Is the HJt log correct in that you don't have any Service Packs installed? i don't see an antivirus program installed.
This has never allowed me to install the SP's
Since the first post the pop ups got much worst, but I'm finally able to access this forum again.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-16 20:26:43
—————————–
20:26:43.983 OS Version: Windows 5.1.2600
20:26:43.983 Number of processors: 1 586 0x204
20:26:43.983 ComputerName: JJCSB11 UserName:
20:26:44.499 Initialize success
20:27:18.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
20:27:18.171 Disk 0 Vendor: MAXTOR_6L080J4 A93.0500 Size: 76345MB BusType: 3
20:27:18.186 Disk 0 MBR read successfully
20:27:18.186 Disk 0 MBR scan
20:27:18.186 Disk 0 Windows XP default MBR code
20:27:18.186 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 31 MB offset 63
20:27:18.202 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76308 MB offset 64260
20:27:18.202 Disk 0 scanning sectors +156344580
20:27:18.358 Disk 0 scanning C:\WINDOWS\System32\drivers
20:27:22.968 Service scanning
20:27:37.327 Modules scanning
20:27:46.436 Disk 0 trace - called modules:
20:27:46.468 TUKERNEL.EXE CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
20:27:46.468 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863d8b48]
20:27:46.999 3 CLASSPNP.SYS[f787fceb] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x863f1030]
20:27:46.999 Scan finished successfully
20:28:17.296 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\hijackthis\MBR.dat"
20:28:17.311 The log file has been saved successfully to "C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\hijackthis\aswMBR.txt"
OTL Extras logfile created on: 3/16/2012 8:33:07 PM - Run 1
OTL by OldTimer - Version 3.2.37.1 Folder = C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\hijackthis
Windows XP Home Edition (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.01 Mb Total Physical Memory | 796.72 Mb Available Physical Memory | 77.88% Memory free
2.86 Gb Paging File | 2.72 Gb Available in Paging File | 95.33% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 60.63 Gb Free Space | 81.36% Space Free | Partition Type: NTFS
Drive E: | 1.91 Gb Total Space | 1.84 Gb Free Space | 96.14% Space Free | Partition Type: FAT
Computer Name: JJCSB11 | User Name: Reid Rodger | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL %1,%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL %1,%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E908702-AF35-4611-9518-955DA24B7E07}" = Microsoft XML Parser and SDK
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7E545666-F422-45FD-B3DF-C0B99A1A579F}" = QuickBooks Pro 2007
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{91208A47-5D08-4C79-986F-1931940F51BB}" = QuickBooks Product Listing Service
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.7
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Chaoscope_is1" = Chaoscope 0.3
"HijackThis" = HijackThis 1.99.1
"IE40" = Microsoft Internet Explorer 6 SP1
"ieSpell" = ieSpell 2.1.1 (build 325)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Q329048" = Windows XP Hotfix (SP1) [See Q329048 for more information]
"Q329115" = Windows XP Hotfix (SP2) [See Q329115 for more information]
"Q329170" = Windows XP Hotfix (SP1) Q329170
"Q329390" = Windows XP Hotfix (SP1) [See Q329390 for more information]
"Q329441" = Windows XP Hotfix (SP1) [See Q329441 for more information]
"Q329834" = Windows XP Hotfix (SP1) [See Q329834 for more information]
"Q810577" = Windows XP Hotfix (SP1) Q810577
"Q810833" = Windows XP Hotfix (SP1) Q810833
"Q815021" = Windows XP Hotfix (SP1) Q815021
"Registry Mechanic_is1" = Registry Mechanic
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinMerge_is1" = WinMerge [removed]
"WS_FTP Pro" = Ipswitch WS_FTP Pro
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/14/2012 1:12:03 AM | Computer Name = JJCSB11 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 10.0.1.4421, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/11/2012 12:56:56 AM | Computer Name = JJCSB11 | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfDisk"
in
the "C:\WINDOWS\system32\perfdisk.dll" Library to finish has expired. There may
be a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/15/2012 11:21:35 PM | Computer Name = JJCSB11 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 10.0.2.4428, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 2/7/2012 9:34:27 AM | Computer Name = JJCSB11 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.100.11 for the Network Card with network
address 00080E5BFEBF has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).
Error - 2/24/2012 12:26:31 AM | Computer Name = JJCSB11 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.100.11 for the Network Card with network
address 00080E5BFEBF has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).
< End of report >
OTL logfile created on: 3/16/2012 8:33:07 PM - Run 1
OTL by OldTimer - Version 3.2.37.1 Folder = C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\hijackthis
Windows XP Home Edition (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.01 Mb Total Physical Memory | 796.72 Mb Available Physical Memory | 77.88% Memory free
2.86 Gb Paging File | 2.72 Gb Available in Paging File | 95.33% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 60.63 Gb Free Space | 81.36% Space Free | Partition Type: NTFS
Drive E: | 1.91 Gb Total Space | 1.84 Gb Free Space | 96.14% Space Free | Partition Type: FAT
Computer Name: JJCSB11 | User Name: Reid Rodger | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\hijackthis\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe (iAnywhere Solutions, Inc.)
PRC - C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ==========
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_67cbf724\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_3344af49\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.serviceprocess\1.0.5000.0__b03f5f7f11d50a3a\system.serviceprocess.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (QuickBooksDB17) – C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe (iAnywhere Solutions, Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (vsdatant) – System32\vsdatant.sys File not found
DRV - (SonyPVP1) – System32\DRIVERS\SonyPVP1.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\REIDRO~1.JJC\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (ndiscm) – C:\WINDOWS\system32\drivers\NetMotCM.sys (Motorola Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (V124) – C:\WINDOWS\system32\drivers\HSF_V124.sys (Conexant)
DRV - (Tones) – C:\WINDOWS\system32\drivers\HSF_TONE.sys (Conexant)
DRV - (hsf_msft) – C:\WINDOWS\system32\drivers\HSF_MSFT.sys (Conexant)
DRV - (SpeakerPhone) – C:\WINDOWS\system32\drivers\HSF_SPKP.sys (Conexant)
DRV - (Rksample) – C:\WINDOWS\system32\drivers\HSF_SAMP.sys (Conexant)
DRV - (K56) – C:\WINDOWS\system32\drivers\HSF_K56K.sys (Conexant)
DRV - (Fallback) – C:\WINDOWS\system32\drivers\HSF_FALL.sys (Conexant)
DRV - (SoftFax) – C:\WINDOWS\system32\drivers\HSF_FAXX.sys (Conexant)
DRV - (Fsks) – C:\WINDOWS\system32\drivers\HSF_FSKS.sys (Conexant)
DRV - (basic2) – C:\WINDOWS\system32\drivers\HSF_BSC2.sys (Conexant)
DRV - (nv4) – C:\WINDOWS\system32\drivers\nv4.sys (NVIDIA Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (DM9102) DAVICOM 9102(A) – C:\WINDOWS\system32\drivers\DM9PCI5.SYS (CNet Technology, Inc. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = htp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rsigrowers.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "search"
FF - prefs.js..browser.startup.homepage: "http://www.rsigrowers.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..network.proxy.type: 2
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/19 20:36:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/10 16:57:02 | 000,000,000 | —D | M]
[2008/08/31 10:17:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Mozilla\Extensions
[2012/01/31 14:46:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Mozilla\Firefox\Profiles\9fsm92nl.default\extensions
[2012/03/10 16:57:04 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/10 16:57:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\REID RODGER.JJCSB11\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\9FSM92NL.DEFAULT\EXTENSIONS\[removed]
[2012/02/19 20:36:29 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/03/10 16:56:53 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/13 06:32:20 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/13 06:32:20 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/03/15 21:11:39 | 000,022,475 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.preferances.com
O1 - Hosts: 127.0.0.1 ad.doubleclick.com
O1 - Hosts: 127.0.0.1 ads.web.aol.com
O1 - Hosts: 127.0.0.1 ad.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.preferences.com
O1 - Hosts: 127.0.0.1 ad.washingtonpost.com
O1 - Hosts: 127.0.0.1 adpick.switchboard.com
O1 - Hosts: 127.0.0.1 ads.doubleclick.com
O1 - Hosts: 127.0.0.1 ads.infospace.com
O1 - Hosts: 127.0.0.1 ads.msn.com
O1 - Hosts: 127.0.0.1 ads.switchboard.com
O1 - Hosts: 127.0.0.1 ads.enliven.com
O1 - Hosts: 127.0.0.1 oz.valueclick.com
O1 - Hosts: 127.0.0.1 doubleclick.net
O1 - Hosts: 127.0.0.1 ads.doubleclick.net
O1 - Hosts: 127.0.0.1 ad2.doubleclick.net
O1 - Hosts: 127.0.0.1 ad3.doubleclick.net
O1 - Hosts: 127.0.0.1 ad4.doubleclick.net
O1 - Hosts: 127.0.0.1 ad5.doubleclick.net
O1 - Hosts: 127.0.0.1 ad6.doubleclick.net
O1 - Hosts: 127.0.0.1 ad7.doubleclick.net
O1 - Hosts: 127.0.0.1 ad8.doubleclick.net
O1 - Hosts: 674 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (WsftpBrowserHelper Class) - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll (Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Radio;) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKCU..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 1
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/C…C4D/mp43dmo.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B6A45727-387D-46FD-951D-7BFC3FE9B9D4}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Reid Rodger.JJCSB11\My Documents\My Pictures\107581VbDA.jpg
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Reid Rodger.JJCSB11\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/10/27 15:08:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/10/27 15:08:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.CAM – [ NTFS ]
O32 - AutoRun File - [2006/10/23 16:17:28 | 000,000,075 | —- | M] () - E:\autorun.inf – [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/16 06:36:04 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\aswMBR.exe
[2012/03/15 21:39:18 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/03/15 21:39:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Reid Rodger.JJCSB11\Start Menu\Programs\HiJackThis
[2012/03/15 18:40:51 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BVMADP
[2012/03/15 18:40:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\4e352e
[2012/03/10 16:57:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun
[2012/03/10 16:57:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/03/10 16:57:02 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/03/10 16:57:02 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/03/10 16:57:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/03/10 16:57:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/03/10 16:57:02 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/16 20:24:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/16 20:24:23 | 1072,775,168 | -HS- | M] () – C:\hiberfil.sys
[2012/03/16 06:36:56 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\aswMBR.exe
[2012/03/15 22:08:14 | 002,044,822 | —- | M] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\tdsskiller.zip
[2012/03/15 21:11:39 | 000,022,475 | RHS- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/15 18:44:11 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/15 18:35:43 | 009,723,479 | —- | M] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\trutlema_import.sql.gz
[2012/03/14 19:07:34 | 150,328,406 | —- | M] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\backup-3.15.2012_02-46-49_trutlema.tar.gz
[2012/03/10 16:56:53 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/03/10 16:56:53 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/03/10 16:56:53 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/03/10 16:56:53 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/03/10 16:56:53 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/03/08 15:15:43 | 005,752,755 | —- | M] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\CubeCart-5.0.7.zip
[2012/02/23 21:26:20 | 000,002,184 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/15 22:08:05 | 002,044,822 | —- | C] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\tdsskiller.zip
[2012/03/15 18:44:11 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/15 18:35:11 | 009,723,479 | —- | C] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\trutlema_import.sql.gz
[2012/03/14 19:03:37 | 150,328,406 | —- | C] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\backup-3.15.2012_02-46-49_trutlema.tar.gz
[2012/03/08 15:15:25 | 005,752,755 | —- | C] () – C:\Documents and Settings\Reid Rodger.JJCSB11\Desktop\CubeCart-5.0.7.zip
[2010/11/21 18:39:59 | 000,299,479 | —- | C] () – C:\WINDOWS\System32\shimg.dll
========== LOP Check ==========
[2012/03/15 22:57:56 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\4e352e
[2010/09/21 08:04:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Applications
[2007/08/02 17:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG7
[2012/03/15 18:40:51 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BVMADP
[2007/05/23 17:04:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\COMMON FILES
[2008/02/19 15:01:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\iolo
[2008/02/19 15:00:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
[2008/08/23 18:07:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2006/01/07 18:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
[2005/12/04 08:41:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Alien Skin
[2006/02/04 07:46:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Avant Browser
[2007/08/02 16:27:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\AVG7
[2005/01/30 14:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\ieSpell
[2008/02/19 15:01:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\iolo
[2005/01/26 18:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Jasc
[2006/12/07 18:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Leadertech
[2005/02/11 17:42:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Opera
[2006/01/07 18:39:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\TuneUp Software
[2010/01/24 09:39:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\Uniblue
[2008/09/04 18:38:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Reid Rodger.JJCSB11\Application Data\W Photo Studio Viewer
[2012/01/20 17:15:00 | 000,000,402 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2006/02/20 20:24:25 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\XoftSpy.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/01/16 15:39:00 | 000,000,042 | —- | M] () – C:\404.shtml
[2003/05/07 09:46:13 | 000,012,705 | —- | M] () – C:\atlog.txt
[2002/10/27 15:08:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2002/10/27 15:08:13 | 000,000,000 | —- | M] () – C:\AUTOEXEC.CAM
[2004/12/31 19:33:33 | 010,436,826 | RHS- | M] () – C:\AVG6DB_F.DAT
[2005/02/21 08:32:42 | 013,836,126 | RHS- | M] () – C:\AVG7DB_F.DAT
[2005/01/26 07:27:45 | 011,885,297 | —- | M] () – C:\AVG7QT.DAT
[2002/10/27 00:26:32 | 000,000,022 | —- | M] () – C:\AVGT602.TM
[2003/12/26 21:25:18 | 000,010,571 | —- | M] () – C:\avgun.log
[2011/11/26 16:56:30 | 000,000,389 | RHS- | M] () – C:\boot.ini
[2001/09/20 09:56:14 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2001/09/20 10:17:36 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2002/03/19 12:44:24 | 000,003,687 | RH– | M] () – C:\DELL.SDR
[2004/01/20 09:19:19 | 001,244,952 | —- | M] () – C:\Documents
[2004/06/04 17:40:14 | 000,000,098 | —- | M] () – C:\DownloadLog.txt
[2006/09/09 19:03:10 | 000,012,093 | —- | M] () – C:\EyeCandyLog.txt
[2012/03/16 20:24:23 | 1072,775,168 | -HS- | M] () – C:\hiberfil.sys
[2007/05/17 18:39:59 | 000,000,164 | —- | M] () – C:\install.dat
[2001/09/20 10:17:36 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2003/12/29 16:24:45 | 000,000,014 | —- | M] () – C:\IPGP.txt
[2002/03/19 12:12:00 | 000,000,319 | -H– | M] () – C:\IPH.PH
[2001/09/20 10:17:36 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2001/08/18 05:00:00 | 000,045,124 | RHS- | M] () – C:\NTDETECT.COM
[2001/08/18 05:00:00 | 000,222,368 | RHS- | M] () – C:\ntldr
[2012/03/16 20:24:23 | 2097,152,000 | -HS- | M] () – C:\pagefile.sys
[2003/10/28 18:00:50 | 000,001,251 | —- | M] () – C:\r.d
[2006/02/01 18:38:08 | 000,000,045 | —- | M] () – C:\TEST.XML
[2003/12/29 16:24:45 | 000,001,044 | —- | M] () – C:\vsettings.ini
[2003/06/17 15:19:40 | 000,000,000 | —- | M] () – C:\welcome.dat
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/01/23 21:02:53 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2002/09/22 16:11:11 | 000,052,270 | —- | M] () – C:\WINDOWS\painted ladies.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/01/23 13:49:35 | 000,090,112 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/01/23 13:49:35 | 000,606,208 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/01/23 13:49:35 | 000,385,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2005/01/23 21:03:37 | 000,000,214 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini
[2005/01/23 21:42:12 | 000,001,992 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\New Office Document.lnk
[2005/01/23 21:42:12 | 000,002,002 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Open Office Document.lnk
[2005/01/23 21:03:37 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Windows Catalog.lnk
[2005/01/23 21:03:37 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Windows Update.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-04-13 21:49:49
< MD5 for: EXPLORER.EX_ >
[2004/08/04 00:56:50 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\i386\explorer.ex_
[2001/08/18 04:00:00 | 000,351,519 | —- | M] () MD5=E6F0FE192F4530358CFFD9A473C9BBDD – C:\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2001/08/18 05:00:00 | 001,000,960 | —- | M] (Microsoft Corporation) MD5=5A26FC6010886D25B3E412493DD95ED8 – C:\WINDOWS\explorer.exe
[2001/08/18 05:00:00 | 001,000,960 | —- | M] (Microsoft Corporation) MD5=5A26FC6010886D25B3E412493DD95ED8 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.SC_ >
[2001/08/18 04:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2001/08/18 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CH_ >
[2004/07/17 11:40:18 | 000,199,077 | —- | M] () MD5=5F64795662F162CCD8B30969B6682029 – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\i386\iexplore.ch_
< MD5 for: IEXPLORE.CHM >
[2001/08/18 04:00:00 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\I386\IEXPLORE.CHM
[2002/08/29 07:14:40 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\WINDOWS\Help\iexplore.chm
[2002/08/29 07:14:40 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\WINDOWS\system32\dllcache\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2001/08/18 04:00:00 | 000,036,907 | —- | M] () MD5=BAB04CF3E54FB3DBE05261738DE6467B – C:\I386\IEXPLORE.EX_
[2004/08/04 00:56:52 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\i386\iexplore.ex_
< MD5 for: IEXPLORE.EXE >
[2012/01/13 14:53:20 | 000,182,856 | —- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2001/08/18 05:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=92B1834F54EAB14B0B7137E6CEF5E1B2 – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2001/08/18 05:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=92B1834F54EAB14B0B7137E6CEF5E1B2 – C:\WINDOWS\system32\dllcache\iexplore.exe
< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/03/15 20:22:43 | 000,088,154 | —- | M] () MD5=396A2A51B6B8B1E156B63B360806A18A – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
< MD5 for: IEXPLORE.HLP >
[2001/08/18 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2002/08/29 07:14:40 | 000,180,241 | —- | M] () MD5=421AE3C34C386C75D019739E4C7179FE – C:\WINDOWS\Help\iexplore.hlp
[2002/08/29 07:14:40 | 000,180,241 | —- | M] () MD5=421AE3C34C386C75D019739E4C7179FE – C:\WINDOWS\system32\dllcache\iexplore.hlp
< MD5 for: WINLOGON.EX_ >
[2004/08/04 00:56:58 | 000,261,115 | —- | M] () MD5=F41C4F5745589D0BB8268C02B71594CA – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\i386\winlogon.ex_
< MD5 for: WINLOGON.EXE >
[2001/08/18 04:00:00 | 000,430,080 | —- | M] (Microsoft Corporation) MD5=2B0E480E975EE51F2D5CE5F068FED6E2 – C:\I386\WINLOGON.EXE
[2001/08/18 05:00:00 | 000,430,080 | —- | M] (Microsoft Corporation) MD5=2B0E480E975EE51F2D5CE5F068FED6E2 – C:\WINDOWS\system32\dllcache\winlogon.exe
[2001/08/18 05:00:00 | 000,430,080 | —- | M] (Microsoft Corporation) MD5=2B0E480E975EE51F2D5CE5F068FED6E2 – C:\WINDOWS\system32\winlogon.exe
[2012/01/13 14:53:20 | 000,182,856 | —- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
< End of report >