Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.15.04
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: YOUR-3B54ED6EDD [administrator]
Protection: Disabled
1/15/2012 8:58:51 PM
mbam-log-2012-01-15 (20-58-51).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 181703
Time elapsed: 23 minute(s), 9 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\11\2ec8364b-436705c6 multiple threats
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\18\7845b2d2-5e5350d0 a variant of Java/TrojanDownloader.Agent.NAN trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\19\79571f53-3f0364f1 probably a variant of Win32/Agent.DYXWUMY trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\2\1f3f8202-784112ea a variant of Java/TrojanDownloader.Agent.NAN trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\24\4ec49a58-4b618d31 Java/Agent.BV trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\40\1fd53268-66b1d6ee probably a variant of Win32/Agent.DYXWUMY trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\5\1eedf745-5f872c94 multiple threats
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\54\2cd50f76-1e2b97a5 Java/Agent.BV trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\6\5b3d5486-54d68b57 a variant of Java/TrojanDownloader.Agent.NAN trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\60\5c2bd6bc-51e7045d probably a variant of Win32/Agent.FQRCZBA trojan
C:\Qoobox\Quarantine\C\WINNT\system32\egNWwGgh.ini.vir Win32/Adware.Virtumonde.NEO application
C:\Qoobox\Quarantine\C\WINNT\system32\MSCJRqss.ini.vir Win32/Adware.Virtumonde.NEO application
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001257.LNK LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001258.LNK LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001259.LNK LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001260.lnk LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001261.lnk LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001262.lnk LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001683.ini Win32/Adware.Virtumonde.NEO application
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001684.ini Win32/Adware.Virtumonde.NEO application
OTL logfile created on: 1/16/2012 1:03:03 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.73 Mb Total Physical Memory | 452.42 Mb Available Physical Memory | 44.59% Memory free
1.88 Gb Paging File | 1.50 Gb Available in Paging File | 80.01% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 20.28 Gb Free Space | 54.42% Space Free | Partition Type: NTFS
Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\desktop\OTL.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINNT\explorer.exe
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINNT\wanmpsvc.exe
========== Modules (No Company Name) ==========
MOD - [2010/03/15 10:28:22 | 000,141,824 | —- | M] () – C:\Program Files\RarExt.dll
MOD - [2008/04/13 18:11:59 | 000,014,336 | —- | M] () – C:\WINNT\system32\msdmo.dll
MOD - [2008/04/13 18:11:51 | 000,059,904 | —- | M] () – C:\WINNT\system32\devenum.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (wuauserv)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - File not found [Disabled | Stopped] – – (AOLService)
SRV - File not found [Disabled | Stopped] – – (AOL ACS)
SRV - File not found [Disabled | Stopped] – – (ACDaemon)
SRV - File not found [Disabled | Stopped] – – (aawservice)
SRV - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/11/29 21:24:28 | 000,603,904 | —- | M] (TuneUp Software) [Disabled | Stopped] – C:\WINNT\system32\TUProgSt.exe – (TuneUp.ProgramStatisticsSvc)
SRV - [2009/01/27 12:26:42 | 000,398,336 | —- | M] (Ares Development Group) [On_Demand | Stopped] – C:\Program Files\Ares\chatServer.exe – (AresChatServer)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [On_Demand | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [On_Demand | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2004/10/15 16:24:42 | 000,206,048 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINNT\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
========== Driver Services (SafeList) ==========
DRV - [2012/01/14 14:51:13 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39F5D8B1-72A1-4F15-8F75-9BA4F51AD7B5}\MpKslaf23d29b.sys – (MpKslaf23d29b)
DRV - [2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINNT\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2010/05/20 14:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/03/15 20:28:27 | 000,095,024 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WINNT\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2010/02/11 06:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINNT\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2007/10/11 05:20:56 | 000,000,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\atwpkt2.sys – (ATWPKT2)
DRV - [2007/10/02 16:45:04 | 004,109,376 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\alcxwdm.sys – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:41:39 | 000,013,776 | —- | M] (Smart Link) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\recagent.sys – (RecAgent)
DRV - [2004/05/13 18:01:23 | 000,028,352 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\System32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2003/05/20 12:23:10 | 000,210,592 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\mtlmnt5.sys – (Mtlmnt5)
DRV - [2003/05/20 12:21:44 | 001,295,472 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\mtlstrm.sys – (Mtlstrm)
DRV - [2003/05/20 12:19:24 | 000,085,688 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\slnthal.sys – (SlNtHal)
DRV - [2003/05/19 14:30:02 | 000,169,120 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\ntmtlfax.sys – (NtMtlFax)
DRV - [2003/05/13 09:58:34 | 000,521,408 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slntamr.sys – (Slntamr)
DRV - [2003/01/16 23:19:32 | 000,039,348 | —- | M] (Vireo Software) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slwdmsup.sys – (SlWdmSup)
DRV - [2003/01/10 16:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/09/10 05:06:00 | 000,025,244 | —- | M] (Adaptec) [Kernel | Auto | Running] – C:\WINNT\System32\drivers\aspi32.sys – (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 59636
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINNT\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/14 18:45:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/10 23:21:23 | 000,000,000 | —D | M]
[2008/07/02 13:47:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/05 22:54:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions
[2011/11/12 20:09:02 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/03/12 14:01:35 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/01/13 12:01:00 | 000,000,000 | —D | M] (Vacuum Places Improved) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/06/24 20:08:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HK5TJ3JO.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/14 18:45:20 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2011/11/14 18:45:12 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/14 18:45:11 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/01/10 18:19:38 | 000,000,027 | —- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINNT\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINNT\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1199318644546 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire
http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC7BC81B-A70D-4700-8CBA-E1D77637A0FA}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINNT\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/15 21:48:13 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/01/14 14:20:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\lupu
[2012/01/14 14:12:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\BurnCDCC
[2012/01/13 22:23:04 | 000,000,000 | —D | C] – C:\c1d7fc001171605dddde
[2012/01/13 21:15:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Aunt Wanda
[2012/01/13 17:32:39 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/01/13 16:56:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GETxPUD
[2012/01/10 23:19:52 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/09 18:04:49 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/01/09 18:01:05 | 000,518,144 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2012/01/09 18:01:05 | 000,406,528 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2012/01/09 18:01:05 | 000,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2012/01/09 18:01:05 | 000,060,416 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2012/01/09 18:00:02 | 000,000,000 | —D | C] – C:\WINNT\ERDNT
[2012/01/09 17:59:53 | 000,000,000 | —D | C] – C:\Qoobox
[2012/01/09 17:57:45 | 004,377,322 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/01/09 17:51:54 | 001,972,528 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2012/01/09 03:34:48 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:17:15 | 004,713,472 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/08 21:58:32 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/01/04 21:37:25 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MpSigStub.exe
[2012/01/04 21:31:54 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/01/04 21:28:53 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:17 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | C] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 04:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/03 04:54:11 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2012/01/03 04:54:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/03 04:52:52 | 010,847,608 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/03 04:40:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/03 04:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2008/06/01 17:56:09 | 001,030,144 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2008/06/01 17:56:09 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2008/06/01 17:56:09 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2008/06/01 17:56:09 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2003/07/01 19:02:45 | 000,014,976 | —- | C] ( ) – C:\WINNT\System32\drivers\winddx.sys
[1979/12/31 23:00:00 | 001,295,472 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlstrm.sys
[1979/12/31 23:00:00 | 000,521,408 | —- | C] ( ) – C:\WINNT\System32\drivers\slntamr.sys
[1979/12/31 23:00:00 | 000,210,592 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlmnt5.sys
[1979/12/31 23:00:00 | 000,169,120 | —- | C] ( ) – C:\WINNT\System32\drivers\ntmtlfax.sys
[1979/12/31 23:00:00 | 000,085,688 | —- | C] ( ) – C:\WINNT\System32\drivers\slnthal.sys
[1979/12/31 23:00:00 | 000,045,056 | —- | C] ( ) – C:\WINNT\System32\slserv.exe
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/16 00:17:03 | 000,000,978 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
[2012/01/15 15:48:12 | 001,953,112 | —- | M] () – C:\Documents and Settings\Owner\Desktop\tdsskiller(1).zip
[2012/01/15 13:43:57 | 000,294,216 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2012/01/15 13:37:19 | 000,625,664 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2012/01/15 05:40:00 | 000,000,424 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/15 04:17:00 | 000,000,926 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
[2012/01/14 14:52:20 | 000,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2012/01/14 14:50:51 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2012/01/13 16:55:44 | 000,497,272 | —- | M] () – C:\Documents and Settings\Owner\Desktop\GETxPUD.exe
[2012/01/13 15:24:32 | 001,972,528 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2012/01/10 23:24:07 | 000,396,071 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MiniToolBox.exe
[2012/01/10 23:21:23 | 000,001,725 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/10 18:19:38 | 000,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2012/01/10 17:59:02 | 004,377,322 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/01/09 18:05:00 | 000,000,323 | RHS- | M] () – C:\boot.ini
[2012/01/09 17:51:40 | 001,558,406 | —- | M] () – C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:33:02 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/09 03:17:54 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/07 05:22:05 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/07 05:22:04 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2012/01/04 22:00:56 | 000,000,207 | —- | M] () – C:\Boot.bak
[2012/01/04 21:33:04 | 000,001,945 | —- | M] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:29:05 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:55:56 | 000,302,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:18 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | M] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 13:40:54 | 000,433,414 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2012/01/03 13:40:54 | 000,068,244 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2012/01/03 04:53:24 | 010,847,608 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/15 15:47:46 | 001,953,112 | —- | C] () – C:\Documents and Settings\Owner\Desktop\tdsskiller(1).zip
[2012/01/15 13:44:14 | 000,302,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2012/01/15 13:43:48 | 000,294,216 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2012/01/15 13:37:03 | 000,625,664 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2012/01/13 16:55:34 | 000,497,272 | —- | C] () – C:\Documents and Settings\Owner\Desktop\GETxPUD.exe
[2012/01/10 23:24:05 | 000,396,071 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MiniToolBox.exe
[2012/01/10 23:21:23 | 000,002,307 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/01/10 23:21:23 | 000,001,725 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/09 18:05:00 | 000,000,207 | —- | C] () – C:\Boot.bak
[2012/01/09 18:04:56 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/01/09 18:01:05 | 000,256,000 | —- | C] () – C:\WINNT\PEV.exe
[2012/01/09 18:01:05 | 000,208,896 | —- | C] () – C:\WINNT\MBR.exe
[2012/01/09 18:01:05 | 000,098,816 | —- | C] () – C:\WINNT\sed.exe
[2012/01/09 18:01:05 | 000,080,412 | —- | C] () – C:\WINNT\grep.exe
[2012/01/09 18:01:05 | 000,068,096 | —- | C] () – C:\WINNT\zip.exe
[2012/01/09 17:51:22 | 001,558,406 | —- | C] () – C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2012/01/09 03:33:02 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/04 21:37:52 | 000,000,424 | -H– | C] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/04 21:33:04 | 000,001,945 | —- | C] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:32:20 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/01/03 19:55:54 | 000,302,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2010/07/31 15:14:26 | 000,212,400 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/30 19:37:32 | 000,256,368 | —- | C] () – C:\Program Files\WinRAR.chm
[2010/04/30 19:37:32 | 000,141,824 | —- | C] () – C:\Program Files\RarExt.dll
[2010/04/30 19:37:32 | 000,052,224 | —- | C] () – C:\Program Files\RarExt64.dll
[2010/04/30 19:37:32 | 000,000,495 | —- | C] () – C:\Program Files\File_Id.diz
[2010/01/09 21:27:08 | 000,000,056 | -H– | C] () – C:\WINNT\System32\ezsidmv.dat
[2008/08/31 19:13:08 | 000,073,220 | —- | C] () – C:\WINNT\System32\EPPICPrinterDB.dat
[2008/08/31 19:13:08 | 000,000,097 | —- | C] () – C:\WINNT\System32\PICSDK.ini
[2008/08/31 19:13:07 | 000,031,053 | —- | C] () – C:\WINNT\System32\EPPICPattern131.dat
[2008/08/31 19:13:07 | 000,029,114 | —- | C] () – C:\WINNT\System32\EPPICPattern1.dat
[2008/08/31 19:13:07 | 000,027,417 | —- | C] () – C:\WINNT\System32\EPPICPattern121.dat
[2008/08/31 19:13:07 | 000,021,021 | —- | C] () – C:\WINNT\System32\EPPICPattern3.dat
[2008/08/31 19:13:07 | 000,015,670 | —- | C] () – C:\WINNT\System32\EPPICPattern5.dat
[2008/08/31 19:13:07 | 000,013,280 | —- | C] () – C:\WINNT\System32\EPPICPattern2.dat
[2008/08/31 19:13:07 | 000,010,673 | —- | C] () – C:\WINNT\System32\EPPICPattern4.dat
[2008/08/31 19:13:07 | 000,004,943 | —- | C] () – C:\WINNT\System32\EPPICPattern6.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_PT.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_BP.dat
[2008/08/31 19:13:07 | 000,001,137 | —- | C] () – C:\WINNT\System32\EPPICPresetData_ES.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_FR.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_CF.dat
[2008/08/31 19:13:07 | 000,001,104 | —- | C] () – C:\WINNT\System32\EPPICPresetData_EN.dat
[2008/08/31 19:11:38 | 000,000,044 | —- | C] () – C:\WINNT\EPSNX400.ini
[2008/06/19 23:32:00 | 000,001,160 | —- | C] () – C:\WINNT\mozver.dat
[2008/06/02 17:23:38 | 000,021,312 | —- | C] () – C:\WINNT\choice.exe
[2008/06/01 17:56:28 | 000,018,464 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox.dat
[2008/06/01 17:56:28 | 000,001,056 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox2.dat
[2008/05/16 13:59:02 | 000,000,374 | —- | C] () – C:\WINNT\wininit.ini
[2008/03/11 16:20:45 | 000,000,121 | —- | C] () – C:\WINNT\winzipsp.ini
[2008/02/08 02:00:14 | 000,000,080 | —- | C] () – C:\WINNT\SuperUtil.ini
[2008/02/08 01:51:36 | 000,000,000 | —- | C] () – C:\WINNT\System32\suupdate.dat
[2008/02/08 01:51:35 | 000,000,000 | —- | C] () – C:\WINNT\System32\mssurun.dat
[2007/12/05 03:08:52 | 001,446,464 | —- | C] () – C:\Program Files\Silverlight.exe
[2007/10/20 19:08:23 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
[2007/10/20 18:25:18 | 000,049,152 | —- | C] () – C:\WINNT\System32\ChCfg.exe
[2007/10/20 18:23:14 | 000,147,456 | —- | C] () – C:\WINNT\System32\RtlCPAPI.dll
[2007/10/18 00:00:21 | 000,055,949 | —- | C] () – C:\WINNT\System32\x264-uninstall.exe
[2007/10/11 05:20:56 | 000,000,000 | —- | C] () – C:\WINNT\System32\drivers\atwpkt2.sys
[2007/03/02 16:03:53 | 000,001,763 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/12 22:02:29 | 000,000,116 | —- | C] () – C:\WINNT\NeroDigital.ini
[2007/01/15 01:25:20 | 000,000,079 | —- | C] () – C:\WINNT\xptools.ini
[2007/01/15 01:21:58 | 000,000,120 | —- | C] () – C:\WINNT\System32\bn.dll
[2007/01/08 18:20:12 | 000,014,848 | —- | C] () – C:\WINNT\System32\BASSMOD.dll
[2006/12/18 03:43:12 | 000,000,022 | —- | C] () – C:\Program Files\zipnew.dat
[2006/12/18 03:43:12 | 000,000,020 | —- | C] () – C:\Program Files\rarnew.dat
[2006/12/18 03:42:56 | 001,039,360 | —- | C] () – C:\Program Files\WinRAR.exe
[2006/12/18 03:42:56 | 000,378,880 | —- | C] () – C:\Program Files\Rar.exe
[2006/12/18 03:42:56 | 000,246,272 | —- | C] () – C:\Program Files\UnRAR.exe
[2006/12/18 03:42:56 | 000,092,672 | —- | C] () – C:\Program Files\Default.SFX
[2006/12/18 03:42:56 | 000,074,240 | —- | C] () – C:\Program Files\Zip.SFX
[2006/12/18 03:42:56 | 000,069,632 | —- | C] () – C:\Program Files\WinCon.SFX
[2006/12/18 03:42:56 | 000,045,056 | —- | C] () – C:\Program Files\RarExtLoader.exe
[2006/12/18 03:42:55 | 000,003,271 | —- | C] () – C:\Program Files\Order.htm
[2006/12/18 03:42:55 | 000,001,088 | —- | C] () – C:\Program Files\RarFiles.lst
[2006/12/18 03:42:55 | 000,001,063 | —- | C] () – C:\Program Files\Descript.ion
[2006/12/18 03:42:55 | 000,000,639 | —- | C] () – C:\Program Files\Uninstall.lst
[2006/11/07 20:52:05 | 000,000,044 | —- | C] () – C:\WINNT\liveup.ini
[2006/08/12 22:09:45 | 000,004,096 | —- | C] () – C:\WINNT\d3dx.dat
[2006/07/16 17:08:08 | 000,000,627 | —- | C] () – C:\Program Files\playlist.xml
[2006/03/23 19:13:53 | 000,052,490 | —- | C] () – C:\WINNT\DcArt32presets.ini
[2006/03/05 01:46:11 | 000,001,610 | —- | C] () – C:\WINNT\GPlrLanc.dat
[2005/12/13 17:30:33 | 000,122,535 | —- | C] () – C:\WINNT\RSEDNClientUninstaller.exe
[2005/11/22 00:41:22 | 000,000,784 | —- | C] () – C:\Documents and Settings\Owner\Application Data\mpauth.dat
[2005/09/26 18:27:37 | 000,000,028 | —- | C] () – C:\WINNT\Systems.ini
[2005/08/31 18:05:37 | 000,000,075 | —- | C] () – C:\WINNT\System32\sysogg.dll
[2005/07/09 06:00:53 | 000,000,008 | —- | C] () – C:\WINNT\System32\wtl.dat
[2005/07/09 05:25:40 | 000,000,004 | —- | C] () – C:\WINNT\System32\micr0st.dll
[2005/07/09 05:16:13 | 000,129,024 | —- | C] () – C:\WINNT\UNWISE.EXE
[2005/06/29 14:53:05 | 000,005,460 | —- | C] () – C:\WINNT\kwv2.dat
[2005/06/27 17:37:46 | 000,187,512 | —- | C] () – C:\WINNT\System32\u3ldgpnu.dat
[2005/06/27 17:37:46 | 000,026,736 | —- | C] () – C:\WINNT\System32\4qlv6iqe.dat
[2005/06/27 17:37:46 | 000,003,864 | —- | C] () – C:\WINNT\System32\ahkhsbsu.dat
[2005/06/27 17:37:46 | 000,002,715 | —- | C] () – C:\WINNT\System32\mvkl8s1u.dat
[2005/06/27 17:37:46 | 000,000,000 | —- | C] () – C:\WINNT\System32\g8k3i4ve.dat
[2005/06/27 17:37:38 | 000,000,035 | —- | C] () – C:\WINNT\System32\01ii4bjf.ini
[2005/06/27 17:37:37 | 000,003,485 | —- | C] () – C:\WINNT\System32\mdeaf9ej.ini
[2005/05/20 21:35:09 | 000,000,056 | RHS- | C] () – C:\WINNT\System32\566097EC98.sys
[2005/03/21 20:59:40 | 000,000,715 | —- | C] () – C:\WINNT\aolback.exe.lnk
[2005/03/21 20:53:31 | 000,000,335 | —- | C] () – C:\WINNT\nsreg.dat
[2005/02/18 16:53:48 | 000,000,000 | —- | C] () – C:\WINNT\impborl.dll
[2005/02/08 14:42:45 | 000,000,092 | —- | C] () – C:\Program Files\play.rbn.rm&proto;=rtsp
[2005/01/13 22:23:53 | 000,001,131 | —- | C] () – C:\WINNT\System32\vh.dat
[2005/01/04 16:19:13 | 000,001,100 | —- | C] () – C:\WINNT\dhstatus.dat
[2004/12/15 08:22:09 | 000,149,504 | —- | C] () – C:\WINNT\System32\UNWISE.EXE
[2004/10/31 18:32:17 | 000,001,100 | —- | C] () – C:\WINNT\checkip.dat
[2004/10/31 18:29:50 | 000,001,393 | —- | C] () – C:\WINNT\ipconfig.dat
[2004/09/25 22:23:36 | 000,004,569 | —- | C] () – C:\WINNT\System32\secupd.dat
[2004/08/29 21:52:13 | 000,131,072 | —- | C] () – C:\WINNT\System32\SpoonUninstall.exe
[2004/08/25 17:53:06 | 000,000,032 | —- | C] () – C:\WINNT\easecdripper.ini
[2004/08/25 17:28:05 | 000,003,082 | —- | C] () – C:\WINNT\System32\affv6628p4now.sys
[2004/08/17 01:56:38 | 000,122,880 | —- | C] () – C:\WINNT\UnGins.exe
[2004/08/13 03:53:41 | 000,000,014 | —- | C] () – C:\WINNT\msoffice.ini
[2004/07/21 21:54:24 | 000,001,125 | —- | C] () – C:\WINNT\winamp.ini
[2004/05/26 14:42:25 | 000,000,048 | —- | C] () – C:\WINNT\upth.ini
[2004/05/26 14:42:25 | 000,000,028 | —- | C] () – C:\WINNT\atid.ini
[2004/02/11 07:50:12 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/02/07 14:41:59 | 000,082,944 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/22 12:00:28 | 000,012,635 | —- | C] () – C:\WINNT\System32\DAntivirus.ini
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\{419EC9B7-3209-4445-9EEC-01B25AAF5B29}.dat
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\System32\{0D36DCD8-9C7D-430C-A8AA-BD8DF873A105}.dat
[2003/10/25 14:37:35 | 000,067,857 | —- | C] () – C:\WINNT\cdPlayer.ini
[2003/10/22 10:05:08 | 000,000,030 | —- | C] () – C:\WINNT\Morphexe.INI
[2003/10/08 13:34:26 | 000,121,440 | —- | C] () – C:\WINNT\System32\MSDRMCtrl.dll
[2003/08/27 18:06:58 | 000,000,027 | —- | C] () – C:\WINNT\UP9ASP.INI
[2003/08/27 17:33:30 | 000,006,550 | —- | C] () – C:\WINNT\jautoexp.dat
[2003/08/27 16:45:53 | 000,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2003/08/27 14:24:03 | 000,000,242 | —- | C] () – C:\WINNT\qwimp.ini
[2003/08/26 16:10:20 | 000,000,120 | —- | C] () – C:\WINNT\SIERRA.INI
[2003/08/23 13:49:22 | 000,000,396 | —- | C] () – C:\WINNT\intuprof.ini
[2003/08/23 13:48:46 | 000,000,880 | —- | C] () – C:\WINNT\QUICKEN.INI
[2003/08/22 20:05:57 | 000,002,241 | —- | C] () – C:\WINNT\hpdj5600.ini
[2003/08/22 20:05:25 | 000,000,414 | —- | C] () – C:\WINNT\hpbvspst.ini
[2003/07/16 14:22:18 | 000,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINNT\patchw32.dll
[2003/07/01 19:23:27 | 000,000,000 | —- | C] () – C:\WINNT\System32\a3d.dll
[2003/07/01 19:10:07 | 000,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2003/07/01 19:07:33 | 000,282,624 | —- | C] () – C:\WINNT\System32\PCDrSystemInformation.dll
[2003/07/01 19:05:00 | 000,094,208 | —- | C] () – C:\WINNT\System32\PCDrKernelModeServices.dll
[2003/07/01 19:05:00 | 000,077,824 | —- | C] () – C:\WINNT\System32\ProgressTrace.dll
[2003/07/01 19:03:46 | 000,000,561 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2003/07/01 19:02:45 | 000,466,944 | —- | C] () – C:\WINNT\System32\SLLights.dll
[2003/07/01 19:02:45 | 000,376,832 | —- | C] () – C:\WINNT\System32\slmh.exe
[2003/07/01 19:02:45 | 000,167,936 | —- | C] () – C:\WINNT\System32\minirec.exe
[2003/07/01 19:02:45 | 000,151,552 | —- | C] () – C:\WINNT\System32\amr_cpl.dll
[2003/07/01 19:02:45 | 000,061,440 | —- | C] () – C:\WINNT\SmCfg.exe
[2003/05/16 11:56:01 | 000,000,770 | —- | C] () – C:\WINNT\orun32.ini
[2003/05/16 10:34:34 | 000,002,048 | –S- | C] () – C:\WINNT\bootstat.dat
[2003/05/16 10:26:45 | 000,021,640 | —- | C] () – C:\WINNT\System32\emptyregdb.dat
[2003/05/16 10:20:03 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/05/16 10:18:53 | 000,221,632 | —- | C] () – C:\WINNT\System32\FNTCACHE.DAT
[2003/03/27 15:28:44 | 000,004,955 | —- | C] () – C:\WINNT\System32\DProg.ini
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINNT\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINNT\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINNT\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINNT\System32\ogg.dll
[2002/09/06 10:36:16 | 000,233,472 | —- | C] () – C:\WINNT\System32\lame_enc.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINNT\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINNT\System32\libpostproc.dll
[2001/08/29 18:57:40 | 000,155,648 | —- | C] () – C:\WINNT\System32\addurl41.DLL
[2001/07/10 13:43:16 | 000,018,432 | —- | C] () – C:\WINNT\System32\winwatch.DLL
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINNT\System32\MPEG2DEC.dll
[2000/09/08 16:53:50 | 000,073,839 | —- | C] () – C:\WINNT\System32\KodakOneTouch.dll
[1979/12/31 23:00:00 | 013,107,200 | —- | C] () – C:\WINNT\System32\oembios.bin
[1979/12/31 23:00:00 | 000,673,088 | —- | C] () – C:\WINNT\System32\mlang.dat
[1979/12/31 23:00:00 | 000,433,414 | —- | C] () – C:\WINNT\System32\perfh009.dat
[1979/12/31 23:00:00 | 000,272,128 | —- | C] () – C:\WINNT\System32\perfi009.dat
[1979/12/31 23:00:00 | 000,218,003 | —- | C] () – C:\WINNT\System32\dssec.dat
[1979/12/31 23:00:00 | 000,188,416 | —- | C] () – C:\WINNT\System32\slextspk.dll
[1979/12/31 23:00:00 | 000,159,744 | —- | C] () – C:\WINNT\System32\SLGen.dll
[1979/12/31 23:00:00 | 000,068,244 | —- | C] () – C:\WINNT\System32\perfc009.dat
[1979/12/31 23:00:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\coinst.dll
[1979/12/31 23:00:00 | 000,046,258 | —- | C] () – C:\WINNT\System32\mib.bin
[1979/12/31 23:00:00 | 000,028,626 | —- | C] () – C:\WINNT\System32\perfd009.dat
[1979/12/31 23:00:00 | 000,024,576 | —- | C] () – C:\WINNT\slrundll.exe
[1979/12/31 23:00:00 | 000,005,114 | —- | C] () – C:\WINNT\System32\oembios.dat
[1979/12/31 23:00:00 | 000,001,804 | —- | C] () – C:\WINNT\System32\dcache.bin
[1979/12/31 23:00:00 | 000,000,741 | —- | C] () – C:\WINNT\System32\noise.dat
========== LOP Check ==========
[2008/12/11 17:53:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/06/11 18:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2010/07/21 19:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/08/31 21:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/01/06 14:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/08/09 17:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/10 22:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2009/12/07 18:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/07/07 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/11/06 19:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/01/03 05:06:09 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/10/18 21:27:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/07 18:04:51 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2003/07/01 19:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\InterTrust
[2009/12/07 19:00:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2006/03/04 04:39:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2007/01/04 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/06/21 16:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DC++
[2008/09/05 16:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eBookPro6
[2010/07/07 21:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2003/08/05 22:50:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/08/31 21:25:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2008/08/31 19:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/02/16 23:56:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\minimem
[2011/09/05 15:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/05/09 07:48:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCToolsFirewallPlus
[2008/08/15 02:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PhotoParade
[2009/11/28 20:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Playrix Entertainment
[2009/10/19 00:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SharePod
[2009/01/04 23:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2009/05/02 11:38:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skunk Studios
[2011/05/09 07:47:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2009/11/29 21:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sudden Games
[2009/04/15 01:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Systweak
[2009/09/26 16:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TikisLab
[2005/12/15 03:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuneUp Software
[2008/02/12 04:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Uniblue
[2007/01/20 03:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/06/29 14:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2007/10/07 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens
[2006/08/12 22:14:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wildfire
[2012/01/15 05:40:00 | 000,000,424 | -H– | M] () – C:\WINNT\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Program Files\play.rbn.rm&proto;=rtsp:SummaryInformation
< End of report >