Hello there _, Thank you in advance for being patient and willing to help. I could be infected beyond the scope of anyone being able to help me, I honestly don't know. Im having several issues, it could be owner error, tired quipment, settings, intentional sabotage from ex-boyfriend or lack of computer skill....I dont know, and thats why I am here. Its old computer running xp professional ,In the recent past, It has had several installs on the one hard drive. I was infected by the windows defender trojan 2011 previously and was walked thru virus/malware/spyware removal, the computer restored to a working state, but has never been completely "fixed" but for the most part functioned satisfactory (for what I need it for. The most obvious was a number of files that could not be removed, deleted or restored the names of the files would change following each system restore-or malicious removal instruction.- to the present-browser hijacking or homepage being changed-addition of new tool bars or search boxes-without my knowledge or consent, the background of pages never loads-it remains white and is characteristic of a clear piece of overlay that puts sign in boxes or clickable links in incorrect places or behind othr text, so that you are unable to click the act now buttton, or play, or sign in...whatever it is you are trying to do. Or the captha display is unseen as indicated it should be. Yesterday I did a troubleshoot on mozilla, I dont even know how I got there honestly, but the jist of the message was true and falses on certain settings, tasks, and what not, one thing particular caught my eye, and it was a specialized preerence(not made by me) that says it was outside the scope of mozilla settings or something very close to that, it was a "yahoo"dont ask" _ I dont remember for sure and cannot return to its location because I don;'t know how to...when I googled the command it brought up several complants (none of the exact same symptons as mine} but bsically was directing the user to what the tech or bleeping computer, I am still unsureif its indicative of having a virus or if its adware...another redirect that always comes up is "conduit".
The other concern is messages saying flashplayer or java out of date- I download the fix or player and then cannot open the download or install the updae or the file is empty....that is all.
I apologize if I was too windy, or all over the place with my description, I do not know what is related, to one or the other or what is relevant and what is just extra noise that I am making for no apparent reasonPlease forgive.+++++++
Below is a copy of the content results after running OTL. I look forward to hearing from someone soon.
Thank you for your time
Krptd
OTL logfile created on: 8/27/2013 6:05:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\taryn\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
989.90 Mb Total Physical Memory | 227.19 Mb Available Physical Memory | 22.95% Memory free
5.56 Gb Paging File | 4.81 Gb Available in Paging File | 86.48% Paging File free
Paging file location(s): C:\pagefile.sys 4800 7000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 32.39 Gb Free Space | 43.50% Space Free | Partition Type: NTFS
Computer Name: MYRADXP | User Name: taryn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\taryn\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\SearchProtect\bin\CltMngSvc.exe (Conduit)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\tryme\Application Data\DefaultTab\DefaultTab\DTUpdate.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Documents and Settings\tryme\Application Data\DefaultTab\DefaultTab\DTUpdate.exe ()
========== Services (SafeList) ==========
SRV - (SSHNAS) -- C:\WINDOWS\system32\sshnas21.dll File not found
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (avgwd) -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (CltMngSvc) -- C:\Program Files\SearchProtect\bin\CltMngSvc.exe (Conduit)
SRV - (RaMediaServer) -- C:\Program Files\Ralink\Common\RaMediaServer.exe ()
SRV - (RalinkRegistryWriter) -- C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (WefiEngSvc) -- C:\Program Files\WeFi\WefiEngSvc.exe (WeFi)
SRV - (getPlusHelper) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (DefaultTabUpdate) -- C:\Documents and Settings\tryme\Application Data\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (ANIWZCSdService) -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (Wireless Service)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (Trufos) -- File not found
DRV - (RTL8192su) -- system32\DRIVERS\RTL8192su.sys File not found
DRV - (Profos) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (cpuz132) -- File not found
DRV - (cpuz129) -- C:\DOCUME~1\taryn\LOCALS~1\Temp\pcwiz32.sys File not found
DRV - (Changer) -- File not found
DRV - (ATMFVsp) -- File not found
DRV - (ATMFNVsp) -- File not found
DRV - (ATMFNET) -- File not found
DRV - (ATMFMdm) -- File not found
DRV - (ATMFFLT) -- File not found
DRV - (ATMFCVsp) -- File not found
DRV - (ATMFBUS) -- File not found
DRV - (Avglogx) -- C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) -- C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) -- C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (rt2870) -- C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (Tcpip6) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (Scutum50) -- C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ANIO) -- C:\WINDOWS\system32\ANIO.sys (Alpha Networks Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atiide) -- C:\WINDOWS\system32\drivers\atiide.sys (ATI Technologies Inc.)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (AR5211) -- C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (MA311) -- C:\WINDOWS\system32\drivers\ma311n51.sys (NETGEAR)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (USB-100) -- C:\WINDOWS\system32\drivers\USBKR100.SYS (USB Corporation Reserved.)
DRV - (PCANDIS5) -- C:\Program Files\MA311 PCI Adapter Configuration Utility\PCANDIS5.SYS (Printing Communications Assoc., Inc. (PCAUSA))
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\..\SearchScopes,DefaultScope = {68EDDF53-2625-49FD-A013-EFB676CAC1E5}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...;ctid=CT3293216
IE - HKCU\..\URLSearchHook: {73507124-6acd-43aa-b749-c3bcfefbea97} - C:\Program Files\Vgrabber_v1.5\prxtbVgra.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {68EDDF53-2625-49FD-A013-EFB676CAC1E5}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{53068978-8A98-4648-91F8-7796DBA0520C}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{68EDDF53-2625-49FD-A013-EFB676CAC1E5}: "URL" = http://search.condui...?...832843&UM=2
IE - HKCU\..\SearchScopes\{C8F27DFA-530F-4E94-AA5E-6FBA410A1313}: "URL" = http://www.mysearchr...q={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incre...box_im2_test_v2
IE - HKCU\..\SearchScopes\{D034B5A4-6CFD-48C3-A013-BE00774E9336}: "URL" = http://search.yahoo....0091250,0,0,0,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:59274
========== FireFox ==========
FF - prefs.js..CT3287802.browser.search.defaultthis.engineName: "true"
FF - prefs.js..CT3293216.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultengine: "SafeSearch"
FF - prefs.js..browser.search.defaultthis.engineName: "Vgrabber v1.5 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.order.1: "SafeSearch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.baggagere...t-an-assclown/"
FF - prefs.js..extensions.enabledAddons: info%40switchviasdasdfsdffasfd.net:0.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.0.1
FF - prefs.js..extensions.enabledItems: {D02B1E87-A8C6-433f-9B5C-2CEC4A072736}:04.10.00.03
FF - prefs.js..extensions.enabledItems: {4CFC8387-5FB1-47C1-8AA4-5B7B906A591E}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1423
FF - prefs.js..extensions.enabledItems: crossriderapp19866@crossrider.com:0.88.28
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Plus Web Player Plug-In,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/07/19 14:43:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/08/19 11:46:38 | 000,000,000 | ---D | M]
[2009/04/05 20:42:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Extensions
[2013/08/26 15:39:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions
[2013/05/28 03:34:12 | 000,000,000 | ---D | M] (AddThis) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2013/08/20 10:55:57 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/05 08:48:10 | 000,000,000 | ---D | M] (CommentsBar Toolbar) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{71d2cf9e-34e4-4401-8841-f4fc3f3edc32}(2)
[2013/08/25 01:02:10 | 000,000,000 | ---D | M] (Vgrabber v1.5) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{73507124-6acd-43aa-b749-c3bcfefbea97}
[2013/07/25 23:01:32 | 000,000,000 | ---D | M] (VisualBee V.3) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{bf9194c2-b86d-4ebc-9b53-1c08b6ff779e}
[2009/12/14 21:49:27 | 000,000,000 | ---D | M] (SignupShield) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{D02B1E87-A8C6-433f-9B5C-2CEC4A072736}
[2013/05/28 03:34:25 | 000,000,000 | ---D | M] ("Deal Vault") -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\crossriderapp19866@crossrider.com
[2013/08/18 17:48:54 | 000,000,000 | ---D | M] (Vaudix) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\erd7wu@zydf.com
[2013/07/10 15:54:07 | 000,000,000 | ---D | M] ("SafeSearch") -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\general@safesearch.net
[2013/05/28 03:34:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\crossriderapp19866@crossrider.com\chrome\content\extensionCode
[2013/08/26 15:39:58 | 000,007,974 | ---- | M] () (No name found) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\info@switchviasdasdfsdffasfd.net.xpi
[2013/08/26 14:06:25 | 000,006,796 | ---- | M] () (No name found) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\info@youtube-mp3.org.xpi
[2013/05/28 02:31:58 | 000,020,591 | ---- | M] () (No name found) -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/08/23 22:58:03 | 000,001,003 | ---- | M] () -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\searchplugins\conduit.xml
[2009/11/26 20:58:07 | 000,002,149 | ---- | M] () -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\searchplugins\MyStart Search.xml
[2013/07/31 00:10:40 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\searchplugins\safesearch-1.xml
[2012/08/01 18:04:00 | 000,001,235 | ---- | M] () -- C:\Documents and Settings\taryn\Application Data\Mozilla\Firefox\Profiles\2yqmveox.default\searchplugins\safesearch.xml
[2013/08/18 17:22:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/08/18 17:22:01 | 000,000,000 | ---D | M] (Wyeke) -- C:\Program Files\Mozilla Firefox\extensions\{4CFC8387-5FB1-47C1-8AA4-5B7B906A591E}
[2013/08/18 17:22:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/18 17:22:19 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/11/26 08:44:54 | 000,002,226 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/01/07 14:01:35 | 000,001,600 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\WebSearchober27940250.xml
[2009/12/10 05:33:54 | 000,002,377 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wyeke127.xml
[2009/12/29 20:38:30 | 000,002,377 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wyeke129.xml
========== Chrome ==========
CHR - Extension: No name found = C:\Documents and Settings\taryn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.9_0\
CHR - Extension: No name found = C:\Documents and Settings\taryn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eafmaofdanmllainmcmnbgpajhgpmdcb\1.3\
CHR - Extension: No name found = C:\Documents and Settings\taryn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0\
CHR - Extension: No name found = C:\Documents and Settings\taryn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbofibgamhkgoonaocfgemncghhadmgb\2.3.19.11_0\
O1 HOSTS File: ([2010/01/10 20:01:16 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Deal Vault) - {11111111-1111-1111-1111-110111981166} - C:\Program Files\Deal Vault\Deal Vault.dll (215 Apps)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Vgrabber v1.5 Toolbar) - {73507124-6acd-43aa-b749-c3bcfefbea97} - C:\Program Files\Vgrabber_v1.5\prxtbVgra.dll (Conduit Ltd.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\tryme\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3BD53DEC-24D7-4F9E-B27C-925559B8D27D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vgrabber v1.5 Toolbar) - {73507124-6ACD-43AA-B749-C3BCFEFBEA97} - C:\Program Files\Vgrabber_v1.5\prxtbVgra.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl.sun.co...?BundleId=26688 (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF59FD9F-B738-47C6-9CD1-8C7539D1B4A7}: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\taryn\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\taryn\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/26 16:13:36 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{02e4ded6-76d3-11de-8bde-0014a504f0a1}\Shell\AutoRun\command - "" = E:\rcaeasyrip_setup.exe
O33 - MountPoints2\{02e4ded6-76d3-11de-8bde-0014a504f0a1}\Shell\install\command - "" = E:\rcaeasyrip_setup.exe
O33 - MountPoints2\{02e4ded6-76d3-11de-8bde-0014a504f0a1}\Shell\usermanualEnglish\command - "" = E:\rcaeasyrip_setup.exe /pdf_English
O33 - MountPoints2\{02e4ded6-76d3-11de-8bde-0014a504f0a1}\Shell\usermanualFrench\command - "" = E:\rcaeasyrip_setup.exe /pdf_French
O33 - MountPoints2\{02e4ded6-76d3-11de-8bde-0014a504f0a1}\Shell\usermanualSpanish\command - "" = E:\rcaeasyrip_setup.exe /pdf_Spanish
O33 - MountPoints2\{328395b0-c112-11de-8c24-0014a504f0a1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{328395b0-c112-11de-8c24-0014a504f0a1}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\{328395b0-c112-11de-8c24-0014a504f0a1}\Shell\phone\command - "" = E:\autorun.exe
O33 - MountPoints2\{8aea37aa-87e3-11de-8bec-0014a504f0a1}\Shell - "" = AutoRun
O33 - MountPoints2\{8aea37aa-87e3-11de-8bec-0014a504f0a1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8aea37aa-87e3-11de-8bec-0014a504f0a1}\Shell\AutoRun\command - "" = E:\start.exe
O33 - MountPoints2\{9da570c2-fea0-11de-8c6c-c405af798ab9}\Shell - "" = AutoRun
O33 - MountPoints2\{9da570c2-fea0-11de-8c6c-c405af798ab9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9da570c2-fea0-11de-8c6c-c405af798ab9}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MySHit.exE
O33 - MountPoints2\{f9900082-de6c-11dd-8b49-0014a504f0a1}\Shell - "" = AutoRun
O33 - MountPoints2\{f9900082-de6c-11dd-8b49-0014a504f0a1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f9900082-de6c-11dd-8b49-0014a504f0a1}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tRYmE.EXE
O33 - MountPoints2\{fe84dd90-e88f-11de-8c56-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{fe84dd90-e88f-11de-8c56-00a0c6000000}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fe84dd90-e88f-11de-8c56-00a0c6000000}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - C:\WINDOWS\system32\sshnas21.dll File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co....hors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/27 06:02:46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\taryn\Desktop\OTL.exe
[2013/08/26 16:21:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013/08/26 16:21:51 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013/08/26 16:21:39 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/08/26 16:21:38 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013/08/26 16:21:36 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013/08/26 13:41:19 | 000,000,000 | ---D | C] -- C:\tmedia
[2013/08/26 04:06:06 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\taryn\Recent
[2013/08/23 23:00:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\taryn\Local Settings\Application Data\Vgrabber_v1.5
[2013/08/23 23:00:08 | 000,000,000 | ---D | C] -- C:\Program Files\Vgrabber_v1.5
[2013/08/19 09:44:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\taryn\Local Settings\Application Data\Spotify
[2013/08/19 09:43:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\taryn\Application Data\Spotify
[2013/08/19 06:06:22 | 000,083,968 | ---- | C] (Eastman Kodak Company) -- C:\WINDOWS\KPAPI32.DLL
[2013/08/19 06:06:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\PhotoCD
[2013/08/19 06:06:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\taryn\Start Menu\Programs\Adobe PhotoDeluxe
[2013/08/19 06:06:21 | 000,353,392 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTIM.DLL
[2013/08/19 06:06:21 | 000,200,912 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTRPZA.QTC
[2013/08/19 06:06:21 | 000,182,368 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTCVID.QTC
[2013/08/19 06:06:21 | 000,165,056 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTSMC.QTC
[2013/08/19 06:06:21 | 000,111,488 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QCMC.QTC
[2013/08/19 06:06:21 | 000,093,200 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTRLE.QTC
[2013/08/19 06:06:21 | 000,073,360 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTOLE.DLL
[2013/08/19 06:06:21 | 000,064,720 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\QTIV32.QTC
[2013/08/19 06:06:21 | 000,058,544 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTRT21.QTC
[2013/08/19 06:06:21 | 000,041,344 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\MCIQTW.DRV
[2013/08/19 06:06:21 | 000,039,936 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\QTIYVU9.QTC
[2013/08/19 06:06:21 | 000,032,128 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\DHIO_DH.QTC
[2013/08/19 06:06:21 | 000,029,072 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTMOVIE.VBX
[2013/08/19 06:06:21 | 000,028,352 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTJPEG.QTC
[2013/08/19 06:06:21 | 000,023,888 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\NAVG.QTC
[2013/08/19 06:06:21 | 000,015,024 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTPIC.VBX
[2013/08/19 06:06:21 | 000,014,336 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTIMCMGR.DLL
[2013/08/19 06:06:21 | 000,010,944 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\REELMGIC.QTC
[2013/08/19 06:06:21 | 000,007,712 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTRAW.QTC
[2013/08/19 06:06:21 | 000,004,128 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTNOTIFY.EXE
[2013/08/19 06:06:20 | 000,060,992 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\PLAYER.EXE
[2013/08/19 06:06:20 | 000,047,712 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\VIEWER.EXE
[2013/08/19 06:06:20 | 000,017,536 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\VIEWENU.DLL
[2013/08/19 06:06:20 | 000,016,912 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\PLAYENU.DLL
[2013/08/19 06:06:20 | 000,008,320 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTHNDLR.DLL
[2013/08/19 06:06:20 | 000,007,312 | ---- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System32\QTOLD.QTC
[2013/08/19 06:06:18 | 000,249,856 | ---- | C] (Play Incorporated) -- C:\WINDOWS\System32\SNAP32N.DLL
[2013/08/19 06:06:18 | 000,202,752 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\PICN1112.DLL
[2013/08/19 06:06:18 | 000,097,568 | ---- | C] (Eastman Kodak) -- C:\WINDOWS\System32\DC50.DLL
[2013/08/19 06:06:18 | 000,034,816 | ---- | C] (Apple Computer, Inc. & Eastman Kodak) -- C:\WINDOWS\System32\QTAKE-D.DLL
[2013/08/19 06:06:17 | 000,078,544 | ---- | C] (Apple Computer, Inc. & Eastman Kodak Company) -- C:\WINDOWS\System32\QTAKE-I.DLL
[2013/08/19 06:06:17 | 000,020,992 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\PICN12.DLL
[2013/08/19 06:06:17 | 000,020,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CTL3D.DLL
[2013/08/19 06:06:14 | 000,000,000 | ---D | C] -- C:\PhotoDlx
[2013/08/19 01:53:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\taryn\Desktop\photo shop
[2013/08/18 17:48:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\StarApp
[2013/08/18 17:47:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Vaudix
[2013/08/18 17:46:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallMate
[2013/08/18 17:22:00 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/08/11 19:36:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\jason louis muthafucking kutyba.rip sister carrie ann kutyba_files
[2013/08/01 12:57:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\taryn\Desktop\untitled folder
[2013/07/31 04:11:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\AVG
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\taryn\My Documents\*.tmp files -> C:\Documents and Settings\taryn\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/08/27 06:16:00 | 000,000,282 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2013/08/27 06:15:00 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9FA917AF-EDD9-4124-9237-3392F6B80E4C}.job
[2013/08/27 06:02:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\taryn\Desktop\OTL.exe
[2013/08/27 05:53:00 | 000,000,246 | -H-- | M] () -- C:\WINDOWS\tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2013/08/27 05:43:17 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/08/27 04:57:10 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{C7008321-5B43-4F9C-85F2-4D328FD574B9}.job
[2013/08/27 04:52:34 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/08/27 04:52:07 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\tasks\Yegzj.job
[2013/08/27 04:52:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/08/26 16:21:22 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/08/26 16:21:20 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2013/08/26 16:21:20 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2013/08/26 16:21:20 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013/08/26 16:21:20 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013/08/26 16:21:20 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013/08/26 16:21:20 | 000,144,896 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013/08/26 12:11:16 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2013/08/26 06:51:25 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\taryn\Desktop\Internet.lnk
[2013/08/26 03:53:49 | 000,000,323 | -HS- | M] () -- C:\boot.ini
[2013/08/26 03:52:27 | 000,463,592 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/08/26 03:52:27 | 000,078,842 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/08/26 03:49:28 | 000,040,606 | ---- | M] () -- C:\Documents and Settings\taryn\Application Data\wklnhst.dat
[2013/08/25 23:00:00 | 000,000,398 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2013/08/25 23:00:00 | 000,000,398 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2013/08/23 23:00:50 | 000,097,995 | ---- | M] () -- C:\WINDOWS\unins000.dat
[2013/08/23 23:00:27 | 000,000,009 | ---- | M] () -- C:\END
[2013/08/23 22:56:25 | 001,169,609 | ---- | M] () -- C:\WINDOWS\unins000.exe
[2013/08/23 00:26:47 | 000,002,664 | ---- | M] () -- C:\Documents and Settings\taryn\My Documents\cc_20130823_002627.reg
[2013/08/21 20:45:23 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Google Chrome.lnk
[2013/08/21 07:51:57 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/08/21 07:51:56 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/08/19 11:46:39 | 000,001,757 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2013/08/19 11:41:03 | 000,002,893 | ---- | M] () -- C:\WINDOWS\ACROREAD.INI
[2013/08/19 09:44:44 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\taryn\Desktop\Spotify.lnk
[2013/08/19 06:06:14 | 000,000,171 | ---- | M] () -- C:\WINDOWS\KPCMS.INI
[2013/08/19 06:02:36 | 000,000,986 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2013/08/19 01:49:13 | 000,012,292 | -H-- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\.DS_Store
[2013/08/14 05:42:36 | 000,001,462 | RHS- | M] () -- C:\Documents and Settings\taryn\ntuser.pol
[2013/08/11 19:36:43 | 000,074,597 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\jason louis muthafucking kutyba.rip sister carrie ann kutyba.htm
[2013/08/07 22:07:51 | 007,886,336 | ---- | M] () -- C:\Documents and Settings\taryn\Desktop\setup.msi
[2013/08/04 00:08:21 | 000,006,481 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\th.jpg
[2013/08/03 23:47:39 | 000,020,449 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\biggest_dog6.jpg
[2013/07/31 18:51:33 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SSVerify.job
[2013/07/31 18:51:30 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2013/07/31 18:51:27 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\MaxPerformaSys.job
[2013/07/31 18:51:25 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/31 18:51:22 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/31 18:51:12 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/07/31 04:11:18 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2013.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\taryn\My Documents\*.tmp files -> C:\Documents and Settings\taryn\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\WINDOWS\System32\lekovaba
[2013/08/26 06:51:25 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\taryn\Desktop\Internet.lnk
[2013/08/23 23:00:50 | 001,169,609 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2013/08/23 23:00:50 | 000,097,995 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2013/08/23 00:26:37 | 000,002,664 | ---- | C] () -- C:\Documents and Settings\taryn\My Documents\cc_20130823_002627.reg
[2013/08/19 11:46:39 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe Reader 7.0.lnk
[2013/08/19 11:46:39 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2013/08/19 09:44:44 | 000,001,860 | ---- | C] () -- C:\Documents and Settings\taryn\Start Menu\Programs\Spotify.lnk
[2013/08/19 09:44:44 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\taryn\Desktop\Spotify.lnk
[2013/08/19 06:06:21 | 000,003,888 | ---- | C] () -- C:\WINDOWS\System32\MCIQTENU.DLL
[2013/08/19 06:06:18 | 000,078,944 | ---- | C] () -- C:\WINDOWS\System32\DC50IP.DLL
[2013/08/19 06:06:17 | 002,109,504 | ---- | C] () -- C:\WINDOWS\System32\KPT20HUB.DLL
[2013/08/19 06:02:36 | 000,000,986 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2013/08/19 06:02:35 | 000,000,819 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2013/08/19 06:02:35 | 000,000,814 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2013/08/11 19:36:42 | 000,074,597 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\jason louis muthafucking kutyba.rip sister carrie ann kutyba.htm
[2013/08/04 00:08:20 | 000,006,481 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\th.jpg
[2013/08/03 23:47:38 | 000,020,449 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Documents\biggest_dog6.jpg
[2013/07/24 01:09:48 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\taryn\Application Data\$_hpcst$.hpc
[2013/05/28 03:03:26 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\WlanApp.dll
[2013/05/28 03:03:26 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\JJAKEn.dll
[2011/01/08 00:14:54 | 000,000,454 | ---- | C] () -- C:\Program Files\010820110145407.bat
[2010/09/26 00:56:34 | 000,000,074 | ---- | C] () -- C:\Documents and Settings\taryn\PDPURCYL.exe
[2010/08/17 18:58:06 | 000,000,258 | ---- | C] () -- C:\Documents and Settings\taryn\Application Data\ANICONFIG_{105B27AF-92DD-49DE-A153-B5CA2C7FC4AC}.ini
[2010/07/21 08:48:46 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\taryn\dpdifomx.exe
[2010/02/08 23:39:43 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\taryn\Application Data\Launch Internet Explorer Browser.lnk
[2009/01/16 13:00:04 | 000,040,606 | ---- | C] () -- C:\Documents and Settings\taryn\Application Data\wklnhst.dat
[2009/01/04 08:43:03 | 000,000,978 | ---- | C] () -- C:\Program Files\reset_fp10.zip
[2008/12/31 20:04:13 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\taryn\Local Settings\Application Data\fusioncache.dat
[2008/12/31 16:22:08 | 000,040,448 | ---- | C] () -- C:\Documents and Settings\taryn\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/26 01:51:59 | 000,001,462 | RHS- | C] () -- C:\Documents and Settings\taryn\ntuser.pol
========== ZeroAccess Check ==========
[2008/12/31 19:58:41 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 17:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll -- [2008/04/13 17:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2009/08/07 01:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ACASystems
[2013/07/20 06:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2013
[2009/12/28 10:02:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2007/11/27 00:36:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2010/06/16 20:02:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Driver Whiz
[2009/11/26 21:07:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IM
[2009/11/26 21:05:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IncrediMail
[2013/08/18 17:48:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallMate
[2013/08/27 05:20:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2011/01/08 00:14:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Oberon Media
[2011/01/02 22:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\oDbNi06300
[2009/03/08 11:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Drivers HeadQuarters
[2007/11/29 22:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ralink Driver
[2010/03/08 09:25:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\RegCure
[2010/01/18 09:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SITEguard
[2013/08/18 17:48:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\StarApp
[2010/01/21 01:37:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\STOPzilla!
[2008/02/14 13:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/01/27 10:20:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
[2013/08/18 17:47:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Vaudix
[2010/09/20 09:48:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\VirtualizedApplications
[2007/11/26 08:34:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\W3i
[2011/07/06 00:04:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WildTangent
[2007/11/26 16:54:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Wyeke
[2009/03/15 10:34:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/07/06 11:52:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/25 12:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/07 01:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\ACASystems
[2007/11/26 15:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\AVG10
[2013/07/20 06:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\AVG2013
[2013/07/10 15:07:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\AVSoftware
[2007/11/26 06:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Babylon
[2009/12/10 02:48:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\blinkx
[2010/03/13 00:25:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Cricket
[2010/06/28 12:00:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\FixCleaner
[2009/03/14 09:47:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\GetRightToGo
[2010/01/25 14:59:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Jasc
[2007/11/29 23:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\mjusbsp
[2009/04/02 10:10:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\OfficeUpdate12
[2009/11/09 08:10:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Password Solutions
[2013/08/24 04:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\PriceGong
[2013/07/24 01:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\SearchProtect
[2010/08/07 02:55:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\SmartDraw
[2010/05/16 12:48:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Smilebox
[2010/10/13 12:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\SoftGrid Client
[2013/08/19 10:28:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Spotify
[2010/08/03 06:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\TP
[2013/05/10 00:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\TuneUp Software
[2010/01/30 10:11:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Ulead Systems
[2010/03/08 09:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\taryn\Application Data\Uniblue
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/13 21:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS.0\explorer.exe
[2008/04/13 21:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS.0\system32\dllcache\explorer.exe
[2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 04:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
[2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
[2004/08/04 00:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2013/08/27 04:53:02 | 000,081,734 | ---- | M] () MD5=0DF4B5BAD066817FE99421D8CA8FDBBA -- C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.HTM >
[2005/01/19 15:25:42 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\da\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:26:08 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\fi\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2003/09/15 11:06:02 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:26:42 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\ko\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\nl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:26:58 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\no\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\pt-BR\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 14:42:18 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\ru\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:27:14 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\sv\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\zh-CHS\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 15:44:52 | 000,002,057 | ---- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 -- C:\Program Files\ATI Technologies\ATI.ACE\zh-CHT\Help\wwhelp\wwhimpl\java\html\explorer.htm
< MD5 for: EXPLORER.SCF >
[2001/08/23 04:00:00 | 000,000,080 | ---- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 -- C:\WINDOWS.0\explorer.scf
[2001/08/23 05:00:00 | 000,000,080 | ---- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 -- C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | ---- | M] () MD5=1435F4731719DF5F57D17DC38196245D -- C:\WINDOWS\Help\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | ---- | M] () MD5=1435F4731719DF5F57D17DC38196245D -- C:\WINDOWS\ie7\iexplore.chm
[2007/04/02 14:09:24 | 000,204,810 | ---- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE -- C:\WINDOWS.0\Help\iexplore.chm
[2004/07/17 11:40:18 | 000,204,810 | ---- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE -- C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | ---- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Pictures\idunnos\63822586338664cd4ad81323\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | ---- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 -- C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.CHW >
[2011/02/13 04:54:44 | 000,153,185 | ---- | M] () MD5=E51A8C3B101F290C26A48EEE51C8AC0A -- C:\Documents and Settings\tryme\Application Data\Microsoft\HTML Help\iexplore.chw
< MD5 for: IEXPLORE.EXE >
[2009/06/29 00:25:31 | 000,634,632 | ---- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD -- C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 22:25:25 | 000,634,024 | ---- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 -- C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2008/10/14 23:34:58 | 000,633,632 | ---- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E -- C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2009/04/24 22:27:50 | 000,636,088 | ---- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 -- C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 22:25:30 | 000,634,024 | ---- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 -- C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2009/08/26 22:18:42 | 000,634,648 | ---- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 -- C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 01:35:10 | 000,634,632 | ---- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD -- C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/27 23:54:16 | 000,634,632 | ---- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB -- C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 06:05:43 | 000,634,648 | ---- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 -- C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/13 21:42:24 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 -- C:\WINDOWS.0\system32\dllcache\iexplore.exe
[2008/04/13 21:42:24 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 -- C:\WINDOWS\ie7\iexplore.exe
[2008/04/13 17:12:22 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 -- C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/10/27 23:54:21 | 000,634,632 | ---- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 -- C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2008/10/15 00:06:26 | 000,633,632 | ---- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB -- C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 21:54:41 | 000,636,072 | ---- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 -- C:\WINDOWS\SoftwareDistribution\Download\263159e92061f273983a0f9531635ce0\sp3gdr\iexplore.exe
[2010/04/16 04:08:29 | 000,634,648 | ---- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 -- C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/22 22:20:02 | 000,634,648 | ---- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 -- C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 21:54:44 | 000,636,088 | ---- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 -- C:\WINDOWS\SoftwareDistribution\Download\263159e92061f273983a0f9531635ce0\sp3qfe\iexplore.exe
[2009/04/24 22:27:39 | 000,636,088 | ---- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C -- C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 04:43:25 | 000,634,656 | ---- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 -- C:\WINDOWS\ie8\iexplore.exe
[2010/02/22 22:19:59 | 000,634,648 | ---- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 -- C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 00:00:27 | 000,634,632 | ---- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A -- C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | ---- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Pictures\idunnos\63822586338664cd4ad81323\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | ---- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 -- C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2004/08/04 00:56:52 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 -- C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2009/08/26 22:18:44 | 000,634,648 | ---- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA -- C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | ---- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Pictures\idunnos\63822586338664cd4ad81323\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/08/27 05:53:02 | 000,096,346 | ---- | M] () MD5=A54E60EADC1F7BDA326E84BA70DB43AB -- C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
[2013/07/21 01:57:44 | 000,044,124 | ---- | M] () MD5=DB2763688AB3413AD5084D1626DBDBCF -- C:\WINDOWS.0\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2001/08/23 04:00:00 | 000,180,335 | ---- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 -- C:\WINDOWS.0\Help\iexplore.hlp
[2001/08/23 05:00:00 | 000,180,335 | ---- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 -- C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2001/08/23 04:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS.0\system32\drivers\etc\services
[2001/08/23 05:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.EXE >
[2009/02/06 04:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS.0\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/06 04:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 21:42:36 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS.0\$NtUninstallKB956572$\services.exe
[2008/04/13 17:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 04:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS.0\system32\dllcache\services.exe
[2009/02/06 04:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS.0\system32\services.exe
[2009/02/06 04:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 04:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe
[2004/08/04 00:56:56 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SERVICES.HTML >
[2011/01/07 10:06:09 | 000,005,334 | ---- | M] () MD5=A33CF6EB7CC2AAD518DB5543E8E5239B -- C:\Documents and Settings\tryme\Desktop\build\us\lib\sites\Celestial Terrestrial\sitebuilder\preview\services.html
[2011/01/07 10:06:09 | 000,005,572 | ---- | M] () MD5=AF50F1A7EF49F64A0DBBF0683DDD8B30 -- C:\Documents and Settings\tryme\Desktop\build\us\lib\sites\Celestial Terrestrial\services.html
< MD5 for: SERVICES.LNK >
[2010/03/08 09:18:30 | 000,001,602 | ---- | M] () MD5=5186AAFCAFF51667064BC28351F722F7 -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
[2010/03/08 09:18:58 | 000,001,602 | ---- | M] () MD5=577B640BAAAEB22E8A7F8C26F94C282F -- C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Administrative Tools\Services.lnk
[2010/03/08 09:18:50 | 000,001,602 | ---- | M] () MD5=D711D3F8A17192E4BB44C1EF77B7ADFB -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2001/08/23 04:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS.0\system32\services.msc
[2001/08/23 05:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS\system32\services.msc
< MD5 for: WINLOGON.EXE >
[2004/08/04 00:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 21:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS.0\system32\dllcache\winlogon.exe
[2008/04/13 21:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS.0\system32\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2007/11/26 16:13:36 | 000,000,000 | ---- | M] () -- C:\asdasd.asdasd
[2007/11/26 16:13:36 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2013/08/26 03:53:49 | 000,000,323 | -HS- | M] () -- C:\boot.ini
[2007/11/26 16:13:36 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2013/08/23 23:00:27 | 000,000,009 | ---- | M] () -- C:\END
[2010/05/28 01:03:35 | 000,000,521 | ---- | M] () -- C:\hpfr3420.xml
[2010/05/28 01:03:33 | 000,002,823 | ---- | M] () -- C:\hpfr3425.log
[2007/11/26 16:13:36 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/11/26 16:13:36 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/04/13 14:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 16:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2009/12/19 18:43:24 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2009/12/19 18:43:24 | 000,001,024 | -H-- | M] () -- C:\ntuser.dat.LOG
[2013/08/27 04:51:51 | 738,197,503 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/12/26 04:52:31 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 03:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2006/06/16 17:31:22 | 000,106,496 | ---- | M] (Nova Development.) -- C:\WINDOWS\UPSCR.Scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2007/11/26 10:36:45 | 000,001,310 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Favorites\WildTangent Games.lnk
< %APPDATA%\Microsoft\*.* >
[2010/06/23 16:58:25 | 000,001,826 | -H-- | M] () -- C:\Documents and Settings\taryn\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2011/01/08 00:14:55 | 000,000,454 | ---- | M] () -- C:\Program Files\010820110145407.bat
[2009/01/04 08:55:56 | 000,000,978 | ---- | M] () -- C:\Program Files\reset_fp10.zip
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is BC85-A62E
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
06/02/2011 03:10 AM <JUNCTION> 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
06/02/2011 03:09 AM <JUNCTION> 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
2 Dir(s) 34,741,161,984 bytes free
< %systemroot%\System32\config\*.sav >
[2008/12/25 21:18:38 | 000,090,112 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008/12/25 21:18:38 | 000,630,784 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008/12/25 21:18:38 | 000,413,696 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/04/03 13:17:54 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2010/01/12 14:23:13 | 000,005,632 | -HS- | M] () -- C:\WINDOWS\system32\Thumbs.db
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/03 13:55:01 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\taryn\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/12/26 05:08:39 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\taryn\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2013/08/27 06:02:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\taryn\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-11 08:35:19
< >
[2007/11/26 07:07:27 | 000,000,880 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2007/11/26 07:07:28 | 000,000,884 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2007/11/26 13:11:52 | 000,000,246 | -H-- | C] () -- C:\WINDOWS\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2007/11/26 13:11:55 | 000,000,282 | -H-- | C] () -- C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2007/11/26 13:11:59 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2007/11/26 13:12:41 | 000,000,310 | -HS- | C] () -- C:\WINDOWS\Tasks\Yegzj.job
[2008/12/26 04:50:34 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2008/12/26 04:52:41 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/02/04 18:07:31 | 000,000,284 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2010/01/07 06:45:01 | 000,000,294 | ---- | C] () -- C:\WINDOWS\Tasks\ckzbekkl.job
[2010/08/05 12:32:14 | 000,000,422 | -H-- | C] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{C7008321-5B43-4F9C-85F2-4D328FD574B9}.job
[2010/12/31 04:09:01 | 000,000,234 | ---- | C] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/01/03 08:37:20 | 000,000,398 | ---- | C] () -- C:\WINDOWS\Tasks\At1.job
[2011/01/03 08:40:20 | 000,000,398 | ---- | C] () -- C:\WINDOWS\Tasks\At2.job
[2011/01/04 13:18:46 | 000,000,422 | -H-- | C] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{9FA917AF-EDD9-4124-9237-3392F6B80E4C}.job
[2013/07/10 15:07:57 | 000,000,292 | ---- | C] () -- C:\WINDOWS\Tasks\MaxPerformaSys.job
[2013/07/10 15:08:55 | 000,000,256 | ---- | C] () -- C:\WINDOWS\Tasks\SSVerify.job
[2013/07/20 07:33:03 | 000,000,830 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
========== Alternate Data Streams ==========
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\All Users.WINDOWS\Documents\.DS_Store:AFP_AfpInfo
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:373E1720
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:45FE2B4E
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:7E95B6FD
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A8ADE5D8
< End of report >