========== Files/Folders - Created Within 30 Days ========== [2010/04/11 21:55:04 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\yo\Desktop\OTL.exe
[2010/04/11 18:33:20 | 000,000,195 | ---- | C] () -- C:\Documents and Settings\yo\mbr.log
[2010/04/11 18:23:34 | 000,000,000 | ---D | C] -- C:\HelpAsst_backup
[2010/04/06 16:30:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/04/06 10:15:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\DoctorWeb
[2010/04/06 00:35:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/04/05 17:46:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2010/04/05 17:29:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Application Data\Avira
[2010/04/05 17:27:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Application Data\PCToolsFirewallPlus
[2010/04/05 17:23:18 | 000,070,664 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.sys
[2010/04/05 17:23:18 | 000,032,680 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis-DNS.sys
[2010/04/05 17:23:15 | 000,115,216 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplfw.sys
[2010/04/05 17:23:10 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools Firewall Plus
[2010/04/05 17:19:00 | 000,233,136 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/04/05 17:18:53 | 000,217,032 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/04/05 17:18:53 | 000,088,040 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/04/05 17:18:47 | 000,070,408 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/04/05 17:18:32 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/04/05 17:18:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/04/05 17:18:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Application Data\PC Tools
[2010/04/05 17:18:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/04/05 17:08:37 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/04/05 17:08:35 | 000,124,784 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/04/05 17:08:35 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/04/05 17:08:35 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/04/05 17:08:34 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2010/04/05 17:08:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2010/04/05 16:42:40 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2010/04/05 16:37:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/04/05 16:02:53 | 000,000,000 | --SD | C] -- C:\commy29599c
[2010/04/05 15:59:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WEBREG
[2010/04/05 15:58:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Application Data\HP
[2010/04/05 15:23:03 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/05 15:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/05 15:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/05 15:23:02 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/04/04 21:52:35 | 000,118,272 | ---- | C] (Hewlett-Packard Company) -- C:\WINDOWS\System32\hpz3l696.dll
[2010/04/04 21:04:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Application Data\HPAppData
[2010/04/04 20:35:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Local Settings\Application Data\ArcSoft
[2010/04/04 20:35:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ArcSoft
[2010/04/04 20:35:29 | 000,000,000 | ---D | C] -- C:\Program Files\ArcSoft
[2010/04/04 20:35:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ArcSoft
[2010/04/04 20:35:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\Application Data\ArcSoft
[2010/04/04 20:33:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2010/04/04 20:32:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP
[2010/04/04 20:32:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2010/04/04 19:54:54 | 000,372,736 | ---- | C] (Hewlett-Packard) -- C:\WINDOWS\System32\hppldcoi.dll
[2010/04/04 19:54:54 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\difxapi.dll
[2010/04/04 19:54:52 | 000,271,704 | ---- | C] (Hewlett-Packard) -- C:\WINDOWS\System32\hpzids01.dll
[2010/04/04 19:54:40 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2010/04/04 19:52:14 | 000,003,993 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/04/04 16:11:51 | 000,000,000 | --SD | C] -- C:\commy
[2010/04/04 15:57:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/04/04 15:57:41 | 000,000,000 | ---D | C] -- C:\Program Files\NOS
[2010/04/04 04:54:36 | 000,052,608 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nvatabus_2.sys
[2010/04/04 04:51:56 | 000,000,000 | ---D | C] -- C:\cmdcons
[2010/04/04 04:51:10 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/04/04 04:51:10 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/04/04 04:51:10 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/04/04 04:51:10 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/04/04 04:50:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/04/04 04:50:55 | 000,000,000 | --SD | C] -- C:\Combo-Fix
[2010/04/04 04:49:52 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/04/04 03:36:18 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/04 03:36:15 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/04 03:36:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/04 02:11:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\yo\My Documents\Downloads
[2010/03/24 09:38:26 | 000,199,432 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\neti1639.sys
[2010/03/20 19:24:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Backup
[2010/03/20 19:23:53 | 000,446,464 | ---- | C] (eHelp Corporation.) -- C:\WINDOWS\System32\HHActiveX.dll
[2010/03/19 22:14:02 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/03/19 11:30:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\McAfee.com
[2010/03/19 10:52:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2010/03/19 10:05:33 | 000,157,712 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/03/09 20:04:42 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\yo\Application Data\netstat.bat
[2010/02/08 18:50:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/02/08 17:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/02/08 17:50:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Google
[2010/02/08 17:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/02/04 20:23:07 | 000,054,093 | ---- | C] () -- C:\Program Files\EULA.eng
[2010/01/29 20:28:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/01/14 13:36:11 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\yo\Local Settings\Application Data\housecall.guid.cache
[2010/01/13 12:53:49 | 001,605,658 | -H-- | C] () -- C:\Documents and Settings\yo\Local Settings\Application Data\IconCache.db
[2009/11/12 11:34:32 | 000,000,063 | ---- | C] () -- C:\Documents and Settings\yo\jagex_runescape_preferences2.dat
[2009/06/20 14:54:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\SACore
[2009/06/18 11:02:46 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\yo\GoToAssistDownloadHelper.exe
[2009/04/15 05:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\NVIDIA Corporation
[2009/04/07 16:05:29 | 000,049,152 | ---- | C] () -- C:\Documents and Settings\yo\PNPrint3.exe
[2008/12/22 16:09:41 | 013,631,488 | ---- | C] () -- C:\Documents and Settings\yo\ntuser.dat
[2008/10/22 18:49:34 | 000,000,074 | ---- | C] () -- C:\Documents and Settings\yo\default.pls
[2008/09/29 12:50:33 | 000,009,638 | ---- | C] () -- C:\Documents and Settings\yo\TraceLog.txt
[2008/07/12 20:30:37 | 000,000,038 | ---- | C] () -- C:\Documents and Settings\yo\jagex_runescape_preferences.dat
[2008/03/05 09:55:29 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\yo\PUTTY.RND
[2008/01/29 13:55:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/01/17 20:41:27 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\yo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/13 00:12:27 | 000,000,968 | RHS- | C] () -- C:\Documents and Settings\yo\ntuser.pol
[2008/01/12 23:02:56 | 000,205,416 | ---- | C] () -- C:\Documents and Settings\yo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/01/12 15:33:45 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\yo\ntuser.dat.LOG
[2008/01/12 15:33:45 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\yo\ntuser.ini
[2008/01/12 15:33:45 | 000,000,062 | -HS- | C] () -- C:\Documents and Settings\yo\Application Data\desktop.ini
[2008/01/12 10:03:52 | 000,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2007/04/09 13:32:58 | 000,033,792 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2006/06/29 14:58:52 | 000,030,808 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\yo\My Documents\*.tmp files -> C:\Documents and Settings\yo\My Documents\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\yo\*.tmp files -> C:\Documents and Settings\yo\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/04/11 22:37:06 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/11 21:55:10 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\yo\Desktop\OTL.exe
[2010/04/11 21:50:54 | 013,631,488 | ---- | M] () -- C:\Documents and Settings\yo\ntuser.dat
[2010/04/11 19:49:31 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/04/11 19:48:35 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/11 19:48:25 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/11 19:48:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/04/11 19:24:45 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\yo\ntuser.ini
[2010/04/11 19:24:12 | 004,958,588 | ---- | M] () -- C:\WINDOWS\{00000001-00000000-00000008-00001102-00000004-20021102}.CDF
[2010/04/11 19:24:12 | 004,958,588 | ---- | M] () -- C:\WINDOWS\{00000001-00000000-00000008-00001102-00000004-20021102}.BAK
[2010/04/11 18:23:09 | 000,016,023 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\prob.docx
[2010/04/11 18:20:22 | 000,490,008 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\HelpAsst_mebroot_fix.exe
[2010/04/10 10:29:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/10 07:42:56 | 005,687,914 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\Vinyl.eps
[2010/04/09 23:10:20 | 037,038,904 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\65b2mypv.exe
[2010/04/09 22:13:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/04/09 15:34:40 | 000,077,312 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\mbr.exe
[2010/04/08 19:24:38 | 000,012,963 | ---- | M] () -- C:\Documents and Settings\yo\My Documents\Signs for Chippokes Estates.docx
[2010/04/07 22:33:16 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/06 16:31:01 | 000,104,381 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\hl=en&tab=wl20.pdf
[2010/04/06 16:12:05 | 000,103,618 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\hl=en&tab=wl.pdf
[2010/04/06 12:53:02 | 000,000,789 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/05 16:02:06 | 003,907,460 | R--- | M] () -- C:\Documents and Settings\yo\Desktop\commy.exe
[2010/04/05 16:00:39 | 000,152,184 | ---- | M] () -- C:\WINDOWS\hphins29.dat
[2010/04/04 20:37:21 | 000,001,954 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Add a Device - Photosmart B8500 series.lnk
[2010/04/04 20:34:48 | 000,001,930 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2010/04/04 20:34:36 | 000,001,870 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 3.5.lnk
[2010/04/04 20:33:46 | 000,001,808 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/04/04 20:33:28 | 000,001,018 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2010/04/04 19:50:51 | 198,219,864 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\PS_BSIZE_04_B8500_NonNet_Full_Win_enu_120_217.exe
[2010/04/04 13:14:18 | 000,003,188 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\Easter.nra
[2010/04/04 04:52:06 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/04/04 03:36:21 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/31 16:01:59 | 000,008,627 | ---- | M] () -- C:\WINDOWS\System32\PAV_FOG.OPC
[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/24 11:09:52 | 000,031,056 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000001-00000000-00000008-00001102-00000004-20021102}.rfx
[2010/03/24 11:09:52 | 000,031,056 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000001-00000000-00000008-00001102-00000004-20021102}.rfx
[2010/03/24 11:09:52 | 000,030,528 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000001-00000000-00000008-00001102-00000004-20021102}.rfx
[2010/03/24 11:09:52 | 000,030,528 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000001-00000000-00000008-00001102-00000004-20021102}.rfx
[2010/03/24 11:09:52 | 000,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000001-00000000-00000008-00001102-00000004-20021102}.rfx
[2010/03/24 11:09:52 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010/03/24 11:09:52 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010/03/24 09:46:57 | 000,000,691 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/03/24 09:41:54 | 000,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/24 09:41:54 | 000,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/24 09:41:52 | 000,513,516 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/23 14:13:45 | 001,842,856 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/22 12:50:22 | 000,205,416 | ---- | M] () -- C:\Documents and Settings\yo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/20 11:12:40 | 000,067,584 | ---- | M] () -- C:\Documents and Settings\yo\My Documents\Antony E.doc
[2010/03/15 19:21:04 | 000,000,036 | -H-- | M] () -- C:\WINDOWS\System32\f9t.dat
[2010/03/15 17:15:00 | 000,559,862 | ---- | M] () -- C:\Documents and Settings\yo\Desktop\PhotoBrent.jpg
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\yo\My Documents\*.tmp files -> C:\Documents and Settings\yo\My Documents\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\yo\*.tmp files -> C:\Documents and Settings\yo\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/04/11 18:20:21 | 000,490,008 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\HelpAsst_mebroot_fix.exe
[2010/04/10 07:42:48 | 005,687,914 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\Vinyl.eps
[2010/04/09 23:10:19 | 037,038,904 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\65b2mypv.exe
[2010/04/09 15:34:40 | 000,077,312 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\mbr.exe
[2010/04/07 22:33:16 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/06 16:31:01 | 000,104,381 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\hl=en&tab=wl20.pdf
[2010/04/06 16:12:05 | 000,103,618 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\hl=en&tab=wl.pdf
[2010/04/06 16:09:30 | 000,012,963 | ---- | C] () -- C:\Documents and Settings\yo\My Documents\Signs for Chippokes Estates.docx
[2010/04/05 17:23:18 | 000,007,435 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.cat
[2010/04/05 17:23:18 | 000,007,399 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctNdis-DNS.cat
[2010/04/05 17:23:15 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctplfw.cat
[2010/04/05 17:19:00 | 000,007,387 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/04/05 17:18:53 | 000,007,412 | ---- | C] () -- C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/04/05 17:18:53 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2010/04/05 17:18:47 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/04/05 16:02:04 | 003,907,460 | R--- | C] () -- C:\Documents and Settings\yo\Desktop\commy.exe
[2010/04/04 20:37:29 | 000,001,060 | ---- | C] () -- C:\WINDOWS\hphmdl29.dat.temp
[2010/04/04 20:37:21 | 000,001,954 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Add a Device - Photosmart B8500 series.lnk
[2010/04/04 20:34:48 | 000,001,930 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2010/04/04 20:34:36 | 000,001,870 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 3.5.lnk
[2010/04/04 20:33:46 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/04/04 20:33:28 | 000,001,018 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2010/04/04 19:52:14 | 000,152,184 | ---- | C] () -- C:\WINDOWS\hphins29.dat
[2010/04/04 19:52:14 | 000,001,060 | ---- | C] () -- C:\WINDOWS\hphmdl29.dat
[2010/04/04 19:50:44 | 198,219,864 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\PS_BSIZE_04_B8500_NonNet_Full_Win_enu_120_217.exe
[2010/04/04 13:14:18 | 000,003,188 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\Easter.nra
[2010/04/04 12:03:36 | 000,016,023 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\prob.docx
[2010/04/04 04:52:06 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/04/04 04:52:01 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/04/04 04:51:10 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/04/04 04:51:10 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/04/04 04:51:10 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/04/04 04:51:10 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/04/04 04:51:10 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/04/04 03:36:21 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/24 12:17:13 | 000,008,627 | ---- | C] () -- C:\WINDOWS\System32\PAV_FOG.OPC
[2010/03/15 17:14:59 | 000,559,862 | ---- | C] () -- C:\Documents and Settings\yo\Desktop\PhotoBrent.jpg
[2009/09/28 21:44:10 | 000,000,038 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/02/13 23:28:05 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\MTictwl.sys
[2009/01/05 16:44:10 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2008/07/01 14:46:07 | 000,000,899 | ---- | C] () -- C:\WINDOWS\CadraViewExp.ini
[2008/06/29 09:39:31 | 001,936,528 | ---- | C] () -- C:\WINDOWS\System32\ltmm15.dll
[2008/05/09 16:42:24 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/04/24 00:20:00 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/01 21:03:21 | 000,025,339 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/01/14 13:56:19 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS61.DLL
[2008/01/14 12:32:14 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2008/01/13 19:29:15 | 000,086,446 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2008/01/13 19:29:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\CTXFIRES.DLL
[2008/01/13 19:29:15 | 000,000,191 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2008/01/13 13:33:55 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/01/12 22:24:48 | 000,024,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\GVTDrv.sys
[2008/01/12 20:24:20 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\idecoi.dll
[2008/01/12 15:58:54 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/12/05 02:41:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/12/05 02:41:00 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/12/05 02:41:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/12/05 02:41:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/12/05 02:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/10/26 14:28:18 | 000,197,408 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2007/10/26 14:28:04 | 000,193,312 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/03/12 12:01:30 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2007/03/09 03:12:32 | 000,027,648 | -HS- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2007/03/06 05:14:48 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007/03/06 05:14:48 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007/01/25 13:31:36 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2006/08/11 15:57:18 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\CTBURST.DLL
[2006/07/25 14:57:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[2006/05/23 13:40:34 | 000,000,269 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2005/06/16 19:17:16 | 000,071,680 | ---- | C] () -- C:\WINDOWS\System32\CTMMACTL.DLL
========== LOP Check ========== [2009/08/05 23:08:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2008/01/27 14:07:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avery
[2010/03/20 19:24:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Backup
[2008/06/02 14:46:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/12/01 01:20:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2008/08/02 16:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
[2008/12/15 11:46:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2010/02/21 08:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\F-Secure
[2008/06/02 19:32:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2008/01/12 21:51:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/07/12 23:06:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Maxtor
[2008/12/23 17:31:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2010/02/23 12:30:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/02/23 15:29:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/08/22 11:19:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/04/11 19:55:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/04 16:06:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/15 11:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2009/09/03 13:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/26 21:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8737778F-82C6-4680-A660-E8B2B8C8C22B}
[2009/04/26 21:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{876C6265-922D-4EF3-A784-71D72FF033C0}
[2009/04/26 21:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{B0AFCE64-DF3F-4824-8985-B21DB0EEE07B}
[2008/01/14 13:47:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{D9AA4D17-9292-410D-9AA5-84526D062900}
[2008/08/14 11:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\1&1
[2008/09/29 02:11:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\3M
[2009/08/05 23:10:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\acccore
[2009/12/25 17:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Alien Skin
[2008/12/15 11:46:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\eBay
[2010/04/05 22:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Facebook
[2008/06/02 19:32:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Flood Light Games
[2008/11/22 15:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\GetRightToGo
[2008/06/29 22:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\GrabPro
[2009/01/16 19:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\ICAClient
[2010/04/04 13:17:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\LimeWire
[2010/04/05 22:36:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\mjusbsp
[2008/04/13 13:21:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Opera
[2008/06/30 12:09:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Orbit
[2010/04/05 17:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\PCToolsFirewallPlus
[2009/02/01 23:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Pogo Games
[2008/12/23 17:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Runaware
[2008/04/27 16:48:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Simple Star
[2008/10/29 12:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Snapfish
[2008/01/14 13:48:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Stamps.com Internet Postage
[2010/02/03 08:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Windows Desktop Search
[2008/12/14 20:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\Windows Search
[2008/06/29 09:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\yo\Application Data\YouSendIt
[2010/04/09 22:13:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >[2002/08/29 08:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 03:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATABUS.SYS >[2003/04/21 15:18:00 | 000,052,608 | R--- | M] (NVIDIA Corporation) MD5=F45FDCB8D45439459A6B738AEF45AA94 -- C:\WINDOWS\system32\drivers\nvatabus.sys
[2003/04/21 15:18:00 | 000,052,608 | R--- | M] (NVIDIA Corporation) MD5=F45FDCB8D45439459A6B738AEF45AA94 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\nvatabus.sys
< MD5 for: SCECLI.DLL >[2004/08/04 03:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[10 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > ========== Alternate Data Streams ========== @Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07348C09
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05113FB9
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73EAFFB
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A6AFE3D
< End of report >
< MD5 for: [2003/04/21 15:18:00 | 000,052,608 | R--- | M] (NVIDIA CORPORATION) >[2003/04/21 15:18:00 | 000,052,608 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvatabus.sys
[2003/04/21 15:18:00 | 000,052,608 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\nvatabus.sys
< MD5 for: [2004/08/04 01:59:42 | 000,095,360 | ---- | M] (MICROSOFT CORPORATION) >[2004/08/04 01:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: [2004/08/04 02:07:41 | 000,042,368 | ---- | M] (MICROSOFT CORPORATION) >[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: [2004/08/04 03:56:42 | 000,055,808 | ---- | M] (MICROSOFT CORPORATION) >[2004/08/04 03:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: [2004/08/04 03:56:44 | 000,180,224 | ---- | M] (MICROSOFT CORPORATION) >[2004/08/04 03:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: [2004/08/04 03:56:44 | 000,407,040 | ---- | M] (MICROSOFT CORPORATION) >[2004/08/04 03:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: [2008/04/13 14:36:38 | 000,042,368 | ---- | M] (MICROSOFT CORPORATION) >[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: [2008/04/13 14:40:30 | 000,096,512 | ---- | M] (MICROSOFT CORPORATION) >[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: [2008/04/13 20:11:53 | 000,056,320 | ---- | M] (MICROSOFT CORPORATION) >[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: [2008/04/13 20:12:01 | 000,407,040 | ---- | M] (MICROSOFT CORPORATION) >[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: [2008/04/13 20:12:05 | 000,181,248 | ---- | M] (MICROSOFT CORPORATION) >[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< MD5 for: AGP440.SYS >[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >[2002/08/29 08:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/01/12 22:35:44 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/09/24 22:09:36 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[10 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles >< End of report >
............................................................................................Obstacles are what you see when you take your eyes off your GOALSNet_Surfer is a
Graduate of BleepingComputer: Malware Removal Training Program You too could train to help others!