noob_dan
Topic Starter
Hi,
I appreciate all patience and any further guidance in advance !
I am definitely a newbie with computers, but I have learned/taught myself lots pretty quickly.
There is a virus going around that has many names i.e. (Windows Recovery, Windows AntiVirus 2012) where all desktop icons are missing, startup menu is empty, administrative tools are empty, desktop background is blue, and constant windows are popping up saying there are 14 or more viruses found, and immediate action needs to be taken, and leads you to nothing but an order form screen…..
I have restored my desktop icons, and most of my startup menu, and administrative tools. System Recovery was not able to load/restore from any of the points chosen (I read this tool is disabled from this virus). I was able copy some of my programs shortcuts to the programs list, but I am still missing several tools/programs. I use Microsoft Security Essentials, and the Windows Malicious Software Removal Tool. Both have ran, and only MSE has came up with several viruses/trojans/etc, and removed them. I read from a previous blog titled "Trojan on my Computer [Solved]" on how to start the malware removal.
I was only able to download and run OTL.exe. The tool aswMBR.exe would download, but would not open. I tried "run as Administrator", disabling anti-virus/firewall, and renaming the application, but nothing would work.
Here are my attached OTL.txt and Extras.txt
OTL logfile created on: 6/30/2012 6:02:55 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\Dan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.99% Memory free
3.84 Gb Paging File | 3.46 Gb Available in Paging File | 90.01% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.68 Gb Total Space | 19.71 Gb Free Space | 58.52% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: DEHAHN | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dan\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NeroMediaHomeService.4) – C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
SRV - (pdfcDispatcher) – C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (tfsnudfa) – system32\dla\tfsnudfa.sys File not found
DRV - (tfsnudf) – system32\dla\tfsnudf.sys File not found
DRV - (tfsnpool) – system32\dla\tfsnpool.sys File not found
DRV - (tfsnopio) – system32\dla\tfsnopio.sys File not found
DRV - (tfsnifs) – system32\dla\tfsnifs.sys File not found
DRV - (tfsndres) – system32\dla\tfsndres.sys File not found
DRV - (tfsndrct) – system32\dla\tfsndrct.sys File not found
DRV - (tfsncofs) – system32\dla\tfsncofs.sys File not found
DRV - (tfsnboio) – system32\dla\tfsnboio.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (MpKsld6d34de9) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{298A0275-4F3A-4DCB-95AE-321EED411A49}\MpKsld6d34de9.sys (Microsoft Corporation)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (BANTExt) – C:\WINDOWS\system32\drivers\BANTExt.sys ()
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (Blfp) – C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)
DRV - (cpqdfw) – C:\WINDOWS\system32\drivers\Cpqdfw.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/17 00:24:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/04/25 11:02:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dan\Application Data\Mozilla\Extensions
[2012/05/01 21:41:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\sc268k5v.default\extensions
[2012/06/13 22:08:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/26 23:31:06 | 000,413,408 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SC268K5V.DEFAULT\EXTENSIONS\{C45C406E-AB73-11D8-BE73-000A95BE3B12}.XPI
[2012/04/26 10:05:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/06/17 00:24:22 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/04/20 20:18:25 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/20 20:18:25 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2008/08/21 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DKgPKMxgvSnGH.exe] C:\Documents and Settings\All Users\Application Data\DKgPKMxgvSnGH.exe File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Nero MediaHome 4] C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe (Nero AG)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe ()
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([update] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: spywarehelpcenter.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{709D542D-75D9-4D22-AB96-42A9DA690C8C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/04/23 22:54:07 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/30 17:55:29 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
[2012/06/29 11:56:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Local Settings\Application Data\Identities
[2012/06/28 20:24:37 | 016,208,824 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Dan\My Documents\Windows-KB890830-V4.9.exe
[2012/06/28 12:21:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Apple Software Update
[2012/06/28 12:19:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Analog Devices
[2012/06/28 12:13:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Adobe
[2012/06/28 12:11:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Xvid
[2012/06/28 12:09:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Windows Media Player
[2012/06/28 12:05:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Application Data\Nero
[2012/06/28 12:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\PDF Complete
[2012/06/28 11:54:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Mozilla Firefox
[2012/06/28 11:53:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Movie Maker
[2012/06/28 11:46:22 | 000,000,000 | R–D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Games
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\SoundMAX
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Sonic
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\QuickTime
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Nero
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Microsoft Silverlight
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Microsoft Office
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\iTunes
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\EPSON
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Broadcom
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\ArcSoft Print Creations
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\ArcSoft Connect
[2012/06/27 18:30:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\Dan\Recent
[2012/06/26 20:27:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Local Settings
[2012/06/25 00:00:17 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2012/06/14 12:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/06/14 12:00:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/12 21:01:52 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2012/05/09 01:08:31 | 006,955,968 | —- | C] (Microsoft Corporation) – C:\Program Files\Silverlight.exe
[2012/04/26 10:04:03 | 000,908,576 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\jxpiinstall.exe
[2012/04/25 11:35:23 | 006,674,008 | —- | C] (Adobe Systems Inc.) – C:\Program Files\Shockwave_Installer_Slim.exe
[2012/04/25 10:38:50 | 010,288,512 | —- | C] (Microsoft Corporation) – C:\Program Files\mseinstall.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/30 17:55:45 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
[2012/06/30 17:15:16 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/30 17:04:03 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/06/30 16:58:25 | 000,552,080 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/30 16:58:25 | 000,104,212 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/30 16:54:45 | 000,013,726 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/30 16:53:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/28 20:24:44 | 016,208,824 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Dan\My Documents\Windows-KB890830-V4.9.exe
[2012/06/27 22:24:05 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/06/27 22:07:04 | 000,000,831 | —- | M] () – C:\WINDOWS\Cpqdiag.ini
[2012/06/26 22:13:25 | 000,196,960 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/23 09:15:13 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/23 09:15:13 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/06/21 07:27:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/14 12:02:35 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/12 21:21:42 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/02 15:19:44 | 000,022,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wucltui.dll
[2012/06/02 15:19:38 | 000,219,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2012/06/02 15:19:38 | 000,210,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuweb.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cdm.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cdm.dll
[2012/06/02 15:19:34 | 000,053,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuauclt.exe
[2012/06/02 15:19:34 | 000,045,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2012/06/02 15:19:34 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2012/06/02 15:19:34 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wups.dll
[2012/06/02 15:19:34 | 000,015,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuapi.dll
[2012/06/02 15:19:18 | 001,933,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuaueng.dll
[2012/06/02 15:18:58 | 000,275,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/06/02 15:18:58 | 000,017,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/30 16:49:04 | 000,654,920 | —- | C] () – C:\Documents and Settings\Dan\My Documents\mtinst.exe
[2012/06/27 22:23:40 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/06/14 12:02:35 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/05/15 00:21:28 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2012/05/09 09:48:32 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2012/05/09 09:48:32 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2012/05/07 00:05:55 | 000,004,608 | —- | C] () – C:\Documents and Settings\Dan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/26 11:34:57 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2012/04/26 11:34:57 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2012/04/26 11:34:57 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2012/04/26 11:34:57 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2012/04/26 11:34:57 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2012/04/26 11:34:57 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2012/04/26 11:34:57 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2012/04/26 11:34:57 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2012/04/26 11:34:57 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2012/04/26 11:34:57 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2012/04/26 11:34:57 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2012/04/26 11:34:57 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2012/04/26 11:34:57 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2012/04/26 11:34:57 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2012/04/26 11:34:57 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2012/04/26 11:34:57 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2012/04/26 11:33:26 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSNX400.ini
[2012/04/26 11:01:04 | 000,001,807 | —- | C] () – C:\WINDOWS\ACT_CFG.INI
[2012/04/26 11:00:52 | 000,019,845 | —- | C] () – C:\WINDOWS\System32\drivers\Cpqdfw.sys
[2012/04/26 11:00:52 | 000,000,831 | —- | C] () – C:\WINDOWS\Cpqdiag.ini
[2012/04/26 10:32:30 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2012/04/26 01:41:10 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2012/04/26 01:41:09 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2012/04/26 01:40:23 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2012/04/26 01:40:22 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2012/04/26 01:40:20 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2012/04/25 23:00:25 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2012/04/25 09:47:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/04/24 00:25:07 | 000,000,664 | —- | C] () – C:\Documents and Settings\Dan\Local Settings\Application Data\FASTWiz.html
[2012/04/24 00:11:45 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/04/23 22:51:04 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/04/23 17:42:32 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/04/22 18:44:52 | 000,196,960 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2012/04/26 11:34:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2012/06/30 00:53:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PDFC
[2012/05/07 22:06:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/27 10:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\EPSON
[2012/04/26 11:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Leadertech
[2012/04/26 20:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\SystemRequirementsLab
[2012/04/26 00:10:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Windows Desktop Search
[2012/04/26 00:32:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/04/23 22:54:07 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2012/04/23 22:48:49 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012/04/23 22:54:07 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2012/04/23 22:54:07 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/04/23 22:54:07 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/06/30 16:53:50 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012/04/23 22:53:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2012/04/24 01:03:41 | 000,001,722 | —- | M] () – C:\Documents and Settings\Dan\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2012/04/26 10:04:11 | 000,908,576 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\jxpiinstall.exe
[2012/04/25 10:39:01 | 010,288,512 | —- | M] (Microsoft Corporation) – C:\Program Files\mseinstall.exe
[2012/04/25 11:35:35 | 006,674,008 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Shockwave_Installer_Slim.exe
[2012/05/09 01:08:43 | 006,955,968 | —- | M] (Microsoft Corporation) – C:\Program Files\Silverlight.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2012/04/22 18:42:56 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012/04/22 18:42:56 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012/04/22 18:42:56 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/06/30 17:55:45 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-13 02:35:31
< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/06/27 09:50:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp
[2012/06/27 09:50:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp\1
[2012/06/27 10:25:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp\2
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/08/21 07:00:00 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/08/21 07:00:00 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/06/30 17:25:31 | 000,018,630 | —- | M] () MD5=26F0EE6F9D37AB1D128C88CC21F9A52D – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
< MD5 for: EXPLORER.SCF >
[2008/08/21 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/08/21 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2008/08/21 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -HS- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.HLP >
[2008/08/21 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EXE >
[2008/08/21 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/08/21 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\mspaint.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\b57xp32.sys:SummaryInformation
< End of report >
I appreciate all patience and any further guidance in advance !
I am definitely a newbie with computers, but I have learned/taught myself lots pretty quickly.
There is a virus going around that has many names i.e. (Windows Recovery, Windows AntiVirus 2012) where all desktop icons are missing, startup menu is empty, administrative tools are empty, desktop background is blue, and constant windows are popping up saying there are 14 or more viruses found, and immediate action needs to be taken, and leads you to nothing but an order form screen…..
I have restored my desktop icons, and most of my startup menu, and administrative tools. System Recovery was not able to load/restore from any of the points chosen (I read this tool is disabled from this virus). I was able copy some of my programs shortcuts to the programs list, but I am still missing several tools/programs. I use Microsoft Security Essentials, and the Windows Malicious Software Removal Tool. Both have ran, and only MSE has came up with several viruses/trojans/etc, and removed them. I read from a previous blog titled "Trojan on my Computer [Solved]" on how to start the malware removal.
I was only able to download and run OTL.exe. The tool aswMBR.exe would download, but would not open. I tried "run as Administrator", disabling anti-virus/firewall, and renaming the application, but nothing would work.
Here are my attached OTL.txt and Extras.txt
OTL logfile created on: 6/30/2012 6:02:55 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\Dan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.99% Memory free
3.84 Gb Paging File | 3.46 Gb Available in Paging File | 90.01% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.68 Gb Total Space | 19.71 Gb Free Space | 58.52% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: DEHAHN | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dan\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NeroMediaHomeService.4) – C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
SRV - (pdfcDispatcher) – C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (tfsnudfa) – system32\dla\tfsnudfa.sys File not found
DRV - (tfsnudf) – system32\dla\tfsnudf.sys File not found
DRV - (tfsnpool) – system32\dla\tfsnpool.sys File not found
DRV - (tfsnopio) – system32\dla\tfsnopio.sys File not found
DRV - (tfsnifs) – system32\dla\tfsnifs.sys File not found
DRV - (tfsndres) – system32\dla\tfsndres.sys File not found
DRV - (tfsndrct) – system32\dla\tfsndrct.sys File not found
DRV - (tfsncofs) – system32\dla\tfsncofs.sys File not found
DRV - (tfsnboio) – system32\dla\tfsnboio.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (MpKsld6d34de9) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{298A0275-4F3A-4DCB-95AE-321EED411A49}\MpKsld6d34de9.sys (Microsoft Corporation)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (BANTExt) – C:\WINDOWS\system32\drivers\BANTExt.sys ()
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (Blfp) – C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)
DRV - (cpqdfw) – C:\WINDOWS\system32\drivers\Cpqdfw.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/17 00:24:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/04/25 11:02:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dan\Application Data\Mozilla\Extensions
[2012/05/01 21:41:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\sc268k5v.default\extensions
[2012/06/13 22:08:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/26 23:31:06 | 000,413,408 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SC268K5V.DEFAULT\EXTENSIONS\{C45C406E-AB73-11D8-BE73-000A95BE3B12}.XPI
[2012/04/26 10:05:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/06/17 00:24:22 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/04/20 20:18:25 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/20 20:18:25 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2008/08/21 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DKgPKMxgvSnGH.exe] C:\Documents and Settings\All Users\Application Data\DKgPKMxgvSnGH.exe File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Nero MediaHome 4] C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe (Nero AG)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe ()
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([update] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: spywarehelpcenter.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{709D542D-75D9-4D22-AB96-42A9DA690C8C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/04/23 22:54:07 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/30 17:55:29 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
[2012/06/29 11:56:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Local Settings\Application Data\Identities
[2012/06/28 20:24:37 | 016,208,824 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Dan\My Documents\Windows-KB890830-V4.9.exe
[2012/06/28 12:21:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Apple Software Update
[2012/06/28 12:19:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Analog Devices
[2012/06/28 12:13:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Adobe
[2012/06/28 12:11:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Xvid
[2012/06/28 12:09:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Windows Media Player
[2012/06/28 12:05:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Application Data\Nero
[2012/06/28 12:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\PDF Complete
[2012/06/28 11:54:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Mozilla Firefox
[2012/06/28 11:53:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Movie Maker
[2012/06/28 11:46:22 | 000,000,000 | R–D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Games
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\SoundMAX
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Sonic
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\QuickTime
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Nero
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Microsoft Silverlight
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Microsoft Office
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\iTunes
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\EPSON
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Broadcom
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\ArcSoft Print Creations
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\ArcSoft Connect
[2012/06/27 18:30:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\Dan\Recent
[2012/06/26 20:27:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Local Settings
[2012/06/25 00:00:17 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2012/06/14 12:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/06/14 12:00:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/12 21:01:52 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2012/05/09 01:08:31 | 006,955,968 | —- | C] (Microsoft Corporation) – C:\Program Files\Silverlight.exe
[2012/04/26 10:04:03 | 000,908,576 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\jxpiinstall.exe
[2012/04/25 11:35:23 | 006,674,008 | —- | C] (Adobe Systems Inc.) – C:\Program Files\Shockwave_Installer_Slim.exe
[2012/04/25 10:38:50 | 010,288,512 | —- | C] (Microsoft Corporation) – C:\Program Files\mseinstall.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/30 17:55:45 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
[2012/06/30 17:15:16 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/30 17:04:03 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/06/30 16:58:25 | 000,552,080 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/30 16:58:25 | 000,104,212 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/30 16:54:45 | 000,013,726 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/30 16:53:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/28 20:24:44 | 016,208,824 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Dan\My Documents\Windows-KB890830-V4.9.exe
[2012/06/27 22:24:05 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/06/27 22:07:04 | 000,000,831 | —- | M] () – C:\WINDOWS\Cpqdiag.ini
[2012/06/26 22:13:25 | 000,196,960 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/23 09:15:13 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/23 09:15:13 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/06/21 07:27:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/14 12:02:35 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/12 21:21:42 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/02 15:19:44 | 000,022,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wucltui.dll
[2012/06/02 15:19:38 | 000,219,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2012/06/02 15:19:38 | 000,210,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuweb.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cdm.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cdm.dll
[2012/06/02 15:19:34 | 000,053,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuauclt.exe
[2012/06/02 15:19:34 | 000,045,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2012/06/02 15:19:34 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2012/06/02 15:19:34 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wups.dll
[2012/06/02 15:19:34 | 000,015,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuapi.dll
[2012/06/02 15:19:18 | 001,933,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuaueng.dll
[2012/06/02 15:18:58 | 000,275,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/06/02 15:18:58 | 000,017,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/30 16:49:04 | 000,654,920 | —- | C] () – C:\Documents and Settings\Dan\My Documents\mtinst.exe
[2012/06/27 22:23:40 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/06/14 12:02:35 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/05/15 00:21:28 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2012/05/09 09:48:32 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2012/05/09 09:48:32 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2012/05/07 00:05:55 | 000,004,608 | —- | C] () – C:\Documents and Settings\Dan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/26 11:34:57 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2012/04/26 11:34:57 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2012/04/26 11:34:57 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2012/04/26 11:34:57 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2012/04/26 11:34:57 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2012/04/26 11:34:57 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2012/04/26 11:34:57 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2012/04/26 11:34:57 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2012/04/26 11:34:57 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2012/04/26 11:34:57 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2012/04/26 11:34:57 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2012/04/26 11:34:57 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2012/04/26 11:34:57 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2012/04/26 11:34:57 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2012/04/26 11:34:57 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2012/04/26 11:34:57 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2012/04/26 11:33:26 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSNX400.ini
[2012/04/26 11:01:04 | 000,001,807 | —- | C] () – C:\WINDOWS\ACT_CFG.INI
[2012/04/26 11:00:52 | 000,019,845 | —- | C] () – C:\WINDOWS\System32\drivers\Cpqdfw.sys
[2012/04/26 11:00:52 | 000,000,831 | —- | C] () – C:\WINDOWS\Cpqdiag.ini
[2012/04/26 10:32:30 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2012/04/26 01:41:10 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2012/04/26 01:41:09 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2012/04/26 01:40:23 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2012/04/26 01:40:22 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2012/04/26 01:40:20 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2012/04/25 23:00:25 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2012/04/25 09:47:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/04/24 00:25:07 | 000,000,664 | —- | C] () – C:\Documents and Settings\Dan\Local Settings\Application Data\FASTWiz.html
[2012/04/24 00:11:45 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/04/23 22:51:04 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/04/23 17:42:32 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/04/22 18:44:52 | 000,196,960 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2012/04/26 11:34:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2012/06/30 00:53:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PDFC
[2012/05/07 22:06:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/27 10:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\EPSON
[2012/04/26 11:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Leadertech
[2012/04/26 20:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\SystemRequirementsLab
[2012/04/26 00:10:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Windows Desktop Search
[2012/04/26 00:32:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/04/23 22:54:07 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2012/04/23 22:48:49 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012/04/23 22:54:07 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2012/04/23 22:54:07 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/04/23 22:54:07 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/06/30 16:53:50 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012/04/23 22:53:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2012/04/24 01:03:41 | 000,001,722 | —- | M] () – C:\Documents and Settings\Dan\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2012/04/26 10:04:11 | 000,908,576 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\jxpiinstall.exe
[2012/04/25 10:39:01 | 010,288,512 | —- | M] (Microsoft Corporation) – C:\Program Files\mseinstall.exe
[2012/04/25 11:35:35 | 006,674,008 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Shockwave_Installer_Slim.exe
[2012/05/09 01:08:43 | 006,955,968 | —- | M] (Microsoft Corporation) – C:\Program Files\Silverlight.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2012/04/22 18:42:56 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012/04/22 18:42:56 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012/04/22 18:42:56 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/06/30 17:55:45 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-13 02:35:31
< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/06/27 09:50:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp
[2012/06/27 09:50:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp\1
[2012/06/27 10:25:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp\2
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/08/21 07:00:00 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/08/21 07:00:00 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/06/30 17:25:31 | 000,018,630 | —- | M] () MD5=26F0EE6F9D37AB1D128C88CC21F9A52D – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
< MD5 for: EXPLORER.SCF >
[2008/08/21 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/08/21 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2008/08/21 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -HS- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.HLP >
[2008/08/21 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EXE >
[2008/08/21 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/08/21 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\mspaint.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\b57xp32.sys:SummaryInformation
< End of report >