] () – C:\WINDOWS\System32\noise.cht
[2010/10/09 03:59:26 | 000,001,696 | —- | C] () – C:\WINDOWS\System32\noise.chs
[2010/10/09 03:59:25 | 000,069,886 | —- | C] () – C:\WINDOWS\System32\edit.com
[2010/10/09 03:59:25 | 000,010,790 | —- | C] () – C:\WINDOWS\System32\edit.hlp
[2010/10/09 03:59:06 | 000,000,697 | —- | C] () – C:\WINDOWS\System32\noise.tha
[2010/10/09 03:58:38 | 000,002,206 | —- | C] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/09 03:58:23 | 000,032,674 | —- | C] () – C:\WINDOWS\System32\winhelp.hlp
[2010/10/09 03:58:21 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\dllcache\win87em.dll
[2010/10/09 03:58:20 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\wiasf.ax
[2010/10/09 03:58:20 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\dllcache\wiasf.ax
[2010/10/09 03:58:18 | 001,326,080 | —- | C] () – C:\WINDOWS\System32\webfldrs.msi
[2010/10/09 03:58:17 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\wdl.trm
[2010/10/09 03:58:14 | 001,095,680 | —- | C] () – C:\WINDOWS\System32\wbdbase.nld
[2010/10/09 03:58:14 | 000,937,984 | —- | C] () – C:\WINDOWS\System32\wbdbase.sve
[2010/10/09 03:58:14 | 000,867,840 | —- | C] () – C:\WINDOWS\System32\wbdbase.ita
[2010/10/09 03:58:14 | 000,786,944 | —- | C] () – C:\WINDOWS\System32\wbdbase.fra
[2010/10/09 03:58:13 | 001,309,184 | —- | C] () – C:\WINDOWS\System32\wbdbase.deu
[2010/10/09 03:58:13 | 000,957,440 | —- | C] () – C:\WINDOWS\System32\wbdbase.enu
[2010/10/09 03:58:13 | 000,750,080 | —- | C] () – C:\WINDOWS\System32\wbdbase.esn
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.sve
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.nld
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.ita
[2010/10/09 03:58:13 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.fra
[2010/10/09 03:58:12 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.esn
[2010/10/09 03:58:12 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.enu
[2010/10/09 03:58:12 | 000,065,489 | —- | C] () – C:\WINDOWS\System32\wbcache.deu
[2010/10/09 03:58:09 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\vwipxspx.exe
[2010/10/09 03:58:09 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\dllcache\vwipxspx.exe
[2010/10/09 03:58:05 | 000,018,832 | —- | C] () – C:\WINDOWS\System32\v7vga.rom
[2010/10/09 03:58:00 | 000,089,588 | —- | C] () – C:\WINDOWS\System32\unicode.nls
[2010/10/09 03:57:57 | 000,015,360 | —- | C] () – C:\WINDOWS\System32\dllcache\tsd32.dll
[2010/10/09 03:57:50 | 000,000,862 | —- | C] () – C:\WINDOWS\System32\termcap
[2010/10/09 03:57:46 | 000,000,246 | —- | C] () – C:\WINDOWS\SYSTEM.UNV
[2010/10/09 03:57:45 | 000,003,577 | —- | C] () – C:\WINDOWS\System32\sysprtj.sep
[2010/10/09 03:57:45 | 000,003,214 | —- | C] () – C:\WINDOWS\System32\sysprint.sep
[2010/10/09 03:57:35 | 000,046,133 | —- | C] () – C:\WINDOWS\System32\sqlsodbc.chm
[2010/10/09 03:57:25 | 000,262,148 | —- | C] () – C:\WINDOWS\System32\sortkey.nls
[2010/10/09 03:57:25 | 000,023,044 | —- | C] () – C:\WINDOWS\System32\sorttbls.nls
[2010/10/09 03:57:15 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\share.exe
[2010/10/09 03:57:15 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\dllcache\share.exe
[2010/10/09 03:57:14 | 000,011,753 | —- | C] () – C:\WINDOWS\System32\setver.exe
[2010/10/09 03:57:13 | 000,240,120 | —- | C] () – C:\WINDOWS\System32\setup.bmp
[2010/10/09 03:57:13 | 000,059,167 | —- | C] () – C:\WINDOWS\System\setup.inf
[2010/10/09 03:57:12 | 000,033,464 | —- | C] () – C:\WINDOWS\System32\services.msc
[2010/10/09 03:57:12 | 000,007,116 | —- | C] () – C:\WINDOWS\System32\drivers\etc\services
[2010/10/09 03:57:10 | 000,036,364 | —- | C] () – C:\WINDOWS\System32\secpol.msc
[2010/10/09 03:57:09 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\scriptpw.dll
[2010/10/09 03:57:02 | 000,044,451 | R— | C] () – C:\WINDOWS\System32\rsop.msc
[2010/10/09 03:57:02 | 000,003,178 | —- | C] () – C:\WINDOWS\System32\rsvpcnts.h
[2010/10/09 03:57:01 | 000,003,167 | —- | C] () – C:\WINDOWS\System32\rsaci.rat
[2010/10/09 03:56:56 | 000,003,338 | —- | C] () – C:\WINDOWS\System32\redir.exe
[2010/10/09 03:56:52 | 000,001,818 | —- | C] () – C:\WINDOWS\System32\rasctrnm.h
[2010/10/09 03:56:44 | 000,003,708 | —- | C] () – C:\WINDOWS\System32\pubprn.vbs
[2010/10/09 03:56:44 | 000,003,708 | —- | C] () – C:\WINDOWS\System32\dllcache\pubprn.vbs
[2010/10/09 03:56:43 | 000,003,010 | —- | C] () – C:\WINDOWS\System32\pschdcnt.h
[2010/10/09 03:56:43 | 000,000,051 | —- | C] () – C:\WINDOWS\System32\pscript.sep
[2010/10/09 03:56:42 | 000,000,799 | —- | C] () – C:\WINDOWS\System32\drivers\etc\protocol
[2010/10/09 03:56:41 | 000,035,755 | —- | C] () – C:\WINDOWS\System32\prncnfg.vbs
[2010/10/09 03:56:41 | 000,035,755 | —- | C] () – C:\WINDOWS\System32\dllcache\prncnfg.vbs
[2010/10/09 03:56:41 | 000,032,546 | —- | C] () – C:\WINDOWS\System32\prnmngr.vbs
[2010/10/09 03:56:41 | 000,032,546 | —- | C] () – C:\WINDOWS\System32\dllcache\prnmngr.vbs
[2010/10/09 03:56:41 | 000,029,454 | —- | C] () – C:\WINDOWS\System32\prnport.vbs
[2010/10/09 03:56:41 | 000,029,454 | —- | C] () – C:\WINDOWS\System32\dllcache\prnport.vbs
[2010/10/09 03:56:41 | 000,025,415 | —- | C] () – C:\WINDOWS\System32\prndrvr.vbs
[2010/10/09 03:56:41 | 000,025,415 | —- | C] () – C:\WINDOWS\System32\dllcache\prndrvr.vbs
[2010/10/09 03:56:41 | 000,021,527 | —- | C] () – C:\WINDOWS\System32\prnjobs.vbs
[2010/10/09 03:56:41 | 000,021,527 | —- | C] () – C:\WINDOWS\System32\dllcache\prnjobs.vbs
[2010/10/09 03:56:41 | 000,015,860 | —- | C] () – C:\WINDOWS\System32\prnqctl.vbs
[2010/10/09 03:56:41 | 000,015,860 | —- | C] () – C:\WINDOWS\System32\dllcache\prnqctl.vbs
[2010/10/09 03:56:35 | 000,000,435 | —- | C] () – C:\WINDOWS\System32\perfwci.h
[2010/10/09 03:56:34 | 000,311,934 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/09 03:56:34 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2010/10/09 03:56:34 | 000,058,273 | R— | C] () – C:\WINDOWS\System32\perfmon.msc
[2010/10/09 03:56:34 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2010/10/09 03:56:34 | 000,000,140 | —- | C] () – C:\WINDOWS\System32\perffilt.h
[2010/10/09 03:56:33 | 000,040,196 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/09 03:56:33 | 000,000,427 | —- | C] () – C:\WINDOWS\System32\perfci.h
[2010/10/09 03:56:31 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\pcl.sep
[2010/10/09 03:56:26 | 000,167,219 | —- | C] () – C:\WINDOWS\System32\pagefileconfig.vbs
[2010/10/09 03:56:26 | 000,167,219 | —- | C] () – C:\WINDOWS\System32\dllcache\pagefile.vbs
[2010/10/09 03:56:19 | 000,006,761 | —- | C] () – C:\WINDOWS\System32\oembios.sig
[2010/10/09 03:56:19 | 000,006,761 | —- | C] () – C:\WINDOWS\System32\dllcache\oembios.sig
[2010/10/09 03:56:19 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2010/10/09 03:56:19 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\dllcache\oembios.dat
[2010/10/09 03:56:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2010/10/09 03:56:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\dllcache\oembios.bin
[2010/10/09 03:56:05 | 000,004,310 | —- | C] () – C:\WINDOWS\System32\odbcconf.rsp
[2010/10/09 03:56:03 | 000,003,252 | —- | C] () – C:\WINDOWS\System32\nw16.exe
[2010/10/09 03:56:03 | 000,003,252 | —- | C] () – C:\WINDOWS\System32\dllcache\nw16.exe
[2010/10/09 03:56:00 | 000,032,968 | —- | C] () – C:\WINDOWS\System32\ntmsoprq.msc
[2010/10/09 03:56:00 | 000,026,209 | —- | C] () – C:\WINDOWS\System32\ntmsmgr.msc
[2010/10/09 03:55:59 | 000,048,794 | —- | C] () – C:\WINDOWS\System32\ntimage.gif
[2010/10/09 03:55:58 | 000,029,146 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos804.sys
[2010/10/09 03:55:57 | 000,029,370 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos411.sys
[2010/10/09 03:55:57 | 000,029,274 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos412.sys
[2010/10/09 03:55:57 | 000,029,146 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos404.sys
[2010/10/09 03:55:57 | 000,027,866 | —- | C] () – C:\WINDOWS\System32\dllcache\ntdos.sys
[2010/10/09 03:55:54 | 000,149,848 | —- | C] () – C:\WINDOWS\System32\noise.deu
[2010/10/09 03:55:54 | 000,049,196 | —- | C] () – C:\WINDOWS\System32\noise.fra
[2010/10/09 03:55:54 | 000,019,684 | —- | C] () – C:\WINDOWS\System32\noise.esn
[2010/10/09 03:55:54 | 000,019,618 | —- | C] () – C:\WINDOWS\System32\noise.ita
[2010/10/09 03:55:54 | 000,013,730 | —- | C] () – C:\WINDOWS\System32\noise.sve
[2010/10/09 03:55:54 | 000,013,256 | —- | C] () – C:\WINDOWS\System32\noise.nld
[2010/10/09 03:55:54 | 000,000,751 | —- | C] () – C:\WINDOWS\System32\noise.enu
[2010/10/09 03:55:54 | 000,000,751 | —- | C] () – C:\WINDOWS\System32\noise.eng
[2010/10/09 03:55:54 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2010/10/09 03:55:53 | 000,007,052 | —- | C] () – C:\WINDOWS\System32\nlsfunc.exe
[2010/10/09 03:55:53 | 000,007,052 | —- | C] () – C:\WINDOWS\System32\dllcache\nlsfunc.exe
[2010/10/09 03:55:51 | 000,000,407 | —- | C] () – C:\WINDOWS\System32\drivers\etc\networks
[2010/10/09 03:55:46 | 000,102,446 | —- | C] () – C:\WINDOWS\System32\net.hlp
[2010/10/09 03:55:24 | 000,844,314 | —- | C] () – C:\WINDOWS\System32\msdxm.ocx
[2010/10/09 03:55:22 | 000,000,817 | —- | C] () – C:\WINDOWS\System32\mscdexnt.exe
[2010/10/09 03:55:22 | 000,000,817 | —- | C] () – C:\WINDOWS\System32\dllcache\mscdexnt.exe
[2010/10/09 03:55:16 | 000,002,755 | —- | C] () – C:\WINDOWS\System32\mqprfsym.h
[2010/10/09 03:55:15 | 000,148,992 | —- | C] () – C:\WINDOWS\System32\mpg2splt.ax
[2010/10/09 03:55:11 | 000,001,492 | —- | C] () – C:\WINDOWS\System32\mmdriver.inf
[2010/10/09 03:55:10 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2010/10/09 03:55:09 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2010/10/09 03:55:06 | 000,039,274 | —- | C] () – C:\WINDOWS\System32\mem.exe
[2010/10/09 03:55:06 | 000,039,274 | —- | C] () – C:\WINDOWS\System32\dllcache\mem.exe
[2010/10/09 03:54:59 | 000,042,166 | —- | C] () – C:\WINDOWS\System32\lusrmgr.msc
[2010/10/09 03:54:57 | 000,265,948 | —- | C] () – C:\WINDOWS\System32\locale.nls
[2010/10/09 03:54:57 | 000,000,487 | —- | C] () – C:\WINDOWS\System32\login.cmd
[2010/10/09 03:54:56 | 000,003,683 | —- | C] () – C:\WINDOWS\System32\drivers\etc\lmhosts.sam
[2010/10/09 03:54:56 | 000,001,131 | —- | C] () – C:\WINDOWS\System32\loadfix.com
[2010/10/09 03:54:54 | 000,007,046 | —- | C] () – C:\WINDOWS\System32\l_intl.nls
[2010/10/09 03:54:54 | 000,000,168 | —- | C] () – C:\WINDOWS\System32\l_except.nls
[2010/10/09 03:54:53 | 000,042,809 | —- | C] () – C:\WINDOWS\System32\dllcache\key01.sys
[2010/10/09 03:54:53 | 000,042,537 | —- | C] () – C:\WINDOWS\System32\dllcache\keyboard.sys
[2010/10/09 03:54:50 | 000,014,710 | —- | C] () – C:\WINDOWS\System32\kb16.com
[2010/10/09 03:54:43 | 000,956,990 | —- | C] () – C:\WINDOWS\System32\instcat.sql
[2010/10/09 03:54:29 | 000,000,929 | —- | C] () – C:\WINDOWS\System32\homepage.inf
[2010/10/09 03:54:27 | 000,004,768 | —- | C] () – C:\WINDOWS\System32\dllcache\himem.sys
[2010/10/09 03:54:23 | 000,021,232 | —- | C] () – C:\WINDOWS\System32\graphics.pro
[2010/10/09 03:54:23 | 000,019,694 | —- | C] () – C:\WINDOWS\System32\graphics.com
[2010/10/09 03:54:22 | 000,034,871 | —- | C] () – C:\WINDOWS\System32\gpedit.msc
[2010/10/09 03:54:20 | 003,440,660 | —- | C] () – C:\WINDOWS\System32\drivers\gm.dls
[2010/10/09 03:54:20 | 000,024,772 | —- | C] () – C:\WINDOWS\System32\geo.nls
[2010/10/09 03:54:15 | 000,152,844 | —- | C] () – C:\WINDOWS\System32\dllcache\framdit.ttf
[2010/10/09 03:54:15 | 000,135,984 | —- | C] () – C:\WINDOWS\System32\dllcache\framd.ttf
[2010/10/09 03:54:15 | 000,032,760 | —- | C] () – C:\WINDOWS\System32\fsmgmt.msc
[2010/10/09 03:54:09 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\fastopen.exe
[2010/10/09 03:54:09 | 000,000,882 | —- | C] () – C:\WINDOWS\System32\dllcache\fastopen.exe
[2010/10/09 03:54:08 | 000,000,080 | —- | C] () – C:\WINDOWS\explorer.scf
[2010/10/09 03:54:04 | 000,097,965 | —- | C] () – C:\WINDOWS\System32\dllcache\evtquery.vbs
[2010/10/09 03:54:04 | 000,097,965 | —- | C] () – C:\WINDOWS\System32\eventquery.vbs
[2010/10/09 03:54:04 | 000,008,424 | —- | C] () – C:\WINDOWS\System32\exe2bin.exe
[2010/10/09 03:54:04 | 000,008,424 | —- | C] () – C:\WINDOWS\System32\dllcache\exe2bin.exe
[2010/10/09 03:54:03 | 000,056,678 | —- | C] () – C:\WINDOWS\System32\eventvwr.msc
[2010/10/09 03:54:01 | 000,006,708 | —- | C] () – C:\WINDOWS\System32\esentprf.hxx
[2010/10/09 03:53:59 | 000,012,642 | —- | C] () – C:\WINDOWS\System32\edlin.exe
[2010/10/09 03:53:59 | 000,012,642 | —- | C] () – C:\WINDOWS\System32\dllcache\edlin.exe
[2010/10/09 03:53:53 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2010/10/09 03:53:52 | 000,000,081 | —- | C] () – C:\WINDOWS\System32\dsound.vxd
[2010/10/09 03:53:18 | 000,053,840 | —- | C] () – C:\WINDOWS\System32\dosx.exe
[2010/10/09 03:53:16 | 000,033,673 | —- | C] () – C:\WINDOWS\System32\diskmgmt.msc
[2010/10/09 03:53:13 | 000,041,397 | —- | C] () – C:\WINDOWS\System32\dfrg.msc
[2010/10/09 03:53:13 | 000,033,079 | —- | C] () – C:\WINDOWS\System32\devmgmt.msc
[2010/10/09 03:53:13 | 000,020,634 | —- | C] () – C:\WINDOWS\System32\dllcache\debug.exe
[2010/10/09 03:53:13 | 000,020,634 | —- | C] () – C:\WINDOWS\System32\debug.exe
[2010/10/09 03:53:12 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2010/10/09 03:53:10 | 000,008,386 | —- | C] () – C:\WINDOWS\System32\ctype.nls
[2010/10/09 03:53:08 | 000,027,097 | —- | C] () – C:\WINDOWS\System32\dllcache\country.sys
[2010/10/09 03:53:06 | 000,038,302 | —- | C] () – C:\WINDOWS\System32\compmgmt.msc
[2010/10/09 03:53:05 | 000,050,620 | —- | C] () – C:\WINDOWS\System32\command.com
[2010/10/09 03:53:04 | 000,061,172 | —- | C] () – C:\WINDOWS\System32\cmmgr32.hlp
[2010/10/09 03:53:04 | 000,040,505 | —- | C] () – C:\WINDOWS\System32\cmdlib.wsc
[2010/10/09 03:53:04 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\cmos.ram
[2010/10/09 03:53:03 | 000,071,859 | —- | C] () – C:\WINDOWS\System32\cliconf.chm
[2010/10/09 03:53:01 | 000,041,762 | —- | C] () – C:\WINDOWS\System32\ciadv.msc
[2010/10/09 03:53:00 | 000,042,339 | —- | C] () – C:\WINDOWS\System32\certmgr.msc
[2010/10/09 03:53:00 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\View Channels.scf
[2010/10/09 03:52:57 | 000,196,642 | —- | C] () – C:\WINDOWS\System32\c_950.nls
[2010/10/09 03:52:57 | 000,196,642 | —- | C] () – C:\WINDOWS\System32\c_949.nls
[2010/10/09 03:52:57 | 000,196,642 | —- | C] () – C:\WINDOWS\System32\c_936.nls
[2010/10/09 03:52:57 | 000,162,850 | —- | C] () – C:\WINDOWS\System32\c_932.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_874.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_865.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_863.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_861.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_860.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_850.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_775.nls
[2010/10/09 03:52:57 | 000,066,594 | —- | C] () – C:\WINDOWS\System32\c_437.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_500.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28605.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28598.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28593.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28592.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_28591.nls
[2010/10/09 03:52:57 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_21866.nls
[2010/10/09 03:52:56 | 000,139,810 | —- | C] () – C:\WINDOWS\System32\c_20261.nls
[2010/10/09 03:52:56 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_20905.nls
[2010/10/09 03:52:56 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_20866.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1258.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1257.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1256.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1255.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1254.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1253.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1252.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1251.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1250.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_1026.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10079.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_10000.nls
[2010/10/09 03:52:55 | 000,066,082 | —- | C] () – C:\WINDOWS\System32\c_037.nls
[2010/10/09 03:52:53 | 000,028,420 | —- | C] () – C:\WINDOWS\System32\bios1.rom
[2010/10/09 03:52:53 | 000,008,191 | —- | C] () – C:\WINDOWS\System32\bios4.rom
[2010/10/09 03:52:47 | 000,012,498 | —- | C] () – C:\WINDOWS\System32\dllcache\append.exe
[2010/10/09 03:52:47 | 000,012,498 | —- | C] () – C:\WINDOWS\System32\append.exe
[2010/10/09 03:52:47 | 000,009,029 | —- | C] () – C:\WINDOWS\System32\dllcache\ansi.sys
[2010/10/09 03:52:43 | 000,002,233 | —- | C] () – C:\WINDOWS\System32\dllcache\12520850.cpx
[2010/10/09 03:52:43 | 000,002,233 | —- | C] () – C:\WINDOWS\System32\12520850.cpx
[2010/10/09 03:52:43 | 000,002,151 | —- | C] () – C:\WINDOWS\System32\dllcache\12520437.cpx
[2010/10/09 03:52:43 | 000,002,151 | —- | C] () – C:\WINDOWS\System32\12520437.cpx
[2010/10/09 03:52:43 | 000,000,707 | —- | C] () – C:\WINDOWS\_default.pif
[2010/09/29 15:52:12 | 000,000,000 | —- | C] () – C:\Documents and Settings\Vern McKinney\defogger_reenable
[2010/09/29 15:35:47 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/09/29 15:35:47 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/09/29 15:35:47 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/09/29 15:35:47 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/09/29 15:35:47 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/09/29 15:33:56 | 003,858,327 | R— | C] () – C:\Documents and Settings\Vern McKinney\Desktop\ComboFix.exe
[2010/09/29 15:17:23 | 000,284,915 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\gmer.zip
[2010/09/29 15:16:53 | 000,050,477 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\Defogger.exe
[2010/09/28 13:49:56 | 000,000,070 | —- | C] () – C:\AUTOEXEC.BAT
[2010/09/28 13:49:56 | 000,000,040 | —- | C] () – C:\CONFIG.SYS
[2010/09/27 15:45:49 | 000,004,981 | —- | C] () – C:\SiSUnist.ini
[2010/09/27 15:45:49 | 000,003,917 | —- | C] () – C:\SiSSetup1.ini
[2010/09/27 15:44:58 | 000,049,152 | —- | C] () – C:\OEMROM.BIN
[2010/09/27 15:24:57 | 000,000,070 | —- | C] () – C:\AUTOEXEC.NS0
[2010/09/27 15:24:57 | 000,000,040 | —- | C] () – C:\CONFIG.NS0
[2010/09/27 15:16:00 | 000,049,152 | -HS- | C] () – C:\VIDEOROM.BIN
[2010/09/27 15:15:40 | 000,046,548 | -HS- | C] () – C:\BOOTLOG.PRV
[2010/09/27 15:14:32 | 000,011,079 | —- | C] () – C:\Program Files\folder.htt
[2010/09/27 00:20:15 | 000,002,000 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\HiJackThis.lnk
[2010/09/27 00:04:56 | 000,305,771 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\HijackThis.zip
[2010/09/26 23:17:36 | 001,402,880 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\Verns Fix.msi
[2010/09/26 15:11:00 | 000,000,845 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2010/09/18 16:32:18 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/09/18 16:30:16 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/18 16:19:11 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/09/18 16:19:11 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/09/15 18:25:16 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/09/06 16:56:36 | 000,001,552 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\CCleaner.lnk
[2010/08/25 19:50:01 | 000,000,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/24 21:07:48 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/08/24 21:07:45 | 000,260,272 | —- | C] () – C:\cmldr
[2010/08/05 23:53:21 | 014,306,443 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\DMV HearingPictures.zip
[2010/08/01 20:37:03 | 000,025,600 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Discussion Topic.doc
[2010/07/20 19:23:56 | 000,084,480 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Poker%20Run[1].doc
[2010/07/05 16:05:57 | 000,020,992 | —- | C] () – C:\Documents and Settings\Vern McKinney\My Documents\Crockett Monday Night.doc
[2010/07/04 03:12:17 | 000,001,455 | —- | C] () – C:\Documents and Settings\Vern McKinney\Desktop\WebEx Player.LNK
[2010/05/22 15:22:13 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/13 00:55:04 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/03/22 17:05:18 | 000,000,102 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2008/04/10 19:47:59 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2007/10/28 14:01:06 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\TVModeLib.dll
[2007/10/28 14:01:05 | 000,034,915 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2007/10/28 14:01:05 | 000,016,819 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2007/10/28 13:59:58 | 000,000,000 | —- | C] () – C:\WINDOWS\khooker.INI
[2007/07/25 21:49:33 | 000,000,051 | —- | C] () – C:\WINDOWS\ASAPrep.ini
[2006/12/18 21:08:58 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/04/14 17:09:47 | 000,005,147 | —- | C] () – C:\Documents and Settings\Vern McKinney\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/04/14 17:09:47 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/02/20 18:10:02 | 000,000,008 | —- | C] () – C:\WINDOWS\sdcomchk.ini
[2006/01/17 12:34:37 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/01/16 02:03:25 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2006/01/16 01:13:18 | 000,023,847 | —- | C] () – C:\WINDOWS\stub14.ini
[2006/01/15 07:13:37 | 000,025,035 | —- | C] () – C:\WINDOWS\stub41.ini
[2006/01/15 07:13:37 | 000,024,667 | —- | C] () – C:\WINDOWS\stub50.ini
[2006/01/05 10:20:09 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\bxquv.dll
[2006/01/03 22:51:43 | 000,022,742 | —- | C] () – C:\WINDOWS\stub91.ini
[2006/01/03 22:51:08 | 000,025,728 | —- | C] () – C:\WINDOWS\stub90.ini
[2006/01/03 22:35:28 | 000,025,441 | —- | C] () – C:\WINDOWS\stub89.ini
[2006/01/03 22:34:26 | 000,025,543 | —- | C] () – C:\WINDOWS\stub88.ini
[2006/01/03 22:30:11 | 000,025,695 | —- | C] () – C:\WINDOWS\stub87.ini
[2006/01/03 22:30:09 | 000,025,438 | —- | C] () – C:\WINDOWS\stub86.ini
[2006/01/02 23:54:39 | 000,025,197 | —- | C] () – C:\WINDOWS\stub85.ini
[2006/01/02 23:52:42 | 000,025,684 | —- | C] () – C:\WINDOWS\stub84.ini
[2006/01/02 23:51:26 | 000,026,118 | —- | C] () – C:\WINDOWS\stub83.ini
[2006/01/02 23:50:52 | 000,025,882 | —- | C] () – C:\WINDOWS\stub82.ini
[2006/01/02 23:49:30 | 000,026,444 | —- | C] () – C:\WINDOWS\stub81.ini
[2006/01/02 23:48:14 | 000,025,840 | —- | C] () – C:\WINDOWS\stub80.ini
[2006/01/02 23:44:42 | 000,025,314 | —- | C] () – C:\WINDOWS\stub79.ini
[2006/01/02 23:44:16 | 000,025,812 | —- | C] () – C:\WINDOWS\stub78.ini
[2006/01/02 23:43:51 | 000,025,329 | —- | C] () – C:\WINDOWS\stub77.ini
[2006/01/02 23:42:56 | 000,026,785 | —- | C] () – C:\WINDOWS\stub76.ini
[2006/01/02 23:42:32 | 000,026,386 | —- | C] () – C:\WINDOWS\stub75.ini
[2006/01/02 23:42:18 | 000,026,446 | —- | C] () – C:\WINDOWS\stub74.ini
[2006/01/02 23:41:17 | 000,026,417 | —- | C] () – C:\WINDOWS\stub73.ini
[2006/01/02 23:40:57 | 000,026,300 | —- | C] () – C:\WINDOWS\stub72.ini
[2006/01/02 23:40:25 | 000,026,413 | —- | C] () – C:\WINDOWS\stub71.ini
[2006/01/02 23:39:36 | 000,025,626 | —- | C] () – C:\WINDOWS\stub70.ini
[2006/01/02 23:39:11 | 000,025,949 | —- | C] () – C:\WINDOWS\stub69.ini
[2006/01/02 23:37:46 | 000,026,241 | —- | C] () – C:\WINDOWS\stub67.ini
[2006/01/02 23:36:24 | 000,026,472 | —- | C] () – C:\WINDOWS\stub66.ini
[2006/01/02 15:02:42 | 000,024,410 | —- | C] () – C:\WINDOWS\stub31.ini
[2006/01/02 15:02:42 | 000,022,711 | —- | C] () – C:\WINDOWS\stub2.ini
[2006/01/01 23:27:05 | 000,026,174 | —- | C] () – C:\WINDOWS\stub65.ini
[2006/01/01 22:54:32 | 000,024,912 | —- | C] () – C:\WINDOWS\stub64.ini
[2006/01/01 22:38:50 | 000,025,074 | —- | C] () – C:\WINDOWS\stub63.ini
[2006/01/01 22:38:16 | 000,025,293 | —- | C] () – C:\WINDOWS\stub62.ini
[2006/01/01 22:34:30 | 000,025,066 | —- | C] () – C:\WINDOWS\stub61.ini
[2006/01/01 06:36:49 | 000,024,565 | —- | C] () – C:\WINDOWS\stub27.ini
[2005/12/31 23:11:39 | 000,025,594 | —- | C] () – C:\WINDOWS\stub60.ini
[2005/12/31 23:11:26 | 000,025,271 | —- | C] () – C:\WINDOWS\stub59.ini
[2005/12/31 23:11:11 | 000,026,307 | —- | C] () – C:\WINDOWS\stub58.ini
[2005/12/31 23:10:59 | 000,025,008 | —- | C] () – C:\WINDOWS\stub57.ini
[2005/12/31 23:10:20 | 000,025,293 | —- | C] () – C:\WINDOWS\stub55.ini
[2005/12/31 23:09:40 | 000,025,311 | —- | C] () – C:\WINDOWS\stub54.ini
[2005/12/31 23:09:20 | 000,025,635 | —- | C] () – C:\WINDOWS\stub53.ini
[2005/12/31 23:09:07 | 000,025,546 | —- | C] () – C:\WINDOWS\stub52.ini
[2005/12/31 23:08:50 | 000,025,592 | —- | C] () – C:\WINDOWS\stub51.ini
[2005/12/31 23:06:55 | 000,024,795 | —- | C] () – C:\WINDOWS\stub49.ini
[2005/12/31 22:58:54 | 000,024,921 | —- | C] () – C:\WINDOWS\stub47.ini
[2005/12/31 22:58:30 | 000,025,352 | —- | C] () – C:\WINDOWS\stub46.ini
[2005/12/31 22:58:13 | 000,024,766 | —- | C] () – C:\WINDOWS\stub45.ini
[2005/12/31 22:57:57 | 000,024,710 | —- | C] () – C:\WINDOWS\stub44.ini
[2005/12/31 22:57:48 | 000,025,043 | —- | C] () – C:\WINDOWS\stub43.ini
[2005/12/31 22:57:24 | 000,024,914 | —- | C] () – C:\WINDOWS\stub42.ini
[2005/12/31 22:56:49 | 000,024,703 | —- | C] () – C:\WINDOWS\stub40.ini
[2005/12/31 22:54:59 | 000,024,420 | —- | C] () – C:\WINDOWS\stub39.ini
[2005/12/31 22:50:21 | 000,024,711 | —- | C] () – C:\WINDOWS\stub38.ini
[2005/12/31 22:49:58 | 000,024,442 | —- | C] () – C:\WINDOWS\stub37.ini
[2005/12/31 06:56:46 | 000,024,305 | —- | C] () – C:\WINDOWS\stub35.ini
[2005/12/31 06:56:28 | 000,024,912 | —- | C] () – C:\WINDOWS\stub34.ini
[2005/12/31 06:56:01 | 000,024,391 | —- | C] () – C:\WINDOWS\stub33.ini
[2005/12/31 06:54:49 | 000,024,809 | —- | C] () – C:\WINDOWS\stub30.ini
[2005/12/31 06:54:16 | 000,024,364 | —- | C] () – C:\WINDOWS\stub29.ini
[2005/12/31 06:54:01 | 000,024,101 | —- | C] () – C:\WINDOWS\stub28.ini
[2005/12/31 06:53:11 | 000,023,818 | —- | C] () – C:\WINDOWS\stub26.ini
[2005/12/31 06:52:53 | 000,023,904 | —- | C] () – C:\WINDOWS\stub25.ini
[2005/12/31 06:52:41 | 000,023,580 | —- | C] () – C:\WINDOWS\stub24.ini
[2005/12/31 06:52:24 | 000,024,085 | —- | C] () – C:\WINDOWS\stub23.ini
[2005/12/31 06:52:06 | 000,023,060 | —- | C] () – C:\WINDOWS\stub22.ini
[2005/12/31 06:51:20 | 000,023,219 | —- | C] () – C:\WINDOWS\stub21.ini
[2005/12/31 06:50:55 | 000,023,685 | —- | C] () – C:\WINDOWS\stub20.ini
[2005/12/31 06:50:45 | 000,022,835 | —- | C] () – C:\WINDOWS\stub19.ini
[2005/12/31 06:50:30 | 000,022,118 | —- | C] () – C:\WINDOWS\stub18.ini
[2005/12/31 06:48:51 | 000,023,395 | —- | C] () – C:\WINDOWS\stub17.ini
[2005/12/31 06:48:29 | 000,023,622 | —- | C] () – C:\WINDOWS\stub16.ini
[2005/12/31 06:48:02 | 000,023,264 | —- | C] () – C:\WINDOWS\stub15.ini
[2005/12/31 06:25:39 | 000,023,745 | —- | C] () – C:\WINDOWS\stub13.ini
[2005/12/31 06:25:14 | 000,023,567 | —- | C] () – C:\WINDOWS\stub12.ini
[2005/12/31 06:17:39 | 000,023,501 | —- | C] () – C:\WINDOWS\stub11.ini
[2005/12/31 06:12:33 | 000,023,416 | —- | C] () – C:\WINDOWS\stub10.ini
[2005/12/31 06:11:41 | 000,023,496 | —- | C] () – C:\WINDOWS\stub9.ini
[2005/12/29 23:44:51 | 000,023,318 | —- | C] () – C:\WINDOWS\stub8.ini
[2005/12/29 23:42:15 | 000,023,344 | —- | C] () – C:\WINDOWS\stub7.ini
[2005/12/29 23:41:23 | 000,023,619 | —- | C] () – C:\WINDOWS\stub6.ini
[2005/12/29 23:40:29 | 000,023,500 | —- | C] () – C:\WINDOWS\stub5.ini
[2005/12/29 23:29:43 | 000,023,246 | —- | C] () – C:\WINDOWS\stub4.ini
[2005/12/29 23:22:39 | 000,023,166 | —- | C] () – C:\WINDOWS\stub3.ini
[2005/12/26 04:34:50 | 000,025,914 | —- | C] () – C:\WINDOWS\stub68.ini
[2005/12/26 04:34:50 | 000,025,158 | —- | C] () – C:\WINDOWS\stub56.ini
[2005/12/22 13:35:45 | 000,024,735 | —- | C] () – C:\WINDOWS\stub36.ini
[2005/12/22 13:14:17 | 000,024,864 | —- | C] () – C:\WINDOWS\stub48.ini
[2005/12/20 11:39:42 | 000,000,000 | —- | C] () – C:\WINDOWS\logs2.ini
[2005/12/18 12:32:22 | 000,024,500 | —- | C] () – C:\WINDOWS\stub32.ini
[2005/08/08 18:01:14 | 000,000,363 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/07/06 23:46:19 | 000,000,695 | —- | C] () – C:\WINDOWS\GARMINWT.INI
[2005/04/01 16:16:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/03/26 12:30:29 | 000,000,090 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/01/16 13:09:56 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/12/11 16:42:01 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2004/10/18 23:03:52 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2004/10/09 23:20:36 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/10/09 23:20:36 | 000,000,023 | —- | C] () – C:\WINDOWS\mid.ini
[2004/10/09 22:14:10 | 000,000,196 | —- | C] () – C:\WINDOWS\aeirem.ini
[2004/03/30 00:15:02 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\ThriXXX010205PNG.dll
[2004/03/30 00:15:01 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\ThriXXX015003JP2.dll
[2004/03/30 00:15:01 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\ThriXXX010104Z.dll
[2003/07/14 12:30:28 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2003/05/23 03:08:52 | 000,107,008 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2003/05/23 03:08:52 | 000,020,992 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/12/05 18:51:00 | 000,059,392 | R— | C] () – C:\WINDOWS\streamhlp.dll
[1999/01/22 11:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========
[2005/03/26 12:33:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2006/12/15 00:01:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2007/08/19 22:08:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/02/04 00:52:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2004/12/11 16:44:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2005/05/10 23:15:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Vern McKinney\Application Data\Leadertech
[2004/10/18 23:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Vern McKinney\Application Data\Nikon
[2007/02/04 00:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Vern McKinney\Application Data\Viewpoint
[2009/12/15 02:17:42 | 000,000,356 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/12/01 02:00:12 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/03/31 03:41:45 | 000,006,754 | —- | M] () – C:\artpdbg.log
[2010/09/28 13:49:58 | 000,000,070 | —- | M] () – C:\AUTOEXEC.BAT
[2004/09/27 14:52:16 | 000,000,038 | -HS- | M] () – C:\AUTOEXEC.DOS
[2010/09/27 15:15:32 | 000,000,070 | —- | M] () – C:\AUTOEXEC.NS0
[2010/08/24 20:36:30 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/24 21:07:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2006/11/19 22:46:01 | 000,012,504 | —- | M] () – C:\bootex.log
[2010/09/27 15:15:40 | 000,046,548 | -HS- | M] () – C:\BOOTLOG.PRV
[2010/09/27 15:28:12 | 000,050,892 | -HS- | M] () – C:\BOOTLOG.TXT
[2010/10/09 04:01:14 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2006/10/29 17:08:34 | 000,007,624 | —- | M] () – C:\caavsetup.log
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/09/29 15:45:37 | 000,023,032 | —- | M] () – C:\ComboFix.txt
[1999/04/23 15:22:00 | 000,093,890 | -HS- | M] () – C:\COMMAND.COM
[2005/12/24 14:52:29 | 000,002,855 | —- | M] () – C:\COMMAND.PIF
[2004/09/27 14:52:16 | 000,000,040 | -HS- | M] () – C:\CONFIG.DOS
[2010/09/27 15:15:32 | 000,000,040 | —- | M] () – C:\CONFIG.NS0
[2010/09/28 13:49:58 | 000,000,040 | —- | M] () – C:\CONFIG.SYS
[2004/09/27 15:08:38 | 000,072,494 | -HS- | M] () – C:\DETLOG.TXT
[2007/08/24 22:10:27 | 000,007,019 | —- | M] () – C:\dnsbak.reg
[2010/01/16 15:00:21 | 000,000,471 | —- | M] () – C:\FRONTPG.LOG
[2004/09/27 15:07:06 | 000,001,012 | —- | M] () – C:\FRUNLOG.TXT
[2007/08/26 05:40:57 | 000,001,268 | —- | M] () – C:\fsbl-20070826120353.log
[2007/09/01 00:34:59 | 000,000,920 | —- | M] () – C:\fsbl-20070901072420.log
[2007/09/01 00:49:39 | 000,000,920 | —- | M] () – C:\fsbl-20070901073754.log
[2007/09/01 01:00:34 | 000,000,920 | —- | M] () – C:\fsbl-20070901075045.log
[2007/09/01 10:47:19 | 000,000,920 | —- | M] () – C:\fsbl-20070901172824.log
[2007/09/02 11:02:11 | 000,000,920 | —- | M] () – C:\fsbl-20070902175050.log
[2007/09/02 12:19:18 | 000,000,920 | —- | M] () – C:\fsbl-20070902190259.log
[2007/09/03 09:18:36 | 000,000,922 | —- | M] () – C:\fsbl-20070903160204.log
[2007/08/26 05:02:53 | 000,904,048 | —- | M] (F-Secure Corporation) – C:\fsbl.exe
[1999/04/23 15:22:00 | 000,222,390 | RHS- | M] () – C:\IO.SYS
[2004/09/27 14:54:34 | 000,000,009 | -HS- | M] () – C:\MSDOS.—
[2004/09/27 15:09:34 | 000,001,685 | RHS- | M] () – C:\MSDOS.SYS
[2010/03/17 21:39:32 | 015,132,878 | —- | M] () – C:\NASA-2010 Blower & Gear Box- Compressed (zipped) Folder.zip
[2010/09/27 15:15:16 | 000,006,064 | -HS- | M] () – C:\NETLOG.TXT
[2004/10/10 11:47:59 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2010/08/24 20:02:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2001/12/07 04:04:30 | 000,049,152 | —- | M] () – C:\OEMROM.BIN
[2010/10/02 00:18:25 | 352,321,536 | -HS- | M] () – C:\pagefile.sys
[2008/09/05 16:53:36 | 000,003,650 | —- | M] () – C:\rapport.txt
[2010/09/26 22:24:17 | 000,000,385 | —- | M] () – C:\rkill.log
[2009/12/09 19:31:11 | 000,030,208 | —- | M] () – C:\San Mateo Bridge Pier # 1 Compressor Valve Temps.12-21-09.xls
[2010/09/27 15:22:44 | 000,000,436 | —- | M] () – C:\SCANDISK.LOG
[2010/09/27 15:15:16 | 000,120,590 | -HS- | M] () – C:\SETUPLOG.TXT
[2010/10/09 11:51:36 | 000,000,340 | —- | M] () – C:\SiSSetup.txt
[2010/10/09 11:51:24 | 000,003,917 | —- | M] () – C:\SiSSetup1.ini
[2010/10/09 11:50:42 | 000,004,981 | —- | M] () – C:\SiSUnist.ini
[2004/09/27 15:04:02 | 000,005,166 | -HS- | M] () – C:\SUHDLOG.DAT
[2004/09/27 15:04:02 | 000,585,760 | -HS- | M] () – C:\SYSTEM.1ST
[2010/09/27 15:16:00 | 000,049,152 | -HS- | M] () – C:\VIDEOROM.BIN
[2006/01/17 23:13:33 | 000,000,061 | —- | M] () – C:\vundofix.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/10/09 11:26:52 | 000,000,067 | -HS- | M] () – C:\WINDOWS\FONTS\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/09/27 15:14:34 | 000,000,266 | -HS- | M] () – C:\Program Files\desktop.ini
[2010/09/27 15:14:34 | 000,011,079 | —- | M] () – C:\Program Files\folder.htt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/10/09 04:06:00 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\config\default.sav
[2010/10/09 04:06:00 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\config\software.sav
[2010/10/09 04:06:00 | 000,397,312 | —- | M] () – C:\WINDOWS\SYSTEM32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/24 20:10:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/10/03 10:54:39 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/09 11:34:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Vern McKinney\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/01/21 16:42:11 | 002,855,080 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\aawsepersonal.exe
[2007/08/26 04:50:38 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Vern McKinney\Desktop\ATF-Cleaner.exe
[2010/09/29 15:34:02 | 003,858,327 | R— | M] () – C:\Documents and Settings\Vern McKinney\Desktop\ComboFix.exe
[2010/09/30 03:43:45 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Vern McKinney\Desktop\cwshredder.exe
[2010/09/29 15:16:54 | 000,050,477 | —- | M] () – C:\Documents and Settings\Vern McKinney\Desktop\Defogger.exe
[2007/08/24 22:07:17 | 000,486,349 | —- | M] ( ) – C:\Documents and Settings\Vern McKinney\Desktop\Fixwareout.exe
[2010/09/28 19:23:17 | 000,921,512 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Vern McKinney\Desktop\Norton_Removal_Tool.exe
[2010/09/28 19:38:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Vern McKinney\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >
[2010/09/28 13:51:56 | 008,028,298 | RH– | M] () – C:\Program Files\Internet Explorer\ie6bak.DAT

< %USERPROFILE%\My Documents\*.exe >
[2005/02/02 21:10:13 | 002,662,400 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\B&T Spindles.exe
[2010/07/23 18:27:35 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Vern McKinney\My Documents\IE 8.exe
[2003/10/15 08:47:24 | 001,221,659 | —- | M] () – C:\Documents and Settings\Vern McKinney\My Documents\MAT-V1-1.exe Aqu, screen saver.exe
[2007/07/25 20:51:31 | 000,196,608 | —- | M] ( ) – C:\Documents and Settings\Vern McKinney\My Documents\Prepware Updater.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2004/10/10 12:20:38 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/10/02 01:35:58 | 000,081,920 | -HS- | M] () – C:\Documents and Settings\Vern McKinney\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >
[2005/01/28 13:44:28 | 000,192,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\INF\unregmp2.exe

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.exe >
[2008/04/13 17:12:28 | 001,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
[2002/08/20 15:08:38 | 000,069,663 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgsin.exe

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< %USERPROFILE%\Templates\*.tmp >

< %SYSTEMDRIVE%\explorexxx.exe\*.* >

< %Windir%\Installer\*.tmp >
[6 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]

< %systemroot%\System32\*.xco >

< %ProgramFiles%\system32\*.* >

< %systemroot%\System32\windos\*.* >

< %SystemRoot%\system32\sandbox\*.* >

< %SystemRoot%\system32\*.amo >

< %SystemRoot%\system32\Windows Live\*.* >

< %ProgramFiles%\logs\*.* >

< %ProgramFiles%\Bifrost\*.* >

< %SystemRoot%\system32\*.goo >

< %systemroot%\system32\IME\*.* >

< %systemroot%\BackUp\*.* >

< %systemroot%\system32\*.ico >

< %systemroot%\system\*.dat >

< %systemroot%\system\*.exe >

< %AppData%\Macromedia\Common\*.* >

< %SYSTEMDRIVE%\dir\*.* /s >

< %systemroot%\system32\ras\*.exe >

< %SYSTEMDRIVE%\MFILES\*.* >

< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >

< %systemroot%\system32\services\*.* >

< %systemroot%\Spooler\*.* >

< %ProgramFiles%\system32\*.* >

< %systemroot%\system32\Setup\*.dll /x >

< %systemroot%\system32\*.mine >

< %SYSTEMDRIVE%\cleansweep.exe\*.* >

< %systemroot%\system32\ras\*.dll >

< %systemroot%\system32\ras\*.drv >

< %systemroot%\*.iq >

< %systemroot%\system32\XP\*.* >

< %SYSTEMDRIVE%\Extracted\*.* >

< %systemroot%\system32\windows\*.* >

< %systemroot%\logs\*.* >

< %SYSTEMDRIVE%\Win.Msi\*.* >

< %systemroot%\regedit\*.* >

< %systemroot%\system32\skype\*.* >

< %AppData%\Adobe\dlluplwin25\*.* >

< %UserProfile%\*.dat >
[2010/10/01 14:17:07 | 009,699,328 | —- | M] () – C:\Documents and Settings\Vern McKinney\ntuser.dat

< %UserProfile%\*.dll >
[2006/05/30 23:01:09 | 000,229,376 | —- | M] () – C:\Documents and Settings\Vern McKinney\cwshredder.dll

< %systemroot%\system32\*.sxo >

< %SYSTEMDRIVE%\Gazma\*.* /s >

< %systemroot%\system32\spynet\*.* >

< %systemroot%\system32\System\*.* >

< %appdata%\Microsoft\Windows\*.* >

< %systemroot%\system32\WinDir\*.* >

< %systemroot%\_\*.* >

< %systemroot%\system32\windows32\*.* >

< %ProgramFiles%\win\*.* >

< %AppData%\Microsoft\CD Burning\*.* >

< %systemroot%\*.cab >

< %systemroot%\K.Backup\*.* >

< %ProgramFiles%\Massenger\*.* >

< %systemroot%\System32\*.doc >

< %systemroot%\Office12\*.* >

< %systemroot%\System32\Rundl32.exe\*.* >

< %ProgramFiles%\yahoo.net\*.* >

< %systemroot%\system32\*.igo >

< %systemroot%\*.rew >

< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2003/12/04 05:18:34 | 000,233,472 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzcfg09.exe
[2003/12/04 05:03:20 | 000,634,880 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzeng09.exe
[2006/03/02 18:49:14 | 000,069,632 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\HPZIPM12.EXE
[2003/12/04 05:27:46 | 000,323,584 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzpre09.exe
[2003/12/04 05:42:04 | 000,364,544 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzstc09.exe
[2003/12/04 05:10:38 | 000,163,840 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpzstw09.exe
[2003/12/04 05:44:34 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpztbu09.exe
[2003/12/04 05:35:58 | 000,430,080 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpztbx09.exe
[2003/12/04 05:44:34 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\hpztsb09.exe

< %USERPROFILE%\.COMMgr\*.* >

< %USERPROFILE%\Desktop\*.bat >

< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
[2010/04/25 15:32:13 | 000,043,008 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv
[2010/04/25 15:32:13 | 000,080,384 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\CosmicBelt.rpv
[2010/04/25 15:32:14 | 000,007,168 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\Fire.rpv
[2010/04/25 15:32:14 | 000,007,680 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\FreqBands.rpv
[2010/04/25 15:32:14 | 000,069,632 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\Nebula.rpv
[2005/06/23 20:34:51 | 000,000,168 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\viz.ini

< %PROGRAMFILES%\Internet Explorer\*.Jmp >

< %PROGRAMFILES%\Windows NT\system\*.dll >

< %systemroot%\system32\*.ext >

< %systemroot%\system32\Com\*.cfg >

< %systemroot%\system32\btz\*.* >

< %systemroot%\system32\EMP\*.* >

< %systemroot%\system32\expo\*.* >

< %systemroot%\system32\inet2\*.* >

< %systemroot%\system32\xrem\*.* >

< %ProgramFiles%\Microsoft\*.* >

< %systemroot%\usgwmt\*.* >

< %ProgramFiles%\B\*.* >

< %SYSTEMDRIVE%\lspp\*.* >

< %systemroot%\Kral\*.* >

< %SYSTEMDRIVE%\windowsdvd.exe\*.* >

< %systemroot%\system32\*.ipo >

< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >

< %systemroot%\system32\*.mof >

< %systemroot%\*.atm >

< %systemroot%\system32\svhost\*.* >

< %ProgramFiles%\system32\*.* >

< %ProgramFiles%\Docmentt\*.* >

< %systemroot%\Help\*.vbs >

< %ProgramFiles%\Windows WinSxs\*.* /s >

< %ProgramFiles%\Outlook Express\IDT\*.* /s >

< %ProgramFiles%\Microsoft Office\365\*.* /s >

< %ProgramFiles%\Windows Live\*.* >

< %systemroot%\system32\win32\*.* >

< %SYSTEMDRIVE%\RECYCLER\*.* >

< %systemroot%\Fresh1\*.* >

< %ProgramFiles%\Kekj\*.* /s >

< %systemroot%\GDU\*.* >

< %systemroot%\KA\*.* >

< %systemroot%\R\*.* >

< %systemroot%\system32\*.fyo >

< %USERPROFILE%\System\*.* >

< %systemroot%\Source\*.* >

< %systemroot%\system32\ac\*.* >

< %ProgramFiles%\MSDN\*.* >

< %AppData%\AdobeUM\winvcldll54\*.* /s >

< %ProgramFiles%\Internet Explorer\*.ico >

< %systemroot%\system32\*.ojo >

< %systemroot%\system32\d323s\*.* >

< %systemroot%\system32\re\*.* >

< %UserProfile%\Microsoft\*.dll >

< %UserProfile%\Microsoft\*.log >

< %systemroot%\Bios\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
Run OTL.exe by double clicking the icon on your desktop.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    [2006/01/16 01:13:18 | 000,023,847 | —- | C] () – C:\WINDOWS\stub14.ini
    [2006/01/15 07:13:37 | 000,025,035 | —- | C] () – C:\WINDOWS\stub41.ini
    [2006/01/15 07:13:37 | 000,024,667 | —- | C] () – C:\WINDOWS\stub50.ini
    [2006/01/03 22:51:43 | 000,022,742 | —- | C] () – C:\WINDOWS\stub91.ini
    [2006/01/03 22:51:08 | 000,025,728 | —- | C] () – C:\WINDOWS\stub90.ini
    [2006/01/03 22:35:28 | 000,025,441 | —- | C] () – C:\WINDOWS\stub89.ini
    [2006/01/03 22:34:26 | 000,025,543 | —- | C] () – C:\WINDOWS\stub88.ini
    [2006/01/03 22:30:11 | 000,025,695 | —- | C] () – C:\WINDOWS\stub87.ini
    [2006/01/03 22:30:09 | 000,025,438 | —- | C] () – C:\WINDOWS\stub86.ini
    [2006/01/02 23:54:39 | 000,025,197 | —- | C] () – C:\WINDOWS\stub85.ini
    [2006/01/02 23:52:42 | 000,025,684 | —- | C] () – C:\WINDOWS\stub84.ini
    [2006/01/02 23:51:26 | 000,026,118 | —- | C] () – C:\WINDOWS\stub83.ini
    [2006/01/02 23:50:52 | 000,025,882 | —- | C] () – C:\WINDOWS\stub82.ini
    [2006/01/02 23:49:30 | 000,026,444 | —- | C] () – C:\WINDOWS\stub81.ini
    [2006/01/02 23:48:14 | 000,025,840 | —- | C] () – C:\WINDOWS\stub80.ini
    [2006/01/02 23:44:42 | 000,025,314 | —- | C] () – C:\WINDOWS\stub79.ini
    [2006/01/02 23:44:16 | 000,025,812 | —- | C] () – C:\WINDOWS\stub78.ini
    [2006/01/02 23:43:51 | 000,025,329 | —- | C] () – C:\WINDOWS\stub77.ini
    [2006/01/02 23:42:56 | 000,026,785 | —- | C] () – C:\WINDOWS\stub76.ini
    [2006/01/02 23:42:32 | 000,026,386 | —- | C] () – C:\WINDOWS\stub75.ini
    [2006/01/02 23:42:18 | 000,026,446 | —- | C] () – C:\WINDOWS\stub74.ini
    [2006/01/02 23:41:17 | 000,026,417 | —- | C] () – C:\WINDOWS\stub73.ini
    [2006/01/02 23:40:57 | 000,026,300 | —- | C] () – C:\WINDOWS\stub72.ini
    [2006/01/02 23:40:25 | 000,026,413 | —- | C] () – C:\WINDOWS\stub71.ini
    [2006/01/02 23:39:36 | 000,025,626 | —- | C] () – C:\WINDOWS\stub70.ini
    [2006/01/02 23:39:11 | 000,025,949 | —- | C] () – C:\WINDOWS\stub69.ini
    [2006/01/02 23:37:46 | 000,026,241 | —- | C] () – C:\WINDOWS\stub67.ini
    [2006/01/02 23:36:24 | 000,026,472 | —- | C] () – C:\WINDOWS\stub66.ini
    [2006/01/02 15:02:42 | 000,024,410 | —- | C] () – C:\WINDOWS\stub31.ini
    [2006/01/02 15:02:42 | 000,022,711 | —- | C] () – C:\WINDOWS\stub2.ini
    [2006/01/01 23:27:05 | 000,026,174 | —- | C] () – C:\WINDOWS\stub65.ini
    [2006/01/01 22:54:32 | 000,024,912 | —- | C] () – C:\WINDOWS\stub64.ini
    [2006/01/01 22:38:50 | 000,025,074 | —- | C] () – C:\WINDOWS\stub63.ini
    [2006/01/01 22:38:16 | 000,025,293 | —- | C] () – C:\WINDOWS\stub62.ini
    [2006/01/01 22:34:30 | 000,025,066 | —- | C] () – C:\WINDOWS\stub61.ini
    [2006/01/01 06:36:49 | 000,024,565 | —- | C] () – C:\WINDOWS\stub27.ini
    [2005/12/31 23:11:39 | 000,025,594 | —- | C] () – C:\WINDOWS\stub60.ini
    [2005/12/31 23:11:26 | 000,025,271 | —- | C] () – C:\WINDOWS\stub59.ini
    [2005/12/31 23:11:11 | 000,026,307 | —- | C] () – C:\WINDOWS\stub58.ini
    [2005/12/31 23:10:59 | 000,025,008 | —- | C] () – C:\WINDOWS\stub57.ini
    [2005/12/31 23:10:20 | 000,025,293 | —- | C] () – C:\WINDOWS\stub55.ini
    [2005/12/31 23:09:40 | 000,025,311 | —- | C] () – C:\WINDOWS\stub54.ini
    [2005/12/31 23:09:20 | 000,025,635 | —- | C] () – C:\WINDOWS\stub53.ini
    [2005/12/31 23:09:07 | 000,025,546 | —- | C] () – C:\WINDOWS\stub52.ini
    [2005/12/31 23:08:50 | 000,025,592 | —- | C] () – C:\WINDOWS\stub51.ini
    [2005/12/31 23:06:55 | 000,024,795 | —- | C] () – C:\WINDOWS\stub49.ini
    [2005/12/31 22:58:54 | 000,024,921 | —- | C] () – C:\WINDOWS\stub47.ini
    [2005/12/31 22:58:30 | 000,025,352 | —- | C] () – C:\WINDOWS\stub46.ini
    [2005/12/31 22:58:13 | 000,024,766 | —- | C] () – C:\WINDOWS\stub45.ini
    [2005/12/31 22:57:57 | 000,024,710 | —- | C] () – C:\WINDOWS\stub44.ini
    [2005/12/31 22:57:48 | 000,025,043 | —- | C] () – C:\WINDOWS\stub43.ini
    [2005/12/31 22:57:24 | 000,024,914 | —- | C] () – C:\WINDOWS\stub42.ini
    [2005/12/31 22:56:49 | 000,024,703 | —- | C] () – C:\WINDOWS\stub40.ini
    [2005/12/31 22:54:59 | 000,024,420 | —- | C] () – C:\WINDOWS\stub39.ini
    [2005/12/31 22:50:21 | 000,024,711 | —- | C] () – C:\WINDOWS\stub38.ini
    [2005/12/31 22:49:58 | 000,024,442 | —- | C] () – C:\WINDOWS\stub37.ini
    [2005/12/31 06:56:46 | 000,024,305 | —- | C] () – C:\WINDOWS\stub35.ini
    [2005/12/31 06:56:28 | 000,024,912 | —- | C] () – C:\WINDOWS\stub34.ini
    [2005/12/31 06:56:01 | 000,024,391 | —- | C] () – C:\WINDOWS\stub33.ini
    [2005/12/31 06:54:49 | 000,024,809 | —- | C] () – C:\WINDOWS\stub30.ini
    [2005/12/31 06:54:16 | 000,024,364 | —- | C] () – C:\WINDOWS\stub29.ini
    [2005/12/31 06:54:01 | 000,024,101 | —- | C] () – C:\WINDOWS\stub28.ini
    [2005/12/31 06:53:11 | 000,023,818 | —- | C] () – C:\WINDOWS\stub26.ini
    [2005/12/31 06:52:53 | 000,023,904 | —- | C] () – C:\WINDOWS\stub25.ini
    [2005/12/31 06:52:41 | 000,023,580 | —- | C] () – C:\WINDOWS\stub24.ini
    [2005/12/31 06:52:24 | 000,024,085 | —- | C] () – C:\WINDOWS\stub23.ini
    [2005/12/31 06:52:06 | 000,023,060 | —- | C] () – C:\WINDOWS\stub22.ini
    [2005/12/31 06:51:20 | 000,023,219 | —- | C] () – C:\WINDOWS\stub21.ini
    [2005/12/31 06:50:55 | 000,023,685 | —- | C] () – C:\WINDOWS\stub20.ini
    [2005/12/31 06:50:45 | 000,022,835 | —- | C] () – C:\WINDOWS\stub19.ini
    [2005/12/31 06:50:30 | 000,022,118 | —- | C] () – C:\WINDOWS\stub18.ini
    [2005/12/31 06:48:51 | 000,023,395 | —- | C] () – C:\WINDOWS\stub17.ini
    [2005/12/31 06:48:29 | 000,023,622 | —- | C] () – C:\WINDOWS\stub16.ini
    [2005/12/31 06:48:02 | 000,023,264 | —- | C] () – C:\WINDOWS\stub15.ini
    [2005/12/31 06:25:39 | 000,023,745 | —- | C] () – C:\WINDOWS\stub13.ini
    [2005/12/31 06:25:14 | 000,023,567 | —- | C] () – C:\WINDOWS\stub12.ini
    [2005/12/31 06:17:39 | 000,023,501 | —- | C] () – C:\WINDOWS\stub11.ini
    [2005/12/31 06:12:33 | 000,023,416 | —- | C] () – C:\WINDOWS\stub10.ini
    [2005/12/31 06:11:41 | 000,023,496 | —- | C] () – C:\WINDOWS\stub9.ini
    [2005/12/29 23:44:51 | 000,023,318 | —- | C] () – C:\WINDOWS\stub8.ini
    [2005/12/29 23:42:15 | 000,023,344 | —- | C] () – C:\WINDOWS\stub7.ini
    [2005/12/29 23:41:23 | 000,023,619 | —- | C] () – C:\WINDOWS\stub6.ini
    [2005/12/29 23:40:29 | 000,023,500 | —- | C] () – C:\WINDOWS\stub5.ini
    [2005/12/29 23:29:43 | 000,023,246 | —- | C] () – C:\WINDOWS\stub4.ini
    [2005/12/29 23:22:39 | 000,023,166 | —- | C] () – C:\WINDOWS\stub3.ini
    [2005/12/26 04:34:50 | 000,025,914 | —- | C] () – C:\WINDOWS\stub68.ini
    [2005/12/26 04:34:50 | 000,025,158 | —- | C] () – C:\WINDOWS\stub56.ini
    [2005/12/22 13:35:45 | 000,024,735 | —- | C] () – C:\WINDOWS\stub36.ini
    [2005/12/22 13:14:17 | 000,024,864 | —- | C] () – C:\WINDOWS\stub48.ini
    [2005/12/18 12:32:22 | 000,024,500 | —- | C] () – C:\WINDOWS\stub32.ini
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the new OTL log


Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You should download the latest version from the Adobe website.
Here is the OTL Log after the scann. I will update Adobe after this! All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\WINDOWS\stub14.ini moved successfully. C:\WINDOWS\stub41.ini moved successfully. C:\WINDOWS\stub50.ini moved successfully. C:\WINDOWS\stub91.ini moved successfully. C:\WINDOWS\stub90.ini moved successfully. C:\WINDOWS\stub89.ini moved successfully. C:\WINDOWS\stub88.ini moved successfully. C:\WINDOWS\stub87.ini moved successfully. C:\WINDOWS\stub86.ini moved successfully. C:\WINDOWS\stub85.ini moved successfully. C:\WINDOWS\stub84.ini moved successfully. C:\WINDOWS\stub83.ini moved successfully. C:\WINDOWS\stub82.ini moved successfully. C:\WINDOWS\stub81.ini moved successfully. C:\WINDOWS\stub80.ini moved successfully. C:\WINDOWS\stub79.ini moved successfully. C:\WINDOWS\stub78.ini moved successfully. C:\WINDOWS\stub77.ini moved successfully. C:\WINDOWS\stub76.ini moved successfully. C:\WINDOWS\stub75.ini moved successfully. C:\WINDOWS\stub74.ini moved successfully. C:\WINDOWS\stub73.ini moved successfully. C:\WINDOWS\stub72.ini moved successfully. C:\WINDOWS\stub71.ini moved successfully. C:\WINDOWS\stub70.ini moved successfully. C:\WINDOWS\stub69.ini moved successfully. C:\WINDOWS\stub67.ini moved successfully. C:\WINDOWS\stub66.ini moved successfully. C:\WINDOWS\stub31.ini moved successfully. C:\WINDOWS\stub2.ini moved successfully. C:\WINDOWS\stub65.ini moved successfully. C:\WINDOWS\stub64.ini moved successfully. C:\WINDOWS\stub63.ini moved successfully. C:\WINDOWS\stub62.ini moved successfully. C:\WINDOWS\stub61.ini moved successfully. C:\WINDOWS\stub27.ini moved successfully. C:\WINDOWS\stub60.ini moved successfully. C:\WINDOWS\stub59.ini moved successfully. C:\WINDOWS\stub58.ini moved successfully. C:\WINDOWS\stub57.ini moved successfully. C:\WINDOWS\stub55.ini moved successfully. C:\WINDOWS\stub54.ini moved successfully. C:\WINDOWS\stub53.ini moved successfully. C:\WINDOWS\stub52.ini moved successfully. C:\WINDOWS\stub51.ini moved successfully. C:\WINDOWS\stub49.ini moved successfully. C:\WINDOWS\stub47.ini moved successfully. C:\WINDOWS\stub46.ini moved successfully. C:\WINDOWS\stub45.ini moved successfully. C:\WINDOWS\stub44.ini moved successfully. C:\WINDOWS\stub43.ini moved successfully. C:\WINDOWS\stub42.ini moved successfully. C:\WINDOWS\stub40.ini moved successfully. C:\WINDOWS\stub39.ini moved successfully. C:\WINDOWS\stub38.ini moved successfully. C:\WINDOWS\stub37.ini moved successfully. C:\WINDOWS\stub35.ini moved successfully. C:\WINDOWS\stub34.ini moved successfully. C:\WINDOWS\stub33.ini moved successfully. C:\WINDOWS\stub30.ini moved successfully. C:\WINDOWS\stub29.ini moved successfully. C:\WINDOWS\stub28.ini moved successfully. C:\WINDOWS\stub26.ini moved successfully. C:\WINDOWS\stub25.ini moved successfully. C:\WINDOWS\stub24.ini moved successfully. C:\WINDOWS\stub23.ini moved successfully. C:\WINDOWS\stub22.ini moved successfully. C:\WINDOWS\stub21.ini moved successfully. C:\WINDOWS\stub20.ini moved successfully. C:\WINDOWS\stub19.ini moved successfully. C:\WINDOWS\stub18.ini moved successfully. C:\WINDOWS\stub17.ini moved successfully. C:\WINDOWS\stub16.ini moved successfully. C:\WINDOWS\stub15.ini moved successfully. C:\WINDOWS\stub13.ini moved successfully. C:\WINDOWS\stub12.ini moved successfully. C:\WINDOWS\stub11.ini moved successfully. C:\WINDOWS\stub10.ini moved successfully. C:\WINDOWS\stub9.ini moved successfully. C:\WINDOWS\stub8.ini moved successfully. C:\WINDOWS\stub7.ini moved successfully. C:\WINDOWS\stub6.ini moved successfully. C:\WINDOWS\stub5.ini moved successfully. C:\WINDOWS\stub4.ini moved successfully. C:\WINDOWS\stub3.ini moved successfully. C:\WINDOWS\stub68.ini moved successfully. C:\WINDOWS\stub56.ini moved successfully. C:\WINDOWS\stub36.ini moved successfully. C:\WINDOWS\stub48.ini moved successfully. C:\WINDOWS\stub32.ini moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Vern McKinney ->Temp folder emptied: 398754 bytes ->Temporary Internet Files folder emptied: 2404918 bytes ->Flash cache emptied: 17882 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1770551 bytes %systemroot%\System32 .tmp files removed: 154129 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 1311207 bytes Total Files Cleaned = 6.00 mb [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: Vern McKinney ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point (0) OTL by OldTimer - Version 3.2.14.1 log created on 10022010_135626 Files\Folders moved on Reboot… Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI