Mikepcap
Topic Starter
I'd really appreciate any help you all can give me on this.
Not sure how long I've had this virus, the only symptoms I can see is that whenever I try to update Malwarebytes (which I've had for years - I also have F-Secure running at all times), or access any page on microsoft.com (and a few other random sites dealing with virus detection/cure) it sends me to the URL with the domain portion switched to google.com, resulting in a 404 error page. This happens on Firefox, MSIE AND Chrome. I ran both the FULL F-Secure and Malwarebytes scans and each found a couple viruses and fixed them, but neither seemed to have fixed this. Also have had trouble with my WD Passport Backup drive (Drive J:) getting errors and having to stop, for a couple of months now, but don't think it is related to this. In fact it was while trying to download new software to fix that, that I first noticed I could not get to microsoft.
I read another similar thread on this forum where the advisor requested running Gooredfix, so here is the result from that first (followed by the OTL results):
GooredFix by jpshortstuff (03.07.10.1)
Log created at 12:29 on 24/12/2012 (Owner)
Firefox version 16.0.2 (en-US)
========== GooredScan ==========
========== GooredLog ==========
C:\Program Files\Mozilla Firefox\extensions\
{3112ca9c-de6d-4884-a869-9855de68056c} [14:40 05/12/2012]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [14:40 05/12/2012]
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [00:11 03/12/2012]
{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [03:06 15/12/2011]
{99079a25-328f-4bd4-be04-00955acaa0a7}(2) [11:20 16/12/2011]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"[removed]"="C:\Program Files\CenturyLink Online Security\NRS\[removed]" [22:51 16/04/2011]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [22:57 15/11/2010]
"{0153E448-190B-4987-BDE1-F256CADA672F}"="C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [22:57 15/11/2010]
-=E.O.F=-
============================================================
I also ran OLT as requested by the new submission page (it took over 2 hours!) Here are the results from that:
==============================================================
OTL Extras logfile created on: 12/24/2012 12:49:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 43.70% Memory free
3.72 Gb Paging File | 2.98 Gb Available in Paging File | 80.14% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 0.81 Gb Free Space | 0.91% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.26 Gb Free Space | 99.72% Space Free | Partition Type: NTFS
Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00626135-E60A-4550-9503-4F50C6C9B8BB}" = Google AdWords Editor
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{0673654C-5296-453B-9798-B61CD7E03FEB}" = SES Driver
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{07D4701F-50D6-4C69-A785-DC556E60663F}" = Eudora
"{08F7CCA6-8590-4401-8B44-CEB09A909AAB}" = del.icio.us Buttons for Internet Explorer
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2522EE78-994E-45C8-9CE5-CE6CB2E0297F}" = Map of North and Central America
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{2FD94FBC-07AE-475C-B522-BFE899B9048E}" = Garmin WebUpdater
"{3004FB81-7B9E-4808-BD13-BC5A530BA60B}" = cp_PrintOnCDConfig
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{31492759-0E89-46B5-9770-F6E5808E3017}" = xImage
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{40631ADD-7633-F1F1-32D2-D1FB6374BAFB}" = Market Samurai
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{4FC9DA9D-F608-454E-8191-D7EFFDCC5726}" = SpyHunter
"{523BD5B6-E904-493C-B902-1BC9B7D44DF4}" = Lexmark Photo Center
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53AF3638-DDB4-4755-B3DC-259981689DB7}" = MioNet
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68131B0A-D78D-4aed-B74E-33A6C7324E50}" = WD Anywhere Backup
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6EEE2F18-AF5C-4E49-9C5B-F6ACC39B2F0E}" = FTP Explorer
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{79ED0EE7-098C-465F-A853-B17F6FC6CDD8}" = GPS TrackMaker
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{80A2A967-C1B7-412D-B2B2-C4A33209C205}" = Garmin POI Loader
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{84F1DE76-C48C-4281-87A0-CC9548D1E7F9}" = Rhapsody Player Engine
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98D451C4-4ACA-4273-BB47-57CFE46B048E}" = WD SmartWare
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B27901FA-F157-4049-B1EC-BC43890A1DCC}" = Active@ File Recovery
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BB7C0C8E-CF0B-44C5-B838-9ED93D15DBDF}" = Map of South America
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C012BF9F-79EA-4601-9778-BFE9B3CE83A1}" = hpg3010QFolder
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB71FF8-DE82-469C-8641-44378F4443EB}" = Garmin WebUpdater
"{CCD04643-5246-48AC-9D8C-F43A37BB8F36}" = WD Drive Manager (x86)
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E2C5C0D1-B4F7-4C1C-9AEF-C80E17677052}" = hpg3010
"{E2E7A0E8-77C4-495F-8FA3-63DAEDAA2DB3}" = F-Secure PSC Prerequisites
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F64D55C1-734C-4249-886E-4C41A9889A36}" = HP Scanjet G3010 7.0
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Acoustica MP3 Audio Mixer" = Acoustica MP3 Audio Mixer
"Actual Search & Replace_is1" = Actual Search & Replace Version 2.8.2
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Alexa Toolbar" = Alexa Toolbar
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"ASTRA32_is1" = ASTRA32 - Advanced System Information Tool 1.52
"Capitalism Plus" = Capitalism Plus
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"CoffeeCup HTML Editor 2008" = CoffeeCup HTML Editor 2008
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"EasyGPS_is1" = EasyGPS
"ExpressBurn" = Express Burn
"ExpressRip" = Express Rip
"ExtraPuTTY 0.24" = ExtraPuTTY 0.24
"Free RAR Extract Frog 1.00" = Free RAR Extract Frog 1.00
"F-Secure Product 444" = CenturyLink™ Online Security
"FTP Explorer" = FTP Explorer
"getPlus®_ocx" = getPlus®_ocx
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"HTML Search and Replace_is1" = HTML Search and Replace 1.0
"IconForge version 6.28_is1" = IconForge version 6.28
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{523BD5B6-E904-493C-B902-1BC9B7D44DF4}" = Lexmark Photo Center
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"Lexmark S300-S400 Series" = Lexmark S300-S400 Series
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1" = Market Samurai
"MasterClipsDeinstKey" = MasterClips Browser v2.03
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"Motherboard Monitor 5_is1" = Motherboard Monitor 5
"Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa2" = Picasa 2
"PlayBox" = PlayBox Toolbar
"Port Magic" = Pure Networks Port Magic
"RealPlayer 15.0" = RealPlayer
"Samsung CLP-320 Series" = Maintenance Samsung CLP-320 Series
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"Ulead PhotoImpact 5.0" = Ulead PhotoImpact 5
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xenu's Link Sleuth" = Xenu's Link Sleuth
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 12/23/2012 2:33:57 AM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2012-12-22 22:33:57-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
No scanner engines loaded and enabled. Virus protection is disabled.
Error - 12/23/2012 6:13:34 AM | Computer Name = MIKE | Source = Application Error | ID = 1000
Description = Faulting application wddmstatus.exe, version 3.1.0.11, faulting module
upnp.dll, version 5.1.2600.2180, fault address 0x0000e896.
Error - 12/23/2012 7:47:58 AM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 1 2012-12-23 03:47:54-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
Malicious code found in file C:\WINDOWS\Temp\USS1052.tmp. Infection: Gen:Variant.Barys.536
Error - 12/23/2012 12:03:21 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2012-12-23 08:03:21-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
No scanner engines loaded and enabled. Virus protection is disabled.
Error - 12/23/2012 12:18:55 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 3 2012-12-23 08:18:55-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
Malicious code found in file C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1102\A0309754.sys.
Infection: Gen:Variant.Barys.536 Action: The file was quarantined.
Error - 12/23/2012 6:26:32 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 4 2012-12-23 14:26:32-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
Manual scanning was finished - workstation was found infected!
Error - 12/23/2012 8:33:18 PM | Computer Name = MIKE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000
Description = Faulting application wdsmartware.exe, version 1.4.1.1, stamp 4c87cbb7,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug? 0,
fault address 0x00012a5b.
Error - 12/23/2012 10:35:44 PM | Computer Name = MIKE | Source = MsiInstaller | ID = 10005
Description = Product: WD Software Upgrader – This application requires Microsoft
.NET Framework 4.0 client profile. Install the .NET Framework then run this installer
again.
Error - 12/24/2012 12:55:26 AM | Computer Name = MIKE | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.62.0.140, faulting module
version.dll, version 5.1.2600.2180, fault address 0x00001deb.
Error - 12/24/2012 3:59:14 PM | Computer Name = MIKE | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeobackup.exe, P2 2.0.0.0, P3 491494cf, P4
mscorlib, P5 2.0.0.0, P6 471ebc5b, P7 3404, P8 15a, P9 system.unauthorizedaccess,
P10 NIL.
[ System Events ]
Error - 12/24/2012 5:52:51 AM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =
Error - 12/24/2012 5:54:33 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
Error - 12/24/2012 5:54:33 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053
Error - 12/24/2012 5:54:34 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
Error - 12/24/2012 6:22:16 AM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =
Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Image Acquisition
(WIA) service to connect.
Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7000
Description = The Windows Image Acquisition (WIA) service failed to start due to
the following error: %%1053
Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
gagp30kx
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
Error - 12/24/2012 4:10:55 PM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =
Error - 12/24/2012 4:12:23 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
< End of report >
================================================================================
=
OTL logfile created on: 12/24/2012 12:49:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 43.70% Memory free
3.72 Gb Paging File | 2.98 Gb Available in Paging File | 80.14% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 0.81 Gb Free Space | 0.91% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.26 Gb Free Space | 99.72% Space Free | Partition Type: NTFS
Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeaserv.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\lxeacoms.exe ( )
PRC - C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackup.exe (Memeo Inc.)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\VTTrayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\sst3cl3.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\hashlib_x86.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fm4av.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\System.Data.SQLite.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epoemdll.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epstring.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizres.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizard.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\customui.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epfunct.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\eputil.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\imagutil.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeascw.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeamicro.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Spam Control\fsas.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSPC\fspcfsm.eng ()
MOD - \\?\c:\program files\centurylink online security\hips\fsumi.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\strres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\gres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\flyerres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\fsavures.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\about.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\aboutres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsavhres.eng ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeadatr.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeaptp.dll ()
MOD - C:\WINDOWS\system32\lxeasmr.dll ()
MOD - C:\WINDOWS\system32\lxeasm.dll ()
MOD - C:\Program Files\WD\WD Anywhere Backup\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\29c7192327cf3999961560bf3a3995c6\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL ()
MOD - C:\WINDOWS\system32\CISPMON.DLL ()
========== Services (SafeList) ==========
SRV - (napagent) – %SystemRoot%\System32\qagentrt.dll File not found
SRV - (hkmsvc) – %SystemRoot%\System32\kmsvc.dll File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (EapHost) – %SystemRoot%\System32\eapsvc.dll File not found
SRV - (Dot3svc) – %SystemRoot%\System32\dot3svc.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (FSORSPClient) – C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (lxeaCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (lxea_device) – C:\WINDOWS\system32\lxeacoms.exe ( )
SRV - (FSMA) – C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) – C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (MemeoBackgroundService) – C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
SRV - (MioNet) – C:\Program Files\MioNet\MioNetManager.exe ()
SRV - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Driver Services (SafeList) ==========
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (F-Secure Gatekeeper) – C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\fsgk.sys ()
DRV - (fsbts) – C:\WINDOWS\system32\drivers\fsbts.sys ()
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (F-Secure HIPS) – C:\Program Files\CenturyLink Online Security\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (FSFW) – C:\WINDOWS\system32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (F-Secure Filter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsfilter.sys ()
DRV - (F-Secure Recognizer) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsrec.sys ()
DRV - (NDISRD) – C:\WINDOWS\System32\drivers\ndisrd.sys (NT Kernel Resources)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ASTRA32) – C:\Program Files\ASTRA32\astra32.sys (Licensed for Sysinfo Lab)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mbmiodrvr) – C:\WINDOWS\system32\mbmiodrvr.sys ([removed])
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {39170861-6644-4F57-95E4-17683AFA09F4}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{39170861-6644-4F57-95E4-17683AFA09F4}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGIT_en
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Twitter"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4
FF - prefs.js..extensions.enabledAddons: %7B8f8fe09b-0bd3-4470-bc1b-8cad42b8203a%7D:0.17
FF - prefs.js..extensions.enabledAddons: %7B0153E448-190B-4987-BDE1-F256CADA672F%7D:15.0.6
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=119&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\3.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=1.0: C:\Program Files\Virtual Earth 3D\ [2007/05/17 16:50:24 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CenturyLink Online Security\NRS\[removed] [2011/05/30 16:21:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/05 06:41:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/05 06:40:57 | 000,000,000 | —D | M]
[2011/12/16 03:20:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/10/03 22:39:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/12/19 03:12:42 | 000,000,000 | —D | M] (Live HTTP Headers) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2011/12/19 03:12:02 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}(2)
[2012/11/20 12:25:46 | 000,243,496 | —- | M] () (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\searchplugins\Search_Results.xml
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012/10/11 14:15:02 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/12/05 06:41:44 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 13:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 13:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/10/11 14:13:20 | 000,129,176 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/09/21 00:45:46 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012/10/13 05:23:37 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.searchqu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Alexa Traffic Rank = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel\1.1.0_0\
CHR - Extension: KOCAttack - Extra Features! = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbbngjfcccafhimngmokmoejfdcjepgc\0.9.1_1\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
O1 HOSTS File: ([2012/03/13 19:42:32 | 000,244,641 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8540 more lines…
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O2 - BHO: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O2 - BHO: (del.icio.us Toolbar Helper) - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKLM\..\Toolbar: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKLM\..\Toolbar: (Alexa Toolbar) - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files\Alexa Toolbar\AlexaToolbar.10.0.dll (Alexa.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKCU\..\Toolbar\WebBrowser: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\CenturyLink Online Security\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [WD Anywhere Backup] C:\Program Files\WD\WD Anywhere Backup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKCU..\Run: [Siufsyut] C:\Documents and Settings\Owner\Application Data\Yzly\cygia.exe (Корпорация Майкрософт)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: samsungsetup.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase9563.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1165369289625 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75A8BD71-DED9-4086-856F-C1CA51592ECB}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\toolbarchrome {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 10:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{977d7f84-a735-11df-89b4-00038a000015}\Shell\AutoRun\command - "" = K:\setup.exe
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{d8a3e2f8-2abb-11e2-8a4e-00038a000015}\Shell\AutoRun\command - "" = K:\WDSetup.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: napagent - %SystemRoot%\System32\qagentrt.dll File not found
NetSvcs: hkmsvc - %SystemRoot%\System32\kmsvc.dll File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/12/24 12:42:16 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GooredFix Backups
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Yzly
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Akvea
[2012/12/05 06:40:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2008/04/09 17:23:24 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/12/24 13:28:03 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:09:15 | 000,000,412 | —- | M] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/24 12:05:03 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/24 12:04:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/24 12:04:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/12/24 12:04:14 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/24 11:47:01 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2012/12/24 03:29:10 | 000,004,442 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2012/12/24 01:50:54 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/12/24 01:19:09 | 000,000,402 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/24 00:02:28 | 000,000,508 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2012/12/23 22:17:02 | 000,000,406 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/23 16:46:27 | 000,000,600 | —- | M] () – C:\Documents and Settings\Owner\PUTTY.RND
[2012/12/23 16:12:33 | 000,002,243 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FTP Explorer.lnk
[2012/12/23 15:26:43 | 000,023,972 | —- | M] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2012/12/22 03:09:29 | 000,000,030 | —- | M] () – C:\WINDOWS\Iedit.INI
[2012/12/21 15:28:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/12/20 15:19:03 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/20 01:32:18 | 000,002,752 | —- | M] () – C:\WINDOWS\MAML.INI
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2012/12/13 12:43:48 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/12/13 03:08:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/11 15:30:07 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/12/11 15:30:06 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/12/10 03:39:00 | 000,000,330 | —- | M] () – C:\WINDOWS\tasks\jucheck.job
[2012/12/03 19:10:31 | 000,003,325 | —- | M] () – C:\Documents and Settings\All Users\Documents\shows-copyscape.htm
[2012/12/03 16:26:38 | 000,003,075 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:41:58 | 000,072,797 | —- | M] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/12/01 16:30:56 | 000,001,579 | —- | M] () – C:\Documents and Settings\Owner\My Documents\coupon-form.rtf
[2012/11/28 18:26:55 | 000,000,879 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/18 01:10:01 | 000,000,412 | —- | C] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/18 01:09:54 | 000,000,406 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/18 01:09:51 | 000,000,402 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/09 00:00:53 | 000,452,508 | —- | C] () – C:\error.fstmp
[2012/12/09 00:00:53 | 000,000,000 | —- | C] () – C:\infect.fstmp
[2012/12/03 16:26:38 | 000,003,075 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:44:44 | 000,072,797 | —- | C] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/11/28 18:26:55 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[2012/11/28 18:26:46 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Copy of WordPad.lnk
[2012/07/25 15:12:16 | 000,109,312 | —- | C] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.BAT
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.~BA
[2012/04/09 22:49:40 | 000,060,228 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2012/03/29 00:58:50 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/01/14 15:38:12 | 000,008,703 | —- | C] () – C:\Documents and Settings\All Users\Application Data\7aa1ff29
[2012/01/14 15:38:12 | 000,008,693 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\9c228de1
[2012/01/14 15:38:12 | 000,008,629 | —- | C] () – C:\Documents and Settings\Owner\Application Data\f739919
[2011/09/29 11:45:08 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\sst3cl3.dll
[2011/08/20 13:42:15 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\lxeasm.dll
[2011/08/20 13:42:15 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\lxeasmr.dll
[2011/08/20 13:42:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxeavs.dll
[2011/08/20 13:42:11 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoin.dll
[2011/08/20 13:42:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\lxeagcfg.dll
[2011/08/20 13:42:00 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxeacui.dll
[2011/08/20 13:42:00 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\lxeacuir.dll
[2011/08/20 13:38:30 | 000,847,872 | —- | C] ( ) – C:\WINDOWS\System32\lxeausb1.dll
[2011/08/20 13:38:30 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxeainpa.dll
[2011/08/20 13:38:30 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\LXEAhcp.dll
[2011/08/20 13:38:30 | 000,344,064 | —- | C] ( ) – C:\WINDOWS\System32\lxeaiesc.dll
[2011/08/20 13:38:30 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\LXEAinst.dll
[2011/08/20 13:38:29 | 001,048,576 | —- | C] ( ) – C:\WINDOWS\System32\lxeaserv.dll
[2011/08/20 13:38:29 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxeapmui.dll
[2011/08/20 13:38:28 | 000,577,536 | —- | C] ( ) – C:\WINDOWS\System32\lxealmpm.dll
[2011/08/20 13:38:28 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\lxeains.dll
[2011/08/20 13:38:28 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lxeainsb.dll
[2011/08/20 13:38:28 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lxeainsr.dll
[2011/08/20 13:38:28 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\lxeajswr.dll
[2011/08/20 13:38:27 | 000,688,128 | —- | C] ( ) – C:\WINDOWS\System32\lxeahbn3.dll
[2011/08/20 13:38:27 | 000,324,264 | —- | C] ( ) – C:\WINDOWS\System32\lxeaih.exe
[2011/08/20 13:38:27 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxeagrd.dll
[2011/08/20 13:38:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\lxeacu.dll
[2011/08/20 13:38:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\lxeacub.dll
[2011/08/20 13:38:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\lxeacur.dll
[2011/08/20 13:38:25 | 000,598,696 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoms.exe
[2011/08/20 13:38:24 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomm.dll
[2011/08/20 13:38:23 | 000,802,816 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomc.dll
[2011/08/20 13:38:23 | 000,373,416 | —- | C] ( ) – C:\WINDOWS\System32\lxeacfg.exe
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Compressor
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Command Line Utility
[2011/07/21 02:49:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2011/07/21 02:49:31 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Core Data Application
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 14:54:02 | 000,042,664 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 01:15:55 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/14 22:47:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Fqureh.dat
[2011/04/14 22:47:28 | 000,000,000 | —- | C] () – C:\WINDOWS\Tbovewipezupew.bin
[2009/10/19 14:15:11 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\PUTTY.RND
[2009/09/21 15:57:13 | 000,000,064 | —- | C] () – C:\Documents and Settings\Owner\setpath.bat
[2008/12/21 03:46:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Common
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Colors
[2008/12/16 17:52:18 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2008/12/16 17:52:18 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Configure Folder Actions
[2008/02/15 17:19:07 | 000,010,240 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/17 16:52:33 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/05/14 01:39:17 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/14 13:52:06 | 000,000,008 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.dat.bin
[2006/12/04 16:39:00 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\PUTTY.RND
[2006/12/04 16:38:00 | 000,356,352 | —- | C] () – C:\Program Files\putty.exe
[2006/12/03 17:04:02 | 000,023,972 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[2004/01/01 15:49:53 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = shell32.dll – [2007/10/25 19:34:01 | 008,460,288 | —- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2006/09/03 22:12:56 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2004/08/04 11:00:00 | 000,472,064 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2004/08/04 11:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/12/16 02:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/04/16 14:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2011/04/15 00:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fAk02400lLmCj02400
[2011/05/22 19:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2011/09/19 04:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lexmark S300-S400 Series
[2009/09/27 23:55:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2009/06/29 01:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2004/01/01 16:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/02/16 04:14:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/07/21 02:51:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/09/29 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2012/12/23 16:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/25 15:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/11/11 15:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2010/08/08 11:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/19 03:12:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B49A644A-1076-4A3D-B124-DAA7862F2318}
[2011/11/29 13:30:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Actual Search & Replace
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Akvea
[2008/06/26 09:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/10/23 14:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/28 01:29:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CursorArts
[2011/04/15 13:13:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Desktopicon
[2010/02/26 00:08:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/04/16 23:00:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F-Secure
[2012/12/24 02:04:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2010/01/31 23:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2009/12/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2012/04/09 18:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/08/23 02:11:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MioNet
[2009/06/29 01:05:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\muvee Technologies
[2010/02/16 05:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
[2011/07/21 02:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2010/01/24 16:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayBox
[2004/01/01 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2011/12/19 03:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchqutoolbar(2)
[2011/09/29 02:24:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Stellarium
[2006/12/03 17:04:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/05/25 15:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/09/30 16:17:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WD
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Yzly
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/04 11:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\WINDOWS\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[1998/05/11 19:01:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=7ADA6F7250F04A62D84A09373F1BBAE9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\WINDOWS\EXPLORER.EXE
[1998/05/11 19:01:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=7ADA6F7250F04A62D84A09373F1BBAE9 – C:\tribble2-backup-c\WINDOWS\EXPLORER.EXE
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\system32\dllcache\explorer.exe
[2004/08/04 11:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[1999/04/23 21:22:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=B22B28F61B1BB06723019307F0FAACFC – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\EXPLORER.EXE
[1999/04/23 22:22:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=B22B28F61B1BB06723019307F0FAACFC – C:\tribble2-backup-d\Office3\WINDOWS\EXPLORER.EXE
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/12/24 02:23:49 | 000,029,776 | —- | M] () MD5=F997F0D85F58421DA7CB8700FD005360 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SC_ >
[2004/08/04 11:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[1998/05/11 19:01:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\WINDOWS\EXPLORER.SCF
[1999/04/23 21:22:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\EXPLORER.SCF
[1998/05/11 19:01:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\tribble2-backup-c\WINDOWS\EXPLORER.SCF
[1999/04/23 22:22:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\tribble2-backup-d\Office3\WINDOWS\EXPLORER.SCF
[2004/08/04 11:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.001 >
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
< MD5 for: IEXPLORE.ASF >
[1996/04/26 16:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLEC\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 16:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 17:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\tribble2-backup-d\TRIBBLEC\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 17:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\tribble2-backup-d\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
< MD5 for: IEXPLORE.CH_ >
[2004/08/04 11:00:00 | 000,199,077 | —- | M] () MD5=5F64795662F162CCD8B30969B6682029 – C:\WINDOWS\I386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/04 11:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.CHW >
[2010/11/04 14:30:34 | 000,153,185 | —- | M] () MD5=F879E396E373F6BD74411EEA8FBF9E75 – C:\WINDOWS\Help\iexplore.chw
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 11:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\WINDOWS\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2007/04/24 06:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/04/22 00:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/04/21 23:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie8\iexplore.exe
[2007/12/06 03:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 00:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 00:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2007/08/17 02:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2006/10/17 12:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2007/08/17 02:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 16:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\iexplore.exe
[2007/10/10 00:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\tribble2-backup-c\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[2007/02/21 00:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 01:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2007/12/06 00:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 06:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2007/06/27 01:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2007/02/27 22:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2004/08/04 11:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2007/10/10 02:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2002/08/28 23:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=EB9EAF627F705525D01DE5FA07EA1818 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Internet Explorer\IEXPLORE.EXE
[2002/08/28 23:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=EB9EAF627F705525D01DE5FA07EA1818 – C:\tribble2-backup-c\Program Files\Internet Explorer\IEXPLORE.EXE
[1999/04/23 21:22:00 | 000,078,272 | —- | M] (Microsoft Corporation) MD5=F51690B7980BD05DB110FDCD1714688E – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\Program Files\Internet Explorer\IEXPLORE.EXE
[1999/04/23 22:22:00 | 000,078,272 | —- | M] (Microsoft Corporation) MD5=F51690B7980BD05DB110FDCD1714688E – C:\tribble2-backup-d\Office3\Program Files\Internet Explorer\IEXPLORE.EXE
< MD5 for: IEXPLORE.EXE.26E3AD32.INI.INUSE >
[2007/05/17 16:52:33 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory\iexplore.exe.26e3ad32.ini.inuse
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 17:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/12/23 18:59:41 | 000,106,880 | —- | M] () MD5=6C857BF7D0C08DB29AD1BAE13A276D56 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HL_ >
[2004/08/04 11:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2004/08/04 11:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: IEXPLORE.INI >
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
< MD5 for: SERVICES >
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 17:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK\SERVICES
[1993/10/09 17:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[2004/08/04 11:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 12:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-d\TRIBBLC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 12:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-d\TRIBBLEC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/02/27 23:06:00 | 000,001,238 | —- | M] () MD5=AC1EC38D56985CC93876FF9F05274012 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Netcomplete\SERVICES
[1995/02/27 23:06:00 | 000,001,238 | —- | M] () MD5=AC1EC38D56985CC93876FF9F05274012 – C:\tribble2-backup-c\Program Files\Netcomplete\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\SERVICES
[2000/02/04 10:28:42 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\RECYCLED\DC9.0\net\win98\services
[2000/02/24 09:35:36 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\RECYCLED\DC9.0\net\win98se\services
[1999/04/23 21:22:00 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\SERVICES
[2000/02/04 10:28:42 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-c\RECYCLED\DC9.0\net\win98\services
[2000/02/24 09:35:36 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-c\RECYCLED\DC9.0\net\win98se\services
[1999/04/23 22:22:00 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-d\Office3\WINDOWS\SERVICES
< MD5 for: SERVICES._ >
[2004/08/04 11:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\WINDOWS\I386\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 10:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\SERVICES._
[1996/06/27 10:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\SERVICES._
< MD5 for: SERVICES.CHM >
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit6\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit3\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit4\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit5\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit6\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit7\Services.chm
[2002/11/18 04:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\QuickBooks Basic\Services.chm
[2003/10/29 17:30:46 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\services.chm
[2003/10/29 17:30:44 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Services.chm
[2003/10/29 17:30:46 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\services.chm
[2003/10/29 17:30:44 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Services.chm
< MD5 for: SERVICES.CSS >
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Quickbooks-save\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 16:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\tribble2-backup-d\Quickbooks-save\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2003/05/30 00:03:06 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Components\Services\services.css
[2003/05/30 00:03:06 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Components\Services\services.css
[2004/05/14 19:49:46 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\tribble2-backup-d\intuit7\Components\Services\services.css
[2002/05/29 15:31:02 | 000,007,703 | —- | M] () MD5=75A6BA0742A7EB410A0AFB38A9A59D29 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Quickbooks-save\QuickBooks\Components\Services\services.css
[2002/05/29 16:31:02 | 000,007,703 | —- | M] () MD5=75A6BA0742A7EB410A0AFB38A9A59D29 – C:\tribble2-backup-d\Quickbooks-save\QuickBooks\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit3\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit4\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit5\Components\Services\services.css
[2002/10/15 14:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\QuickBooks Basic\Components\Services\services.css
[2004/11/09 23:43:02 | 000,011,525 | —- | M] () MD5=FF757041D7C3EBA68F0127402D174D27 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\Components\Services\services.css
[2004/11/09 23:43:02 | 000,011,525 | —- | M] () MD5=FF757041D7C3EBA68F0127402D174D27 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\Components\Services\services.css
< MD5 for: SERVICES.CV_ >
[1996/05/07 10:00:18 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\tribble2-backup-d\TRIBBLEC\TRIBBLED\WINFAX1\SERVICES.CV_
< MD5 for: SERVICES.DOC >
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\tribble2-backup-c\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
< MD5 for: SERVICES.EX_ >
[2004/08/04 11:00:00 | 000,049,955 | —- | M] () MD5=85A738BA493104ED103B26CADEB8B543 – C:\WINDOWS\I386\SERVICES.EX_
< MD5 for: SERVICES.EXE >
[2008/04/13 16:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\system32\dllcache\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.GIF >
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2012/02/04 19:44:22 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\websites\bestdotcom-premove-backup\lvmarket\services.gif
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\tribble2-backup-c\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
< MD5 for: SERVICES.HTM >
[2012/02/04 19:44:24 | 000,003,652 | —- | M] () MD5=18DB327C3EFBEB7421648AB07F21DE23 – C:\websites\bestdotcom-premove-backup\lvmarket\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\galleria\web\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\websites\galleria\web\services.htm
[2001/11/29 00:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2\websites\galleria\backup-051402\services.htm
[2001/11/29 00:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2\websites\galleria\web\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\websites\galleria\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\preslimo\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\mikes-backup\websites\preslimo\web\services.htm
[2002/09/23 13:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\tribble2\websites\preslimo\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\tribble2-backup-c\mikes-backup\websites\preslimo\web\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\preslimo\web\whatson\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\mikes-backup\websites\preslimo\web\whatson\services.htm
[2002/09/23 13:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2\websites\preslimo\web\whatson\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2-backup-c\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2-backup-c\mikes-backup\websites\preslimo\web\whatson\services.htm
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\tribble2-backup-c\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\IDI\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofce\IDI\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofce\IDI\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\tribble2-backup-c\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
< MD5 for: SERVICES.HTML >
[2001/10/22 13:07:10 | 000,004,043 | —- | M] () MD5=BB431A68F828197874960F469A96304E – C:\Program Files\CoffeeCup Software\templates\Resturant\services.html
< MD5 for: SERVICES.JPG >
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.JPG
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\mikes-backup\ofce\LVMARKET\SERVICES.JPG
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.JPG
< MD5 for: SERVICES.LIM >
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit6\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit3\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit4\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit5\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit6\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit7\Services.lim
[2002/11/15 17:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\QuickBooks Basic\Services.lim
[2003/10/29 17:30:58 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\services.lim
[2003/10/29 17:30:56 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Services.lim
[2003/10/29 17:30:58 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\services.lim
[2003/10/29 17:30:56 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Services.lim
< MD5 for: SERVICES.LNK >
[2004/08/26 10:04:45 | 000,001,602 | —- | M] () MD5=6EA8801235B7C68E8DFAA9C1B99BEDB2 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MS_ >
[2004/08/04 11:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\WINDOWS\I386\SERVICES.MS_
< MD5 for: SERVICES.MSC >
[2004/08/04 11:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.OLD >
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\GAL\SERVICES.OLD
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\mikes-backup\ofce\GAL\SERVICES.OLD
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\tribble2-backup-c\mikes-backup\ofce\GAL\SERVICES.OLD
< MD5 for: SERVICES.PNG >
[2008/03/27 04:42:50 | 000,003,143 | —- | M] () MD5=087ECCA024AB9A71D659CB6E4F910D2E – C:\Program Files\CoffeeCup Software\Graphics\plano\yellow\services.png
[2008/03/27 04:52:46 | 000,003,090 | —- | M] () MD5=1E9256F745C06682AFDCD57A5B038134 – C:\Program Files\CoffeeCup Software\Graphics\plano\orange\services.png
[2008/03/27 04:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files\CoffeeCup Software\Graphics\plano\red\services.png
[2008/03/27 05:06:18 | 000,003,208 | —- | M] () MD5=BF7751362552A6E38BD3E6A610ED9889 – C:\Program Files\CoffeeCup Software\Graphics\plano\violet\services.png
[2008/03/27 04:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files\CoffeeCup Software\Graphics\plano\blue\services.png
[2008/03/27 05:01:46 | 000,003,305 | —- | M] () MD5=CB54DD779139E4475AA92417CEB09846 – C:\Program Files\CoffeeCup Software\Graphics\plano\green\services.png
[2008/03/27 04:47:26 | 000,003,497 | —- | M] () MD5=F0AF7DB71281CC55799AB75203BFB664 – C:\Program Files\CoffeeCup Software\Graphics\plano\indigo\services.png
< MD5 for: SERVICES.SBS >
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\tribble2-backup-c\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: SERVICES.TIF >
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.TIF
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\mikes-backup\ofce\LVMARKET\SERVICES.TIF
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.TIF
< MD5 for: SERVICES.TXT >
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\SERVICES.TXT
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\mikes-backup\ofce\SERVICES.TXT
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\tribble2-backup-c\mikes-backup\ofce\SERVICES.TXT
[1999/04/23 21:22:00 | 000,005,130 | —- | M] () MD5=9FD21574C1827280937828D2D8C67F5D – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\SERVICES.TXT
[1999/04/23 22:22:00 | 000,005,130 | —- | M] () MD5=9FD21574C1827280937828D2D8C67F5D – C:\tribble2-backup-d\Office3\WINDOWS\SERVICES.TXT
< MD5 for: WINLOGON.EX_ >
[2004/08/04 11:00:00 | 000,261,115 | —- | M] () MD5=F41C4F5745589D0BB8268C02B71594CA – C:\WINDOWS\I386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2006/11/06 15:33:15 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2006/11/06 15:33:15 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2004/01/01 16:14:14 | 000,000,032 | —- | M] () – C:\ati.log
[2004/08/26 10:04:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/02 13:11:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/26 10:04:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2011/04/17 14:29:35 | 000,001,134 | —- | M] () – C:\FixNCR.reg
[2012/12/24 12:04:14 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2011/03/15 17:13:12 | 000,030,191 | —- | M] () – C:\install.log
[2004/08/26 10:04:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/11/24 15:31:03 | 000,018,947 | —- | M] () – C:\logfile
[2004/08/26 10:04:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/01/01 16:14:54 | 000,000,160 | —- | M] () – C:\napster.log
[2004/08/04 11:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 11:00:00 | 000,250,032 | —- | M] () – C:\ntldr
[2012/12/24 12:04:02 | 2078,785,536 | -HS- | M] () – C:\pagefile.sys
[2008/06/03 02:36:01 | 000,002,111 | —- | M] () – C:\rapport.txt
[2011/04/18 14:23:00 | 000,005,958 | —- | M] () – C:\recycbin-2.reg
[2011/04/18 11:53:06 | 000,000,569 | —- | M] () – C:\rkill.log
[2005/06/12 07:34:01 | 000,000,256 | —- | M] () – C:\SmartInstaller.log
[2011/04/19 17:23:21 | 000,050,682 | —- | M] () – C:\TDSSKiller.2.4.21.0_19.04.2011_18.17.46_log.txt
[2012/12/24 02:26:59 | 000,097,620 | —- | M] () – C:\TDSSKiller.2.8.15.0_24.12.2012_02.23.58_log.txt
[2012/07/19 13:09:11 | 000,069,966 | —- | M] () – C:\VETlog.dmp
[2012/07/19 13:09:12 | 002,351,370 | —- | M] () – C:\VETlog.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
[2006/02/19 02:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2004/08/26 10:03:59 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/09/04 21:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD3q.DLL
[2002/09/04 21:00:00 | 000,046,080 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP3q.DLL
[2003/07/29 01:36:00 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL
[2009/11/04 07:14:19 | 000,157,696 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2011/06/20 18:23:26 | 000,024,576 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\sst3cpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/10/01 15:29:48 | 000,109,312 | —- | M] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:13:07 | 000,001,401 | —- | M] () – C:\Program Files\PRNTBILL.BAT
[2003/10/01 13:32:26 | 000,001,401 | —- | M] () – C:\Program Files\PRNTBILL.~BA
[2004/05/03 12:45:00 | 000,356,352 | —- | M] () – C:\Program Files\putty.exe
[2008/04/09 17:18:10 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/26 02:53:19 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/26 02:53:18 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/26 02:53:18 | 000,864,256 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/20 00:57:19 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/03 16:48:37 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/21 17:34:16 | 008,582,536 | —- | M] (Mozilla) – C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.6.13.exe
[1997/12/23 01:14:15 | 000,091,648 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gzip.exe
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-15 08:23:03
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB21672$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C10F9B26
< End of report >
Not sure how long I've had this virus, the only symptoms I can see is that whenever I try to update Malwarebytes (which I've had for years - I also have F-Secure running at all times), or access any page on microsoft.com (and a few other random sites dealing with virus detection/cure) it sends me to the URL with the domain portion switched to google.com, resulting in a 404 error page. This happens on Firefox, MSIE AND Chrome. I ran both the FULL F-Secure and Malwarebytes scans and each found a couple viruses and fixed them, but neither seemed to have fixed this. Also have had trouble with my WD Passport Backup drive (Drive J:) getting errors and having to stop, for a couple of months now, but don't think it is related to this. In fact it was while trying to download new software to fix that, that I first noticed I could not get to microsoft.
I read another similar thread on this forum where the advisor requested running Gooredfix, so here is the result from that first (followed by the OTL results):
GooredFix by jpshortstuff (03.07.10.1)
Log created at 12:29 on 24/12/2012 (Owner)
Firefox version 16.0.2 (en-US)
========== GooredScan ==========
========== GooredLog ==========
C:\Program Files\Mozilla Firefox\extensions\
{3112ca9c-de6d-4884-a869-9855de68056c} [14:40 05/12/2012]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [14:40 05/12/2012]
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [00:11 03/12/2012]
{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [03:06 15/12/2011]
{99079a25-328f-4bd4-be04-00955acaa0a7}(2) [11:20 16/12/2011]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"[removed]"="C:\Program Files\CenturyLink Online Security\NRS\[removed]" [22:51 16/04/2011]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [22:57 15/11/2010]
"{0153E448-190B-4987-BDE1-F256CADA672F}"="C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [22:57 15/11/2010]
-=E.O.F=-
============================================================
I also ran OLT as requested by the new submission page (it took over 2 hours!) Here are the results from that:
==============================================================
OTL Extras logfile created on: 12/24/2012 12:49:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 43.70% Memory free
3.72 Gb Paging File | 2.98 Gb Available in Paging File | 80.14% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 0.81 Gb Free Space | 0.91% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.26 Gb Free Space | 99.72% Space Free | Partition Type: NTFS
Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00626135-E60A-4550-9503-4F50C6C9B8BB}" = Google AdWords Editor
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{0673654C-5296-453B-9798-B61CD7E03FEB}" = SES Driver
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{07D4701F-50D6-4C69-A785-DC556E60663F}" = Eudora
"{08F7CCA6-8590-4401-8B44-CEB09A909AAB}" = del.icio.us Buttons for Internet Explorer
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2522EE78-994E-45C8-9CE5-CE6CB2E0297F}" = Map of North and Central America
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{2FD94FBC-07AE-475C-B522-BFE899B9048E}" = Garmin WebUpdater
"{3004FB81-7B9E-4808-BD13-BC5A530BA60B}" = cp_PrintOnCDConfig
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{31492759-0E89-46B5-9770-F6E5808E3017}" = xImage
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{40631ADD-7633-F1F1-32D2-D1FB6374BAFB}" = Market Samurai
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{4FC9DA9D-F608-454E-8191-D7EFFDCC5726}" = SpyHunter
"{523BD5B6-E904-493C-B902-1BC9B7D44DF4}" = Lexmark Photo Center
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53AF3638-DDB4-4755-B3DC-259981689DB7}" = MioNet
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68131B0A-D78D-4aed-B74E-33A6C7324E50}" = WD Anywhere Backup
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6EEE2F18-AF5C-4E49-9C5B-F6ACC39B2F0E}" = FTP Explorer
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{79ED0EE7-098C-465F-A853-B17F6FC6CDD8}" = GPS TrackMaker
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{80A2A967-C1B7-412D-B2B2-C4A33209C205}" = Garmin POI Loader
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{84F1DE76-C48C-4281-87A0-CC9548D1E7F9}" = Rhapsody Player Engine
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98D451C4-4ACA-4273-BB47-57CFE46B048E}" = WD SmartWare
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B27901FA-F157-4049-B1EC-BC43890A1DCC}" = Active@ File Recovery
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BB7C0C8E-CF0B-44C5-B838-9ED93D15DBDF}" = Map of South America
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C012BF9F-79EA-4601-9778-BFE9B3CE83A1}" = hpg3010QFolder
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB71FF8-DE82-469C-8641-44378F4443EB}" = Garmin WebUpdater
"{CCD04643-5246-48AC-9D8C-F43A37BB8F36}" = WD Drive Manager (x86)
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E2C5C0D1-B4F7-4C1C-9AEF-C80E17677052}" = hpg3010
"{E2E7A0E8-77C4-495F-8FA3-63DAEDAA2DB3}" = F-Secure PSC Prerequisites
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F64D55C1-734C-4249-886E-4C41A9889A36}" = HP Scanjet G3010 7.0
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Acoustica MP3 Audio Mixer" = Acoustica MP3 Audio Mixer
"Actual Search & Replace_is1" = Actual Search & Replace Version 2.8.2
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Alexa Toolbar" = Alexa Toolbar
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"ASTRA32_is1" = ASTRA32 - Advanced System Information Tool 1.52
"Capitalism Plus" = Capitalism Plus
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"CoffeeCup HTML Editor 2008" = CoffeeCup HTML Editor 2008
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"EasyGPS_is1" = EasyGPS
"ExpressBurn" = Express Burn
"ExpressRip" = Express Rip
"ExtraPuTTY 0.24" = ExtraPuTTY 0.24
"Free RAR Extract Frog 1.00" = Free RAR Extract Frog 1.00
"F-Secure Product 444" = CenturyLink™ Online Security
"FTP Explorer" = FTP Explorer
"getPlus®_ocx" = getPlus®_ocx
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"HTML Search and Replace_is1" = HTML Search and Replace 1.0
"IconForge version 6.28_is1" = IconForge version 6.28
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{523BD5B6-E904-493C-B902-1BC9B7D44DF4}" = Lexmark Photo Center
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"Lexmark S300-S400 Series" = Lexmark S300-S400 Series
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1" = Market Samurai
"MasterClipsDeinstKey" = MasterClips Browser v2.03
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"Motherboard Monitor 5_is1" = Motherboard Monitor 5
"Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa2" = Picasa 2
"PlayBox" = PlayBox Toolbar
"Port Magic" = Pure Networks Port Magic
"RealPlayer 15.0" = RealPlayer
"Samsung CLP-320 Series" = Maintenance Samsung CLP-320 Series
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"Ulead PhotoImpact 5.0" = Ulead PhotoImpact 5
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xenu's Link Sleuth" = Xenu's Link Sleuth
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 12/23/2012 2:33:57 AM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2012-12-22 22:33:57-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
No scanner engines loaded and enabled. Virus protection is disabled.
Error - 12/23/2012 6:13:34 AM | Computer Name = MIKE | Source = Application Error | ID = 1000
Description = Faulting application wddmstatus.exe, version 3.1.0.11, faulting module
upnp.dll, version 5.1.2600.2180, fault address 0x0000e896.
Error - 12/23/2012 7:47:58 AM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 1 2012-12-23 03:47:54-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
Malicious code found in file C:\WINDOWS\Temp\USS1052.tmp. Infection: Gen:Variant.Barys.536
Error - 12/23/2012 12:03:21 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2012-12-23 08:03:21-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
No scanner engines loaded and enabled. Virus protection is disabled.
Error - 12/23/2012 12:18:55 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 3 2012-12-23 08:18:55-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
Malicious code found in file C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1102\A0309754.sys.
Infection: Gen:Variant.Barys.536 Action: The file was quarantined.
Error - 12/23/2012 6:26:32 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 4 2012-12-23 14:26:32-07:00 MIKE MIKE\Owner F-Secure Anti-Virus
Manual scanning was finished - workstation was found infected!
Error - 12/23/2012 8:33:18 PM | Computer Name = MIKE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000
Description = Faulting application wdsmartware.exe, version 1.4.1.1, stamp 4c87cbb7,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug? 0,
fault address 0x00012a5b.
Error - 12/23/2012 10:35:44 PM | Computer Name = MIKE | Source = MsiInstaller | ID = 10005
Description = Product: WD Software Upgrader – This application requires Microsoft
.NET Framework 4.0 client profile. Install the .NET Framework then run this installer
again.
Error - 12/24/2012 12:55:26 AM | Computer Name = MIKE | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.62.0.140, faulting module
version.dll, version 5.1.2600.2180, fault address 0x00001deb.
Error - 12/24/2012 3:59:14 PM | Computer Name = MIKE | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeobackup.exe, P2 2.0.0.0, P3 491494cf, P4
mscorlib, P5 2.0.0.0, P6 471ebc5b, P7 3404, P8 15a, P9 system.unauthorizedaccess,
P10 NIL.
[ System Events ]
Error - 12/24/2012 5:52:51 AM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =
Error - 12/24/2012 5:54:33 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
Error - 12/24/2012 5:54:33 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053
Error - 12/24/2012 5:54:34 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
Error - 12/24/2012 6:22:16 AM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =
Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Image Acquisition
(WIA) service to connect.
Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7000
Description = The Windows Image Acquisition (WIA) service failed to start due to
the following error: %%1053
Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
gagp30kx
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
Error - 12/24/2012 4:10:55 PM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =
Error - 12/24/2012 4:12:23 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
< End of report >
================================================================================
=
OTL logfile created on: 12/24/2012 12:49:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 43.70% Memory free
3.72 Gb Paging File | 2.98 Gb Available in Paging File | 80.14% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 0.81 Gb Free Space | 0.91% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.26 Gb Free Space | 99.72% Space Free | Partition Type: NTFS
Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeaserv.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\lxeacoms.exe ( )
PRC - C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackup.exe (Memeo Inc.)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\VTTrayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\sst3cl3.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\hashlib_x86.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fm4av.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\System.Data.SQLite.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epoemdll.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epstring.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizres.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizard.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\customui.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epfunct.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\eputil.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\imagutil.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeascw.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeamicro.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Spam Control\fsas.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSPC\fspcfsm.eng ()
MOD - \\?\c:\program files\centurylink online security\hips\fsumi.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\strres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\gres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\flyerres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\fsavures.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\about.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\aboutres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsavhres.eng ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeadatr.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeaptp.dll ()
MOD - C:\WINDOWS\system32\lxeasmr.dll ()
MOD - C:\WINDOWS\system32\lxeasm.dll ()
MOD - C:\Program Files\WD\WD Anywhere Backup\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\29c7192327cf3999961560bf3a3995c6\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL ()
MOD - C:\WINDOWS\system32\CISPMON.DLL ()
========== Services (SafeList) ==========
SRV - (napagent) – %SystemRoot%\System32\qagentrt.dll File not found
SRV - (hkmsvc) – %SystemRoot%\System32\kmsvc.dll File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (EapHost) – %SystemRoot%\System32\eapsvc.dll File not found
SRV - (Dot3svc) – %SystemRoot%\System32\dot3svc.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (FSORSPClient) – C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (lxeaCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (lxea_device) – C:\WINDOWS\system32\lxeacoms.exe ( )
SRV - (FSMA) – C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) – C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (MemeoBackgroundService) – C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
SRV - (MioNet) – C:\Program Files\MioNet\MioNetManager.exe ()
SRV - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Driver Services (SafeList) ==========
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (F-Secure Gatekeeper) – C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\fsgk.sys ()
DRV - (fsbts) – C:\WINDOWS\system32\drivers\fsbts.sys ()
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (F-Secure HIPS) – C:\Program Files\CenturyLink Online Security\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (FSFW) – C:\WINDOWS\system32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (F-Secure Filter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsfilter.sys ()
DRV - (F-Secure Recognizer) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsrec.sys ()
DRV - (NDISRD) – C:\WINDOWS\System32\drivers\ndisrd.sys (NT Kernel Resources)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ASTRA32) – C:\Program Files\ASTRA32\astra32.sys (Licensed for Sysinfo Lab)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mbmiodrvr) – C:\WINDOWS\system32\mbmiodrvr.sys ([removed])
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {39170861-6644-4F57-95E4-17683AFA09F4}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{39170861-6644-4F57-95E4-17683AFA09F4}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGIT_en
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Twitter"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4
FF - prefs.js..extensions.enabledAddons: %7B8f8fe09b-0bd3-4470-bc1b-8cad42b8203a%7D:0.17
FF - prefs.js..extensions.enabledAddons: %7B0153E448-190B-4987-BDE1-F256CADA672F%7D:15.0.6
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=119&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\3.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=1.0: C:\Program Files\Virtual Earth 3D\ [2007/05/17 16:50:24 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CenturyLink Online Security\NRS\[removed] [2011/05/30 16:21:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/05 06:41:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/05 06:40:57 | 000,000,000 | —D | M]
[2011/12/16 03:20:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/10/03 22:39:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/12/19 03:12:42 | 000,000,000 | —D | M] (Live HTTP Headers) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2011/12/19 03:12:02 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}(2)
[2012/11/20 12:25:46 | 000,243,496 | —- | M] () (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\searchplugins\Search_Results.xml
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012/10/11 14:15:02 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/12/05 06:41:44 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 13:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 13:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/10/11 14:13:20 | 000,129,176 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/09/21 00:45:46 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012/10/13 05:23:37 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.searchqu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Alexa Traffic Rank = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel\1.1.0_0\
CHR - Extension: KOCAttack - Extra Features! = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbbngjfcccafhimngmokmoejfdcjepgc\0.9.1_1\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
O1 HOSTS File: ([2012/03/13 19:42:32 | 000,244,641 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8540 more lines…
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O2 - BHO: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O2 - BHO: (del.icio.us Toolbar Helper) - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKLM\..\Toolbar: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKLM\..\Toolbar: (Alexa Toolbar) - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files\Alexa Toolbar\AlexaToolbar.10.0.dll (Alexa.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKCU\..\Toolbar\WebBrowser: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\CenturyLink Online Security\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [WD Anywhere Backup] C:\Program Files\WD\WD Anywhere Backup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKCU..\Run: [Siufsyut] C:\Documents and Settings\Owner\Application Data\Yzly\cygia.exe (Корпорация Майкрософт)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: samsungsetup.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase9563.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1165369289625 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75A8BD71-DED9-4086-856F-C1CA51592ECB}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\toolbarchrome {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 10:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{977d7f84-a735-11df-89b4-00038a000015}\Shell\AutoRun\command - "" = K:\setup.exe
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{d8a3e2f8-2abb-11e2-8a4e-00038a000015}\Shell\AutoRun\command - "" = K:\WDSetup.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: napagent - %SystemRoot%\System32\qagentrt.dll File not found
NetSvcs: hkmsvc - %SystemRoot%\System32\kmsvc.dll File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/12/24 12:42:16 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GooredFix Backups
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Yzly
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Akvea
[2012/12/05 06:40:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2008/04/09 17:23:24 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/12/24 13:28:03 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:09:15 | 000,000,412 | —- | M] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/24 12:05:03 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/24 12:04:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/24 12:04:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/12/24 12:04:14 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/24 11:47:01 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2012/12/24 03:29:10 | 000,004,442 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2012/12/24 01:50:54 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/12/24 01:19:09 | 000,000,402 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/24 00:02:28 | 000,000,508 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2012/12/23 22:17:02 | 000,000,406 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/23 16:46:27 | 000,000,600 | —- | M] () – C:\Documents and Settings\Owner\PUTTY.RND
[2012/12/23 16:12:33 | 000,002,243 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FTP Explorer.lnk
[2012/12/23 15:26:43 | 000,023,972 | —- | M] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2012/12/22 03:09:29 | 000,000,030 | —- | M] () – C:\WINDOWS\Iedit.INI
[2012/12/21 15:28:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/12/20 15:19:03 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/20 01:32:18 | 000,002,752 | —- | M] () – C:\WINDOWS\MAML.INI
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2012/12/13 12:43:48 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/12/13 03:08:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/11 15:30:07 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/12/11 15:30:06 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/12/10 03:39:00 | 000,000,330 | —- | M] () – C:\WINDOWS\tasks\jucheck.job
[2012/12/03 19:10:31 | 000,003,325 | —- | M] () – C:\Documents and Settings\All Users\Documents\shows-copyscape.htm
[2012/12/03 16:26:38 | 000,003,075 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:41:58 | 000,072,797 | —- | M] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/12/01 16:30:56 | 000,001,579 | —- | M] () – C:\Documents and Settings\Owner\My Documents\coupon-form.rtf
[2012/11/28 18:26:55 | 000,000,879 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/18 01:10:01 | 000,000,412 | —- | C] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/18 01:09:54 | 000,000,406 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/18 01:09:51 | 000,000,402 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/09 00:00:53 | 000,452,508 | —- | C] () – C:\error.fstmp
[2012/12/09 00:00:53 | 000,000,000 | —- | C] () – C:\infect.fstmp
[2012/12/03 16:26:38 | 000,003,075 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:44:44 | 000,072,797 | —- | C] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/11/28 18:26:55 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[2012/11/28 18:26:46 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Copy of WordPad.lnk
[2012/07/25 15:12:16 | 000,109,312 | —- | C] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.BAT
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.~BA
[2012/04/09 22:49:40 | 000,060,228 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2012/03/29 00:58:50 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/01/14 15:38:12 | 000,008,703 | —- | C] () – C:\Documents and Settings\All Users\Application Data\7aa1ff29
[2012/01/14 15:38:12 | 000,008,693 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\9c228de1
[2012/01/14 15:38:12 | 000,008,629 | —- | C] () – C:\Documents and Settings\Owner\Application Data\f739919
[2011/09/29 11:45:08 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\sst3cl3.dll
[2011/08/20 13:42:15 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\lxeasm.dll
[2011/08/20 13:42:15 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\lxeasmr.dll
[2011/08/20 13:42:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxeavs.dll
[2011/08/20 13:42:11 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoin.dll
[2011/08/20 13:42:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\lxeagcfg.dll
[2011/08/20 13:42:00 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxeacui.dll
[2011/08/20 13:42:00 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\lxeacuir.dll
[2011/08/20 13:38:30 | 000,847,872 | —- | C] ( ) – C:\WINDOWS\System32\lxeausb1.dll
[2011/08/20 13:38:30 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxeainpa.dll
[2011/08/20 13:38:30 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\LXEAhcp.dll
[2011/08/20 13:38:30 | 000,344,064 | —- | C] ( ) – C:\WINDOWS\System32\lxeaiesc.dll
[2011/08/20 13:38:30 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\LXEAinst.dll
[2011/08/20 13:38:29 | 001,048,576 | —- | C] ( ) – C:\WINDOWS\System32\lxeaserv.dll
[2011/08/20 13:38:29 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxeapmui.dll
[2011/08/20 13:38:28 | 000,577,536 | —- | C] ( ) – C:\WINDOWS\System32\lxealmpm.dll
[2011/08/20 13:38:28 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\lxeains.dll
[2011/08/20 13:38:28 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lxeainsb.dll
[2011/08/20 13:38:28 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lxeainsr.dll
[2011/08/20 13:38:28 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\lxeajswr.dll
[2011/08/20 13:38:27 | 000,688,128 | —- | C] ( ) – C:\WINDOWS\System32\lxeahbn3.dll
[2011/08/20 13:38:27 | 000,324,264 | —- | C] ( ) – C:\WINDOWS\System32\lxeaih.exe
[2011/08/20 13:38:27 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxeagrd.dll
[2011/08/20 13:38:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\lxeacu.dll
[2011/08/20 13:38:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\lxeacub.dll
[2011/08/20 13:38:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\lxeacur.dll
[2011/08/20 13:38:25 | 000,598,696 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoms.exe
[2011/08/20 13:38:24 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomm.dll
[2011/08/20 13:38:23 | 000,802,816 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomc.dll
[2011/08/20 13:38:23 | 000,373,416 | —- | C] ( ) – C:\WINDOWS\System32\lxeacfg.exe
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Compressor
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Command Line Utility
[2011/07/21 02:49:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2011/07/21 02:49:31 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Core Data Application
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 14:54:02 | 000,042,664 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 01:15:55 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/14 22:47:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Fqureh.dat
[2011/04/14 22:47:28 | 000,000,000 | —- | C] () – C:\WINDOWS\Tbovewipezupew.bin
[2009/10/19 14:15:11 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\PUTTY.RND
[2009/09/21 15:57:13 | 000,000,064 | —- | C] () – C:\Documents and Settings\Owner\setpath.bat
[2008/12/21 03:46:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Common
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Colors
[2008/12/16 17:52:18 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2008/12/16 17:52:18 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Configure Folder Actions
[2008/02/15 17:19:07 | 000,010,240 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/17 16:52:33 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/05/14 01:39:17 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/14 13:52:06 | 000,000,008 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.dat.bin
[2006/12/04 16:39:00 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\PUTTY.RND
[2006/12/04 16:38:00 | 000,356,352 | —- | C] () – C:\Program Files\putty.exe
[2006/12/03 17:04:02 | 000,023,972 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[2004/01/01 15:49:53 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = shell32.dll – [2007/10/25 19:34:01 | 008,460,288 | —- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2006/09/03 22:12:56 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2004/08/04 11:00:00 | 000,472,064 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2004/08/04 11:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/12/16 02:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/04/16 14:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2011/04/15 00:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fAk02400lLmCj02400
[2011/05/22 19:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2011/09/19 04:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lexmark S300-S400 Series
[2009/09/27 23:55:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2009/06/29 01:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2004/01/01 16:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/02/16 04:14:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/07/21 02:51:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/09/29 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2012/12/23 16:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/25 15:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/11/11 15:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2010/08/08 11:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/19 03:12:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B49A644A-1076-4A3D-B124-DAA7862F2318}
[2011/11/29 13:30:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Actual Search & Replace
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Akvea
[2008/06/26 09:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/10/23 14:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/28 01:29:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CursorArts
[2011/04/15 13:13:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Desktopicon
[2010/02/26 00:08:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/04/16 23:00:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F-Secure
[2012/12/24 02:04:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2010/01/31 23:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2009/12/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2012/04/09 18:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/08/23 02:11:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MioNet
[2009/06/29 01:05:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\muvee Technologies
[2010/02/16 05:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
[2011/07/21 02:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2010/01/24 16:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayBox
[2004/01/01 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2011/12/19 03:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchqutoolbar(2)
[2011/09/29 02:24:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Stellarium
[2006/12/03 17:04:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/05/25 15:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/09/30 16:17:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WD
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Yzly
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/04 11:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\WINDOWS\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[1998/05/11 19:01:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=7ADA6F7250F04A62D84A09373F1BBAE9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\WINDOWS\EXPLORER.EXE
[1998/05/11 19:01:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=7ADA6F7250F04A62D84A09373F1BBAE9 – C:\tribble2-backup-c\WINDOWS\EXPLORER.EXE
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\system32\dllcache\explorer.exe
[2004/08/04 11:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[1999/04/23 21:22:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=B22B28F61B1BB06723019307F0FAACFC – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\EXPLORER.EXE
[1999/04/23 22:22:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=B22B28F61B1BB06723019307F0FAACFC – C:\tribble2-backup-d\Office3\WINDOWS\EXPLORER.EXE
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/12/24 02:23:49 | 000,029,776 | —- | M] () MD5=F997F0D85F58421DA7CB8700FD005360 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SC_ >
[2004/08/04 11:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[1998/05/11 19:01:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\WINDOWS\EXPLORER.SCF
[1999/04/23 21:22:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\EXPLORER.SCF
[1998/05/11 19:01:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\tribble2-backup-c\WINDOWS\EXPLORER.SCF
[1999/04/23 22:22:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\tribble2-backup-d\Office3\WINDOWS\EXPLORER.SCF
[2004/08/04 11:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.001 >
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
< MD5 for: IEXPLORE.ASF >
[1996/04/26 16:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLEC\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 16:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 17:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\tribble2-backup-d\TRIBBLEC\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 17:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\tribble2-backup-d\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
< MD5 for: IEXPLORE.CH_ >
[2004/08/04 11:00:00 | 000,199,077 | —- | M] () MD5=5F64795662F162CCD8B30969B6682029 – C:\WINDOWS\I386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/04 11:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.CHW >
[2010/11/04 14:30:34 | 000,153,185 | —- | M] () MD5=F879E396E373F6BD74411EEA8FBF9E75 – C:\WINDOWS\Help\iexplore.chw
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 11:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\WINDOWS\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2007/04/24 06:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/04/22 00:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/04/21 23:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie8\iexplore.exe
[2007/12/06 03:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 00:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 00:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2007/08/17 02:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2006/10/17 12:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2007/08/17 02:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 16:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\iexplore.exe
[2007/10/10 00:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\tribble2-backup-c\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[2007/02/21 00:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 01:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2007/12/06 00:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 06:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2007/06/27 01:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2007/02/27 22:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2004/08/04 11:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2007/10/10 02:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2002/08/28 23:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=EB9EAF627F705525D01DE5FA07EA1818 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Internet Explorer\IEXPLORE.EXE
[2002/08/28 23:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=EB9EAF627F705525D01DE5FA07EA1818 – C:\tribble2-backup-c\Program Files\Internet Explorer\IEXPLORE.EXE
[1999/04/23 21:22:00 | 000,078,272 | —- | M] (Microsoft Corporation) MD5=F51690B7980BD05DB110FDCD1714688E – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\Program Files\Internet Explorer\IEXPLORE.EXE
[1999/04/23 22:22:00 | 000,078,272 | —- | M] (Microsoft Corporation) MD5=F51690B7980BD05DB110FDCD1714688E – C:\tribble2-backup-d\Office3\Program Files\Internet Explorer\IEXPLORE.EXE
< MD5 for: IEXPLORE.EXE.26E3AD32.INI.INUSE >
[2007/05/17 16:52:33 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory\iexplore.exe.26e3ad32.ini.inuse
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 17:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/12/23 18:59:41 | 000,106,880 | —- | M] () MD5=6C857BF7D0C08DB29AD1BAE13A276D56 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HL_ >
[2004/08/04 11:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2004/08/04 11:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: IEXPLORE.INI >
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
< MD5 for: SERVICES >
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 17:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK\SERVICES
[1993/10/09 17:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[2004/08/04 11:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 12:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-d\TRIBBLC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 12:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-d\TRIBBLEC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/02/27 23:06:00 | 000,001,238 | —- | M] () MD5=AC1EC38D56985CC93876FF9F05274012 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Netcomplete\SERVICES
[1995/02/27 23:06:00 | 000,001,238 | —- | M] () MD5=AC1EC38D56985CC93876FF9F05274012 – C:\tribble2-backup-c\Program Files\Netcomplete\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\SERVICES
[2000/02/04 10:28:42 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\RECYCLED\DC9.0\net\win98\services
[2000/02/24 09:35:36 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\RECYCLED\DC9.0\net\win98se\services
[1999/04/23 21:22:00 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\SERVICES
[2000/02/04 10:28:42 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-c\RECYCLED\DC9.0\net\win98\services
[2000/02/24 09:35:36 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-c\RECYCLED\DC9.0\net\win98se\services
[1999/04/23 22:22:00 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-d\Office3\WINDOWS\SERVICES
< MD5 for: SERVICES._ >
[2004/08/04 11:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\WINDOWS\I386\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 10:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\SERVICES._
[1996/06/27 10:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\SERVICES._
< MD5 for: SERVICES.CHM >
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit6\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit3\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit4\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit5\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit6\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit7\Services.chm
[2002/11/18 04:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\QuickBooks Basic\Services.chm
[2003/10/29 17:30:46 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\services.chm
[2003/10/29 17:30:44 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Services.chm
[2003/10/29 17:30:46 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\services.chm
[2003/10/29 17:30:44 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Services.chm
< MD5 for: SERVICES.CSS >
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Quickbooks-save\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 16:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\tribble2-backup-d\Quickbooks-save\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2003/05/30 00:03:06 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Components\Services\services.css
[2003/05/30 00:03:06 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Components\Services\services.css
[2004/05/14 19:49:46 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\tribble2-backup-d\intuit7\Components\Services\services.css
[2002/05/29 15:31:02 | 000,007,703 | —- | M] () MD5=75A6BA0742A7EB410A0AFB38A9A59D29 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Quickbooks-save\QuickBooks\Components\Services\services.css
[2002/05/29 16:31:02 | 000,007,703 | —- | M] () MD5=75A6BA0742A7EB410A0AFB38A9A59D29 – C:\tribble2-backup-d\Quickbooks-save\QuickBooks\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit3\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit4\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit5\Components\Services\services.css
[2002/10/15 14:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\QuickBooks Basic\Components\Services\services.css
[2004/11/09 23:43:02 | 000,011,525 | —- | M] () MD5=FF757041D7C3EBA68F0127402D174D27 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\Components\Services\services.css
[2004/11/09 23:43:02 | 000,011,525 | —- | M] () MD5=FF757041D7C3EBA68F0127402D174D27 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\Components\Services\services.css
< MD5 for: SERVICES.CV_ >
[1996/05/07 10:00:18 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\tribble2-backup-d\TRIBBLEC\TRIBBLED\WINFAX1\SERVICES.CV_
< MD5 for: SERVICES.DOC >
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\tribble2-backup-c\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
< MD5 for: SERVICES.EX_ >
[2004/08/04 11:00:00 | 000,049,955 | —- | M] () MD5=85A738BA493104ED103B26CADEB8B543 – C:\WINDOWS\I386\SERVICES.EX_
< MD5 for: SERVICES.EXE >
[2008/04/13 16:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\system32\dllcache\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.GIF >
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2012/02/04 19:44:22 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\websites\bestdotcom-premove-backup\lvmarket\services.gif
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\tribble2-backup-c\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
< MD5 for: SERVICES.HTM >
[2012/02/04 19:44:24 | 000,003,652 | —- | M] () MD5=18DB327C3EFBEB7421648AB07F21DE23 – C:\websites\bestdotcom-premove-backup\lvmarket\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\galleria\web\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\websites\galleria\web\services.htm
[2001/11/29 00:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2\websites\galleria\backup-051402\services.htm
[2001/11/29 00:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2\websites\galleria\web\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\websites\galleria\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\preslimo\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\mikes-backup\websites\preslimo\web\services.htm
[2002/09/23 13:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\tribble2\websites\preslimo\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\tribble2-backup-c\mikes-backup\websites\preslimo\web\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\preslimo\web\whatson\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\mikes-backup\websites\preslimo\web\whatson\services.htm
[2002/09/23 13:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2\websites\preslimo\web\whatson\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2-backup-c\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2-backup-c\mikes-backup\websites\preslimo\web\whatson\services.htm
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\tribble2-backup-c\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\IDI\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofce\IDI\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofce\IDI\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\tribble2-backup-c\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
< MD5 for: SERVICES.HTML >
[2001/10/22 13:07:10 | 000,004,043 | —- | M] () MD5=BB431A68F828197874960F469A96304E – C:\Program Files\CoffeeCup Software\templates\Resturant\services.html
< MD5 for: SERVICES.JPG >
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.JPG
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\mikes-backup\ofce\LVMARKET\SERVICES.JPG
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.JPG
< MD5 for: SERVICES.LIM >
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit6\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit3\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit4\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit5\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit6\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit7\Services.lim
[2002/11/15 17:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\QuickBooks Basic\Services.lim
[2003/10/29 17:30:58 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\services.lim
[2003/10/29 17:30:56 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Services.lim
[2003/10/29 17:30:58 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\services.lim
[2003/10/29 17:30:56 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Services.lim
< MD5 for: SERVICES.LNK >
[2004/08/26 10:04:45 | 000,001,602 | —- | M] () MD5=6EA8801235B7C68E8DFAA9C1B99BEDB2 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MS_ >
[2004/08/04 11:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\WINDOWS\I386\SERVICES.MS_
< MD5 for: SERVICES.MSC >
[2004/08/04 11:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.OLD >
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\GAL\SERVICES.OLD
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\mikes-backup\ofce\GAL\SERVICES.OLD
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\tribble2-backup-c\mikes-backup\ofce\GAL\SERVICES.OLD
< MD5 for: SERVICES.PNG >
[2008/03/27 04:42:50 | 000,003,143 | —- | M] () MD5=087ECCA024AB9A71D659CB6E4F910D2E – C:\Program Files\CoffeeCup Software\Graphics\plano\yellow\services.png
[2008/03/27 04:52:46 | 000,003,090 | —- | M] () MD5=1E9256F745C06682AFDCD57A5B038134 – C:\Program Files\CoffeeCup Software\Graphics\plano\orange\services.png
[2008/03/27 04:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files\CoffeeCup Software\Graphics\plano\red\services.png
[2008/03/27 05:06:18 | 000,003,208 | —- | M] () MD5=BF7751362552A6E38BD3E6A610ED9889 – C:\Program Files\CoffeeCup Software\Graphics\plano\violet\services.png
[2008/03/27 04:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files\CoffeeCup Software\Graphics\plano\blue\services.png
[2008/03/27 05:01:46 | 000,003,305 | —- | M] () MD5=CB54DD779139E4475AA92417CEB09846 – C:\Program Files\CoffeeCup Software\Graphics\plano\green\services.png
[2008/03/27 04:47:26 | 000,003,497 | —- | M] () MD5=F0AF7DB71281CC55799AB75203BFB664 – C:\Program Files\CoffeeCup Software\Graphics\plano\indigo\services.png
< MD5 for: SERVICES.SBS >
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\tribble2-backup-c\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: SERVICES.TIF >
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.TIF
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\mikes-backup\ofce\LVMARKET\SERVICES.TIF
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.TIF
< MD5 for: SERVICES.TXT >
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\SERVICES.TXT
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\mikes-backup\ofce\SERVICES.TXT
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\tribble2-backup-c\mikes-backup\ofce\SERVICES.TXT
[1999/04/23 21:22:00 | 000,005,130 | —- | M] () MD5=9FD21574C1827280937828D2D8C67F5D – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\SERVICES.TXT
[1999/04/23 22:22:00 | 000,005,130 | —- | M] () MD5=9FD21574C1827280937828D2D8C67F5D – C:\tribble2-backup-d\Office3\WINDOWS\SERVICES.TXT
< MD5 for: WINLOGON.EX_ >
[2004/08/04 11:00:00 | 000,261,115 | —- | M] () MD5=F41C4F5745589D0BB8268C02B71594CA – C:\WINDOWS\I386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2006/11/06 15:33:15 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2006/11/06 15:33:15 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2004/01/01 16:14:14 | 000,000,032 | —- | M] () – C:\ati.log
[2004/08/26 10:04:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/02 13:11:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/26 10:04:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2011/04/17 14:29:35 | 000,001,134 | —- | M] () – C:\FixNCR.reg
[2012/12/24 12:04:14 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2011/03/15 17:13:12 | 000,030,191 | —- | M] () – C:\install.log
[2004/08/26 10:04:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/11/24 15:31:03 | 000,018,947 | —- | M] () – C:\logfile
[2004/08/26 10:04:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/01/01 16:14:54 | 000,000,160 | —- | M] () – C:\napster.log
[2004/08/04 11:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 11:00:00 | 000,250,032 | —- | M] () – C:\ntldr
[2012/12/24 12:04:02 | 2078,785,536 | -HS- | M] () – C:\pagefile.sys
[2008/06/03 02:36:01 | 000,002,111 | —- | M] () – C:\rapport.txt
[2011/04/18 14:23:00 | 000,005,958 | —- | M] () – C:\recycbin-2.reg
[2011/04/18 11:53:06 | 000,000,569 | —- | M] () – C:\rkill.log
[2005/06/12 07:34:01 | 000,000,256 | —- | M] () – C:\SmartInstaller.log
[2011/04/19 17:23:21 | 000,050,682 | —- | M] () – C:\TDSSKiller.2.4.21.0_19.04.2011_18.17.46_log.txt
[2012/12/24 02:26:59 | 000,097,620 | —- | M] () – C:\TDSSKiller.2.8.15.0_24.12.2012_02.23.58_log.txt
[2012/07/19 13:09:11 | 000,069,966 | —- | M] () – C:\VETlog.dmp
[2012/07/19 13:09:12 | 002,351,370 | —- | M] () – C:\VETlog.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
[2006/02/19 02:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2004/08/26 10:03:59 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/09/04 21:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD3q.DLL
[2002/09/04 21:00:00 | 000,046,080 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP3q.DLL
[2003/07/29 01:36:00 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL
[2009/11/04 07:14:19 | 000,157,696 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2011/06/20 18:23:26 | 000,024,576 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\sst3cpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/10/01 15:29:48 | 000,109,312 | —- | M] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:13:07 | 000,001,401 | —- | M] () – C:\Program Files\PRNTBILL.BAT
[2003/10/01 13:32:26 | 000,001,401 | —- | M] () – C:\Program Files\PRNTBILL.~BA
[2004/05/03 12:45:00 | 000,356,352 | —- | M] () – C:\Program Files\putty.exe
[2008/04/09 17:18:10 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/26 02:53:19 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/26 02:53:18 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/26 02:53:18 | 000,864,256 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/20 00:57:19 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/03 16:48:37 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/21 17:34:16 | 008,582,536 | —- | M] (Mozilla) – C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.6.13.exe
[1997/12/23 01:14:15 | 000,091,648 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gzip.exe
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-15 08:23:03
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB21672$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C10F9B26
< End of report >