OTL logs:
OTL Extras logfile created on: 7/28/2011 4:34:00 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\claYTON\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.25 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 61.12% Memory free
4.35 Gb Paging File | 3.41 Gb Available in Paging File | 78.50% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.93 Gb Total Space | 33.00 Gb Free Space | 59.00% Space Free | Partition Type: NTFS
Computer Name: ME | User Name: claYTON | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{1C523473-52A7-4548-9EA4-AEFBE085B407}" = Belkin Wireless Utility
"{1E99F5D7-4262-4C7C-9135-F066E7485811}" = System Requirements Lab
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{556A649F-72D2-4E41-A40C-794E0277AADB}" = System Requirements Lab CYRI
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Chuzzle Deluxe1.0" = Chuzzle Deluxe
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"InstallShield_{1C523473-52A7-4548-9EA4-AEFBE085B407}" = Belkin Wireless Utility
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 5.0 (x86 en-US)" = Mozilla Firefox 5.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton Security Suite
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Peggle Nights Deluxe 1.0" = Peggle Nights Deluxe 1.0
"Security Task Manager" = Security Task Manager 1.7h
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.4
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/28/2011 4:12:59 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 7/28/2011 4:12:59 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 7/28/2011 4:20:17 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 7/28/2011 4:20:17 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 7/28/2011 4:23:20 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 7/28/2011 4:23:20 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 7/28/2011 4:30:15 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 7/28/2011 4:30:15 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 7/28/2011 4:30:17 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 7/28/2011 4:30:17 PM | Computer Name = ME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
[ System Events ]
Error - 7/27/2011 4:40:20 PM | Computer Name = ME | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%3
Error - 7/27/2011 4:40:20 PM | Computer Name = ME | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060
Error - 7/27/2011 4:40:27 PM | Computer Name = ME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RecAgent
Error - 7/28/2011 8:22:44 AM | Computer Name = ME | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%3
Error - 7/28/2011 8:22:44 AM | Computer Name = ME | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060
Error - 7/28/2011 8:23:03 AM | Computer Name = ME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RecAgent
Error - 7/28/2011 3:53:25 PM | Computer Name = ME | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%3
Error - 7/28/2011 3:53:25 PM | Computer Name = ME | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060
Error - 7/28/2011 3:53:31 PM | Computer Name = ME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RecAgent
Error - 7/28/2011 3:56:06 PM | Computer Name = ME | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 00000008, parameter2 00000002, parameter3
00000000, parameter4 804ee25b.
< End of report >
OTL logfile created on: 7/28/2011 4:34:00 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\claYTON\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.25 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 61.12% Memory free
4.35 Gb Paging File | 3.41 Gb Available in Paging File | 78.50% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.93 Gb Total Space | 33.00 Gb Free Space | 59.00% Space Free | Partition Type: NTFS
Computer Name: ME | User Name: claYTON | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\claYTON\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\ALCFDRTM.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\claYTON\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
MOD - C:\Program Files\AlienGUIse\wbhelp.dll (Stardock.Net, Inc)
========== Win32 Services (SafeList) ==========
SRV - (WebrootSpySweeperService) – File not found
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (SLService) – C:\WINDOWS\System32\slserv.exe (Smart Link)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
========== Driver Services (SafeList) ==========
DRV - (MpKsl7cd9d7c0) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{44F941E4-A4A7-4271-AE98-69F17571FC2A}\MpKsl7cd9d7c0.sys (Microsoft Corporation)
DRV - (MpKslbdf09487) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{44F941E4-A4A7-4271-AE98-69F17571FC2A}\MpKslbdf09487.sys (Microsoft Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110723.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110727.030\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110728.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110728.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (SSHRMD) – C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSFS0509) – C:\WINDOWS\SYSTEM32\Drivers\SSFS0509.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSIDRV) – C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software Inc (www.webroot.com))
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (BLKWGN) – C:\WINDOWS\system32\drivers\BLKWGN.sys (Belkin Corporation.)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\InCDfs.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDpass.sys (Nero AG)
DRV - (incdrm) – C:\WINDOWS\System32\drivers\InCDrm.sys (Nero AG)
DRV - (W8335XP) NETGEAR WG511v2 54 Mbps Wireless PC Card for Windows XP (8335) – C:\WINDOWS\system32\drivers\WG511v2XP.sys (Marvell Semiconductor, Inc)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (wlanndi5) – C:\WINDOWS\system32\wlanndi5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (vncdrv) – C:\WINDOWS\system32\drivers\vncdrv.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4E EE DD 77 11 04 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "
http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..keyword.URL: "
http://websearch.ask.com/redirect?client=ff&src;=kw&tb;=X-SD&o;=13959&locale;=en_US&apn;_uid=6e0df002-3359-469a-a96e-6ea201440cbe&apn;_ptnrs=SV&apn;_sauid=12A56375-E964-44A9-89C2-73E7F69A6C68&apn;_dtid=YYYYYYYYUS&q;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/07/20 09:52:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn_2010_9_0_6 [2011/07/28 15:53:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/15 10:44:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/15 10:44:44 | 000,000,000 | —D | M]
[2009/07/15 00:33:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\claYTON\Application Data\Mozilla\Extensions
[2011/07/28 15:59:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\claYTON\Application Data\Mozilla\Firefox\Profiles\j63ktbyn.default\extensions
[2010/06/27 08:21:49 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\claYTON\Application Data\Mozilla\Firefox\Profiles\j63ktbyn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/22 12:16:19 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\claYTON\Application Data\Mozilla\Firefox\Profiles\j63ktbyn.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/06/22 12:16:24 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\claYTON\Application Data\Mozilla\Firefox\Profiles\j63ktbyn.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/07/28 16:00:34 | 000,000,000 | —D | M] (Support.com Toolbar) – C:\Documents and Settings\claYTON\Application Data\Mozilla\Firefox\Profiles\j63ktbyn.default\extensions\[removed]
[2011/07/28 16:00:54 | 000,002,568 | —- | M] () – C:\Documents and Settings\claYTON\Application Data\Mozilla\Firefox\Profiles\j63ktbyn.default\searchplugins\askcom.xml
[2011/07/03 20:25:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/27 08:58:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/27 21:37:18 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) –
[2011/07/28 15:53:12 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN_2010_9_0_6
[2011/07/20 09:52:38 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
() (No name found) – C:\DOCUMENTS AND SETTINGS\CLAYTON\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\J63KTBYN.DEFAULT\EXTENSIONS\[removed]
[2010/06/27 08:58:05 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/16 00:17:34 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2007/01/31 18:57:55 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [DivX Download Manager] File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1247511599656 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303}
http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab (MSN Games – Texas Holdem Poker)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab (HGPlugin9USA Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\System32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - C:\WINDOWS\System32\WRLogonNtf.dll (Webroot Software, Inc.)
O24 - Desktop Components:0 () -
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\claYTON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\claYTON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/21 20:43:19 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/07/28 16:27:25 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\claYTON\Desktop\OTL.exe
[2011/07/28 15:16:38 | 001,915,904 | —- | C] (AVAST Software) – C:\Documents and Settings\claYTON\Desktop\aswMBR.exe
[2011/07/28 13:50:28 | 000,000,000 | —D | C] – C:\Documents and Settings\claYTON\Start Menu\Programs\HiJackThis
[2011/07/28 13:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
[2011/07/28 13:37:11 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/07/28 13:36:36 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\claYTON\Desktop\HJTInstall.exe
[2011/07/28 12:49:40 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/07/28 11:57:20 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/07/28 11:28:55 | 013,063,352 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\claYTON\Desktop\MICROSOFT SECURITY ESSENTIALS.exe
[2011/07/28 11:14:38 | 000,000,000 | —D | C] – C:\Documents and Settings\claYTON\Local Settings\Application Data\AskToolbar
[2011/07/28 11:14:10 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2011/07/28 11:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\claYTON\Application Data\Sammsoft
[2011/07/07 15:58:25 | 000,000,000 | —D | C] – C:\Documents and Settings\claYTON\Start Menu\Programs\Accessories
[2011/07/07 15:31:46 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/07/07 15:12:35 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/07/07 15:11:05 | 000,000,000 | RH-D | C] – C:\Documents and Settings\claYTON\Recent
[2011/07/03 22:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\claYTON\Desktop\Burning Heads - Album Discography (2010)
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/28 16:38:00 | 000,000,390 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/07/28 16:27:44 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\claYTON\Desktop\OTL.exe
[2011/07/28 16:26:46 | 000,000,499 | —- | M] () – C:\Documents and Settings\claYTON\Desktop\MBR.zip
[2011/07/28 16:26:18 | 000,000,512 | —- | M] () – C:\Documents and Settings\claYTON\Desktop\MBR.dat
[2011/07/28 16:01:12 | 000,000,238 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/07/28 16:00:59 | 000,001,940 | —- | M] () – C:\Documents and Settings\claYTON\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/07/28 16:00:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/07/28 15:54:06 | 000,050,868 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/07/28 15:53:51 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/28 15:52:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/28 15:19:33 | 001,915,904 | —- | M] (AVAST Software) – C:\Documents and Settings\claYTON\Desktop\aswMBR.exe
[2011/07/28 15:02:57 | 093,323,264 | —- | M] () – C:\Documents and Settings\claYTON\Desktop\747_Lara.wmv
[2011/07/28 13:50:29 | 000,001,988 | —- | M] () – C:\Documents and Settings\claYTON\Desktop\HiJackThis.lnk
[2011/07/28 13:49:28 | 001,402,880 | —- | M] () – C:\Documents and Settings\claYTON\Desktop\HiJackThis.msi
[2011/07/28 13:36:42 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\claYTON\Desktop\HJTInstall.exe
[2011/07/28 12:52:21 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/07/28 11:28:55 | 013,063,352 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\claYTON\Desktop\MICROSOFT SECURITY ESSENTIALS.exe
[2011/07/19 20:12:49 | 000,233,576 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/16 14:43:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/16 14:37:40 | 000,092,672 | —- | M] () – C:\Documents and Settings\claYTON\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/15 08:45:29 | 000,446,386 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/15 08:45:29 | 000,073,426 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/07 15:58:32 | 000,000,815 | —- | M] () – C:\Documents and Settings\claYTON\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/03 20:26:01 | 000,000,742 | —- | M] () – C:\Documents and Settings\claYTON\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/07/03 20:26:01 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/28 16:26:46 | 000,000,499 | —- | C] () – C:\Documents and Settings\claYTON\Desktop\MBR.zip
[2011/07/28 16:26:18 | 000,000,512 | —- | C] () – C:\Documents and Settings\claYTON\Desktop\MBR.dat
[2011/07/28 13:48:46 | 001,402,880 | —- | C] () – C:\Documents and Settings\claYTON\Desktop\HiJackThis.msi
[2011/07/28 13:37:13 | 000,001,988 | —- | C] () – C:\Documents and Settings\claYTON\Desktop\HiJackThis.lnk
[2011/07/28 13:34:14 | 093,323,264 | —- | C] () – C:\Documents and Settings\claYTON\Desktop\747_Lara.wmv
[2011/07/28 12:57:04 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/07/28 12:56:40 | 000,000,390 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/07/28 12:52:21 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/07/28 11:48:09 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/07/28 11:14:36 | 000,000,238 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/07/15 08:21:09 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/07/07 15:58:30 | 000,000,815 | —- | C] () – C:\Documents and Settings\claYTON\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/07 15:58:27 | 000,000,803 | —- | C] () – C:\Documents and Settings\claYTON\Start Menu\Programs\Internet Explorer.lnk
[2011/07/07 15:40:20 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/05/12 15:16:23 | 000,001,940 | —- | C] () – C:\Documents and Settings\claYTON\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/01/31 22:37:12 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/10/17 11:08:50 | 000,000,551 | —- | C] () – C:\Documents and Settings\claYTON\Application Data\AutoGK.ini
[2010/10/17 10:49:17 | 000,043,602 | —- | C] () – C:\WINDOWS\System32\xvid-uninstall.exe
[2010/09/23 10:55:47 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2010/09/23 10:55:47 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2010/09/23 10:55:47 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2010/09/23 10:55:45 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2010/09/23 10:55:45 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2010/09/23 10:55:45 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2010/09/23 10:55:45 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2010/09/23 10:55:45 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2010/09/23 10:55:45 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2010/09/10 17:51:33 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2010/09/04 16:51:52 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/07/20 15:53:05 | 000,000,039 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/01/13 18:24:07 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\bassmod.dll
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/09/07 20:30:38 | 001,597,690 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/09/03 17:55:48 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/09/03 17:42:03 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/09/02 21:35:25 | 003,412,000 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009/09/02 21:35:25 | 000,679,968 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox2.dat
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/07/16 18:48:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\RTCOMDLL.dll
[2009/07/16 18:48:26 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2009/07/16 18:45:57 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2009/07/14 20:00:20 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2009/07/13 14:47:10 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2007/07/03 13:18:31 | 000,092,672 | —- | C] () – C:\Documents and Settings\claYTON\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/09 14:38:51 | 000,000,017 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2007/02/02 21:20:39 | 000,000,050 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2007/02/01 13:04:01 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/01/31 21:57:06 | 000,000,067 | —- | C] () – C:\WINDOWS\vmreg32.dll
[2006/12/08 08:50:14 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/12/08 08:47:54 | 001,159,168 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/10/08 13:51:19 | 000,020,992 | —- | C] () – C:\WINDOWS\System32\wrlzma.dll
[2006/10/07 18:55:22 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/07/31 21:18:08 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/07/31 21:17:58 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/04/07 20:39:32 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/04/07 20:38:05 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/04/06 20:49:28 | 000,000,000 | —- | C] () – C:\WINDOWS\win32104-166131713.exe
[2006/04/06 20:03:29 | 000,000,045 | —- | C] () – C:\WINDOWS\jptc.dat
[2006/04/06 20:03:14 | 001,490,945 | —- | C] () – C:\Documents and Settings\claYTON\Application Data\Install.dat
[2006/04/06 20:03:11 | 000,000,000 | —- | C] () – C:\WINDOWS\keyboard91.dat
[2006/03/29 10:22:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/29 08:53:57 | 000,000,104 | —- | C] () – C:\WINDOWS\wb.ini
[2005/06/21 22:22:23 | 000,002,340 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/06/21 20:45:51 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/06/21 20:40:23 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/06/21 13:31:05 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/21 13:29:48 | 000,233,576 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/05/05 03:53:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2005/05/05 03:40:40 | 000,192,512 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2004/08/04 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,446,386 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,073,426 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/17 21:02:16 | 000,651,264 | R— | C] () – C:\WINDOWS\System32\libeay32.dll
[2003/07/17 21:02:16 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\ssleay32.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/02/07 10:29:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/02/07 10:27:14 | 000,004,742 | —- | C] () – C:\WINDOWS\System32\oembios.dat
========== LOP Check ==========
[2011/06/21 13:02:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BioWare
[2009/09/02 20:27:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2009/07/16 14:32:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/08/13 20:27:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2009/08/18 00:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/18 09:24:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/09/03 16:26:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedBit
[2010/03/31 10:33:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/03 21:28:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/01/24 21:52:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/03 21:26:50 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/07/12 18:08:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/04/07 20:45:22 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\acccore
[2008/12/23 15:40:29 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Aim
[2010/02/21 19:58:59 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Bioshock2
[2010/03/14 15:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Boomzap
[2009/11/17 13:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\GetRightToGo
[2011/01/04 11:52:51 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Local
[2006/04/06 23:02:31 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\MSNInstaller
[2011/07/28 11:47:07 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Sammsoft
[2011/01/04 11:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\SystemRequirementsLab
[2009/09/03 21:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\TuneUp Software
[2010/01/05 20:41:07 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Uniblue
[2009/07/13 19:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\Windows Search
[2011/06/16 20:12:25 | 000,000,000 | —D | M] – C:\Documents and Settings\claYTON\Application Data\YoudaGames
[2011/07/28 16:00:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/07/28 16:40:57 | 000,000,390 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2011/07/28 16:01:12 | 000,000,238 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/06/21 20:43:19 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/02/01 13:45:25 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/09/19 11:11:23 | 000,000,151 | —- | M] () – C:\ClientRegistry.blob
[2005/06/21 20:43:19 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/02/10 18:59:10 | 000,011,922 | —- | M] () – C:\debug.txt
[2009/12/20 22:34:56 | 000,000,752 | —- | M] () – C:\dns_.log
[2006/04/06 20:04:18 | 000,000,000 | —- | M] () – C:\exit
[2009/07/10 13:39:00 | 000,350,720 | —- | M] () – C:\hjsplit.exe
[2005/06/21 20:43:19 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/04/07 20:48:27 | 000,000,431 | -H– | M] () – C:\IPH.PH
[2006/04/06 18:28:18 | 000,000,224 | —- | M] () – C:\Lan.log
[2005/06/21 20:43:19 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/07/11 17:35:33 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/28 15:51:29 | 2413,993,984 | -HS- | M] () – C:\pagefile.sys
[2010/06/29 21:11:41 | 000,000,719 | —- | M] () – C:\Shortcut to Downloads.lnk
[2006/04/12 21:36:40 | 000,004,903 | —- | M] () – C:\sz.xml
[2010/01/17 10:50:11 | 012,701,964 | —- | M] () – C:\TsimFuckis AKA Chick3n Little #22.wav
[2006/04/06 20:03:04 | 000,000,000 | —- | M] () – C:\uniq
[2010/01/20 21:07:44 | 015,826,188 | —- | M] () – C:\video.wav
< %systemroot%\Fonts\*.com >
[2006/04/18 18:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 17:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 18:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 17:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/06/21 20:42:48 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2003/08/06 16:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware logo_slvr.jpg
[2003/08/06 16:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware_logo_slvr.jpg
[2004/07/10 22:37:00 | 000,479,385 | —- | M] () – C:\WINDOWS\ALX_1600x1200.jpg
[2004/07/10 22:37:00 | 000,325,841 | —- | M] () – C:\WINDOWS\AW_1600x1200.jpg
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2009/09/04 09:23:39 | 000,001,834 | -H– | M] () – C:\Documents and Settings\claYTON\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/06/21 13:29:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/06/21 13:29:12 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/06/21 13:29:12 | 000,888,832 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2011/01/24 18:35:49 | 000,001,486 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Calculator.lnk
[2009/07/11 17:43:04 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/07/11 17:43:04 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2005/06/21 20:43:27 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2011/07/16 09:24:38 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-27 21:00:24
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2011/07/28 15:53:33 | 000,064,974 | —- | M] () MD5=C64014780F55710B078B0B9AA1FE33B6 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SCF >
[2004/08/04 08:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/04 08:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\internet explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/04 08:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\internet explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\internet explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2011/07/28 11:22:03 | 000,088,774 | —- | M] () MD5=5E56C428D8F9E6B2008EE6C186A827AB – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 08:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EXE >
[2004/08/04 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 4564 bytes -> C:\WINDOWS\Alien.bmp:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware_logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D74B6CF5
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >