Recently, when I started my PC
1) My windows firewall icon shows "turn off", and it reverts back to normal after 30 seconds or so after i have started up my computer (i have already set the settings to "on" on the windows firewall page)
2) My screen freezes sometimes, i'm not too sure if its hardware issue or virus
3) even my mozilla browser freezes and hangs (this happens quite frequently now)
4) I am using a wireless USB adaptor to connect to the internet, it has been working fine all the while, but recently, it doesn't connect automatically to the internet and i have to manually right click on the icon and select "repair" every single time to connect to the Internet.
5) I have the "windows update icon" located at my taskbar and even though i try to install the updates, the icon is always there when i turn on my PC
Did a Norton scan and all are fine.
Have downloaded OTL and attached are the findings… appreciate your kind advise!
Thanks
OTL.TXT
OTL logfile created on: 4/11/2011 8:38:16 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 151.00 Mb Available Physical Memory | 30.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 24.07 Gb Free Space | 61.63% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 23.75 Gb Free Space | 63.74% Space Free | Partition Type: NTFS
Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\user\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\user\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110410.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110410.002\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110408.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110225.002\BHDrvx86.sys (Symantec Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (SMCWGU(SMC)) SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) – C:\WINDOWS\system32\drivers\SMCWGU.sys (SMC Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC52) Intel® – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://sg.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/01/08 13:34:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 10:43:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 10:43:32 | 000,000,000 | —D | M]
[2010/06/23 19:14:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions
[2010/12/12 08:39:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/30 23:22:13 | 000,002,567 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\searchplugins\askcom.xml
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/24 21:04:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/19 16:51:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/01/08 13:34:21 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPLGN
[2010/12/19 16:50:56 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/12/19 16:50:55 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WINDVDPatch] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SMCWUSB-G 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/30 14:18:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ctmp3 - C:\WINDOWS\system32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/30 23:19:43 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\AskToolbar
[2011/03/30 23:18:09 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2011/03/30 23:17:38 | 000,000,000 | —D | C] – C:\Program Files\DsNET Corp
[2011/03/30 07:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\SelfMV
[2011/03/30 07:43:45 | 000,000,000 | —D | C] – C:\Program Files\MyFree Codec
[2011/03/28 18:01:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Samsung
[2011/03/28 18:00:01 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\WINDOWS\System32\dgderapi.dll
[2011/03/28 18:00:01 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\DIFxAPI.dll
[2011/03/28 18:00:01 | 000,020,032 | —- | C] (Devguru Co., Ltd) – C:\WINDOWS\System32\drivers\dgderdrv.sys
[2011/03/28 17:34:04 | 000,163,840 | —- | C] (CANON INC.) – C:\WINDOWS\BJPSUNST.EXE
[2011/03/28 17:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CD-LabelPrint
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\WINDOWS\StartHtmico
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200 Manual
[2011/03/28 17:29:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200
[2011/03/28 17:29:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/03/28 15:26:35 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2011/03/28 15:17:20 | 000,140,288 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM78.DLL
[2011/03/28 15:17:15 | 000,090,112 | R— | C] (CANON INC.) – C:\WINDOWS\System32\CNMCP78.exe
[2011/03/25 00:52:28 | 000,000,000 | —D | C] – C:\Temp
[2011/03/23 20:32:32 | 000,000,000 | —D | C] – C:\WINDOWS\System32\System32
[2011/03/22 23:04:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Samsung
[2011/03/22 23:03:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\samsung
[2011/03/22 01:26:13 | 000,136,680 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdm.sys
[2011/03/22 01:26:13 | 000,012,776 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdfl.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcmnt.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcm.sys
[2011/03/22 01:26:11 | 000,121,192 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadbus.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwhnt.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwh.sys
[2011/03/22 01:23:21 | 004,659,712 | —- | C] (Dmitry Streblechenko) – C:\WINDOWS\System32\Redemption.dll
[2011/03/22 01:21:57 | 000,000,000 | —D | C] – C:\Program Files\MarkAny
[2011/03/22 01:18:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Program Files\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/03/22 01:16:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2011/03/22 01:16:09 | 000,016,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/03/22 01:14:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\umdf
[2011/03/22 01:09:33 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Downloaded Installations
[2007/02/20 13:16:14 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/11 20:26:39 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/11 20:26:36 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.CDF
[2011/04/11 20:26:36 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.BAK
[2011/04/11 20:26:26 | 000,081,191 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/11 20:26:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/11 20:25:56 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2011/04/11 07:34:53 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/04/11 07:34:53 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/04/11 07:34:53 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/11 07:34:53 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/09 14:01:09 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/04/07 21:46:04 | 001,562,228 | —- | M] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/04/05 07:57:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/05 07:49:14 | 000,025,088 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 23:19:20 | 000,000,839 | —- | M] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/29 22:15:00 | 000,170,722 | —- | M] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:18 | 000,001,612 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/25 00:51:22 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/22 23:03:29 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/03/22 01:16:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/22 01:16:20 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | M] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/07 21:46:04 | 001,562,228 | —- | C] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/03/30 23:19:20 | 000,000,839 | —- | C] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/30 23:18:19 | 000,000,232 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/03/29 22:15:00 | 000,170,722 | —- | C] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:17 | 000,001,612 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/28 15:17:20 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2011/03/25 00:51:22 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/23 07:43:36 | 000,240,160 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/22 01:16:20 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | C] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[2011/01/29 17:00:24 | 000,030,568 | —- | C] () – C:\WINDOWS\MusiccityDownload.exe
[2011/01/29 17:00:22 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2011/01/29 17:00:22 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/29 17:00:22 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/29 17:00:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/01 03:13:12 | 008,596,886 | —- | C] () – C:\Documents and Settings\user\Application Data\Black Eyed Peas - The Time (Dirty Bit).zip
[2010/11/14 18:23:30 | 007,198,459 | —- | C] () – C:\Documents and Settings\user\Application Data\Kesha - We R Who We R.zip
[2010/10/21 19:16:51 | 000,001,940 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/21 07:41:34 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/03 00:51:48 | 000,016,384 | —- | C] () – C:\Documents and Settings\user\Application Data\tc7.exe
[2010/09/04 00:54:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/23 19:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/05/19 19:18:06 | 000,016,384 | —- | C] () – C:\Documents and Settings\user\Application Data\nn8.exe
[2009/10/06 15:16:00 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/16 09:26:11 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/04 20:02:08 | 000,025,088 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/09 19:25:59 | 000,000,398 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2008/06/07 15:04:14 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/06/07 15:04:14 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/06/07 15:04:07 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/07 15:04:05 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/06/07 15:04:03 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/06/07 15:03:46 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/06/07 15:03:46 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2008/06/07 15:03:41 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/04/25 20:22:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:17:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2007/02/20 13:17:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2007/02/20 13:16:44 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2007/02/20 13:16:44 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/02/20 13:16:35 | 000,164,044 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2007/02/20 13:16:35 | 000,113,373 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2007/02/20 13:16:35 | 000,113,273 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2007/02/20 13:16:33 | 000,179,669 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2007/02/20 13:16:33 | 000,044,055 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2007/02/20 13:16:22 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2007/02/20 13:16:22 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2007/02/20 13:16:20 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2007/02/20 13:16:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2007/02/20 12:35:52 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/03/20 23:36:32 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/30 22:09:29 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/30 22:08:17 | 000,134,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/30 14:43:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/30 14:38:37 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/11/30 14:38:37 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/30 14:38:36 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/30 14:21:25 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/11/30 14:15:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2004/08/04 20:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 20:00:00 | 000,432,686 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 20:00:00 | 000,067,516 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 20:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 20:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 20:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/03/14 12:24:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ZyDelReg.exe
[1999/01/23 02:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2011/03/28 17:29:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/06/27 10:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/12/23 11:09:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLive
[2011/03/28 17:56:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2010/11/08 21:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Thomson Reuters
[2010/07/03 19:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/02/20 21:02:15 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ICAClient
[2008/11/09 19:26:04 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\NJStar
[2011/03/28 17:55:55 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Samsung
[2006/10/20 20:27:46 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sports Interactive
[2006/09/17 17:18:52 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Teleca
[2010/11/04 19:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Tific
[2011/04/05 00:48:57 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\uTorrent
[2011/04/09 14:01:09 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/11/30 14:18:49 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/11/30 14:12:58 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/12/18 15:29:25 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/11/30 14:18:49 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/04/11 20:25:56 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2005/11/30 14:18:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/11/30 14:18:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 20:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/04/11 20:25:55 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2005/11/30 14:27:04 | 000,000,090 | —- | M] () – C:\setup.log
[2009/07/30 20:04:54 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/08/14 07:12:25 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/08/14 07:26:47 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/08/14 20:05:58 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/08/14 21:40:59 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/08/14 22:28:32 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/08/16 09:26:37 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/08/16 10:06:08 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/08/16 18:07:34 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/08/17 22:16:39 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/08/18 13:07:12 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/08/18 14:13:20 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/08/19 07:16:38 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/08/20 13:56:16 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/09/03 21:00:07 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/07/14 07:43:03 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/07/14 20:46:22 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/07/29 07:42:37 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/07/30 00:33:31 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/07/30 07:40:29 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/07/30 20:04:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/08/14 07:12:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/08/14 07:26:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/08/14 20:05:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/08/14 21:40:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/08/14 22:28:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/08/16 09:26:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/08/16 10:06:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/08/16 18:07:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/08/17 22:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/08/18 13:07:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/08/18 14:13:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/08/19 07:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/08/20 13:56:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/09/03 21:00:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/07/14 07:43:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/07/14 20:46:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/07/29 07:42:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/07/30 00:33:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/07/30 07:40:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/11/30 14:18:14 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 13:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2005/08/26 13:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/11/30 22:07:31 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/11/30 22:07:31 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/11/30 22:07:31 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/11/30 14:18:56 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2007/02/20 13:17:53 | 000,000,180 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Free AOL & Unlimited Internet.url
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/30 14:23:35 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/11/30 14:23:34 | 000,000,079 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/12/21 20:03:51 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\user\Desktop\erunt-setup.exe
[2008/05/11 20:41:46 | 002,963,912 | —- | M] (Macrovision Corporation) – C:\Documents and Settings\user\Desktop\ijjiAutoInstaller.exe
[2008/11/09 19:25:17 | 006,212,784 | —- | M] (NJStar Software Corp.) – C:\Documents and Settings\user\Desktop\njcom273sw8618.exe
[2010/12/18 12:29:37 | 000,296,448 | —- | M] () – C:\Documents and Settings\user\Desktop\uj7y5il6.exe
[2008/12/28 21:18:59 | 001,234,120 | —- | M] () – C:\Documents and Settings\user\Desktop\wrar380.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-10 23:34:07
< End of report >