Not always, but often when I click on a link in Google or Yahoo, I get redirected to an advertising site of some sort. None of these sites have any domain or name in common. I've tried everything to fix this problem, but nothing seems to work. The malware has even removed my system restore points. Hitman Pro didn't do the trick, and Malwarebytes closes as soon as I open it (I've tried doing the mbam-clean, restart process and I still cant run Malwarebytes, not even in safe mode or off of a memory stick). This seems to be a very powerful virus, as other programs (such as my HP printing console) refuse to open anymore. Please help me! Thanks in advance.
Here is the HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:07:15 PM, on 7/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys\WUSB300N\WLService.exe
C:\Program Files\Linksys\WUSB300N\WUSB300N.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Hojjat Adeli\My Documents\Downloads\OTL.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.netscape.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.226 osguardpro.microsoft.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HitmanPro35] "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" /scan:boot
O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Mozilla Firefox.lnk = C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: connection manager.lnk = ?
O4 - Global Startup: hpzrcv01.LNK = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247105164671
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1247105132184
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Network Associates McShield (McShield) - Unknown owner - C:\Program Files\Network Associates\VirusScan\mcshield.exe (file missing)
O23 - Service: Network Associates Task Manager (McTaskManager) - Unknown owner - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe (file missing)
O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe
O24 - Desktop Component 0: (no name) - http://www.pbs.org/wnet/gperf/alvinailey/assets/duplicate6/backgroundplain.gif
--
End of file - 7666 bytes
C:\Documents and Settings\Hojjat Adeli\Desktop\CCleaner.lnk
[2010/07/25 15:24:59 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/25 14:01:33 | 000,001,663 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Hitman Pro 3.5.lnk
[2010/07/13 23:44:12 | 000,000,892 | ---- | C] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/07/13 23:44:12 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2010/02/14 16:33:48 | 000,015,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/01/21 21:18:10 | 000,000,398 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2010/01/21 21:17:49 | 000,001,205 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2010/01/21 21:16:29 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\HPPCPR01.DLL
[2009/10/13 18:29:18 | 000,001,044 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2009/10/13 18:15:05 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2009/10/11 12:54:01 | 000,520,267 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2009/07/06 23:51:16 | 000,000,079 | ---- | C] () -- C:\WINDOWS\uascasio.INI
[2009/07/06 23:47:57 | 000,557,056 | ---- | C] () -- C:\WINDOWS\System32\UascAsio.dll
[2009/06/21 14:51:09 | 000,000,371 | ---- | C] () -- C:\WINDOWS\GearBox.ini
[2009/02/17 16:59:10 | 000,106,496 | ---- | C] () -- C:\WINDOWS\acufutls.dll
[2008/05/16 03:10:13 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/08/26 18:19:59 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2006/01/15 12:00:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/06/12 20:59:10 | 000,001,827 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005/04/25 14:31:35 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A6W.INI
[2005/01/21 12:54:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcf.INI
[2005/01/07 14:09:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2005/01/04 15:14:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PCFriend.INI
[2003/10/15 17:43:46 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\ISODisk.sys
[2003/08/23 13:59:34 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Brpcfx.ini
[2003/08/23 13:59:29 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2003/08/23 13:59:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2003/08/18 20:21:59 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2003/08/18 20:21:51 | 000,000,037 | ---- | C] () -- C:\WINDOWS\TB50.INI
[2003/08/17 11:20:33 | 000,001,253 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2003/08/17 11:20:22 | 000,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
[2003/08/17 11:20:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
[2003/08/17 11:20:22 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
[2003/08/17 11:20:00 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
[2003/08/16 15:33:16 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\mdcgina.dll
[2003/02/22 14:07:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2003/02/22 13:42:06 | 000,000,134 | ---- | C] () -- C:\WINDOWS\KIDSOFT.INI
[2003/02/21 23:17:59 | 000,000,603 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2003/02/21 23:17:55 | 000,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI
[2003/02/18 22:06:19 | 000,000,451 | ---- | C] () -- C:\WINDOWS\yukon.ini
[2002/08/21 05:59:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2002/08/21 05:52:40 | 000,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2002/08/21 05:48:49 | 000,000,788 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/08/21 04:24:00 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2002/08/05 00:29:52 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2002/05/08 07:43:25 | 000,000,188 | -H-- | C] () -- C:\WINDOWS\Mmob864g5s3d6p.dll
[2002/03/26 21:18:24 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[2001/11/14 20:19:38 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1999/01/22 21:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/11 01:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 20:12:00 | 001,384,479 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\SYSTEM32\msvbvm60.dll
[28 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[28 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2001/11/14 19:22:22 | 000,090,112 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2001/11/14 19:22:22 | 000,606,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2001/11/14 19:22:22 | 000,380,928 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %systemroot%\system32\*.sys >
[2001/08/17 18:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ANSI.SYS
[2002/03/15 02:14:16 | 000,005,376 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\SYSTEM32\ATIICDXX.SYS
[2001/08/17 18:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\SYSTEM32\COUNTRY.SYS
[2003/09/25 22:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\SYSTEM32\GTNDIS5.sys
[2001/08/17 18:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\SYSTEM32\HIMEM.SYS
[2006/12/19 17:00:56 | 000,011,648 | ---- | M] (Hewlett-Packard Development Company) -- C:\WINDOWS\SYSTEM32\hpnucmp.sys
[2007/10/31 12:54:06 | 000,039,552 | ---- | M] (Hewlett-Packard Development Company) -- C:\WINDOWS\SYSTEM32\hpnuhub.sys
[2007/11/23 00:50:10 | 000,018,560 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\SYSTEM32\HPWPAUSB.sys
[2001/08/17 18:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\SYSTEM32\KEY01.SYS
[2002/08/29 00:23:06 | 000,042,537 | ---- | M] () -- C:\WINDOWS\SYSTEM32\keyboard.sys
[2007/09/27 01:00:02 | 000,470,912 | ---- | M] (Marvell Semiconductor, Inc) -- C:\WINDOWS\SYSTEM32\Mrvw243.sys
[2007/09/27 00:58:54 | 000,461,952 | ---- | M] (Marvell Semiconductor, Inc) -- C:\WINDOWS\SYSTEM32\Mrvw245.sys
[2001/08/17 18:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS.SYS
[2001/08/17 18:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS404.SYS
[2001/08/17 18:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS411.SYS
[2001/08/17 18:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS412.SYS
[2001/08/17 18:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS804.SYS
[2004/08/04 01:45:08 | 000,033,840 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio.sys
[2004/08/04 01:45:14 | 000,034,560 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio404.sys
[2004/08/04 01:45:10 | 000,035,648 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio411.sys
[2004/08/04 01:45:15 | 000,035,424 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio412.sys
[2004/08/04 01:45:12 | 000,034,560 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio804.sys
[2003/10/22 12:54:14 | 000,016,848 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\SYSTEM32\Pcandis4.sys
[2003/10/22 12:54:18 | 000,017,162 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\SYSTEM32\Pcandis5.sys
[2008/04/13 14:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\watchdog.sys
[2010/05/02 01:22:50 | 001,851,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\win32k.sys
[28 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2008/04/13 20:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv01nt5.dll
[2008/04/13 20:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv02nt5.dll
[2008/04/13 20:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv05nt5.dll
[2008/04/13 20:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv07nt5.dll
[2008/04/13 20:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv08nt5.dll
[2008/04/13 20:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv09nt5.dll
[2008/04/13 20:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv11nt5.dll
[2008/04/13 20:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv01nt5.dll
[2008/04/13 20:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv02nt5.dll
[2008/04/13 20:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv04nt5.dll
[2008/04/13 20:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv06nt5.dll
[2008/04/13 20:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv10nt5.dll
[2008/04/13 20:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ch7xxnt5.dll
[2003/09/02 00:00:00 | 000,184,320 | ---- | M] (Digidesign, A Division of Avid Teechnology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\Digiasio.dll
[2008/04/13 20:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\siint5.dll
[2008/04/13 20:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\vchnt5.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2001/11/14 19:31:14 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/06/30 14:38:43 | 000,000,212 | -HS- | M] () -- C:\BOOT.INI
[2001/11/14 04:35:22 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS
[2001/11/14 19:31:14 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2002/08/21 04:28:04 | 000,003,775 | RH-- | M] () -- C:\DELL.SDR
[2008/05/11 14:52:18 | 000,015,982 | ---- | M] () -- C:\drwtsn32.log
[2001/11/14 19:31:14 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2002/08/21 05:56:19 | 000,000,317 | -H-- | M] () -- C:\IPH.PH
[2001/11/14 19:31:14 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2006/09/18 16:59:48 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/07/08 23:32:47 | 000,250,048 | RHS- | M] () -- C:\NTLDR
[2010/07/25 15:34:28 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys
[2010/03/30 21:59:29 | 000,000,452 | ---- | M] () -- C:\rkill.log
[2010/07/25 15:34:57 | 000,000,746 | ---- | M] () -- C:\test.txt
< %PROGRAMFILES%\*. >
[2010/03/07 14:52:43 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica Beatcraft
[2010/07/25 13:14:41 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica Mixcraft 4
[2010/07/25 13:30:48 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica Shared Effects
[2009/10/11 20:38:07 | 000,000,000 | ---D | M] -- C:\Program Files\Addictive Drums
[2010/04/04 15:09:30 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2005/03/18 15:23:47 | 000,000,000 | ---D | M] -- C:\Program Files\Allen
[2010/02/28 23:38:03 | 000,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2005/03/03 16:27:11 | 000,000,000 | ---D | M] -- C:\Program Files\aod
[2010/01/24 18:11:22 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2003/10/24 20:17:26 | 000,000,000 | ---D | M] -- C:\Program Files\ASIO4ALL v2
[2010/04/17 22:40:07 | 000,000,000 | ---D | M] -- C:\Program Files\ATT
[2010/04/17 22:41:21 | 000,000,000 | ---D | M] -- C:\Program Files\ATT-PRT22-WISE
[2008/01/06 13:41:18 | 000,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2010/01/24 18:16:12 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2003/08/23 13:59:18 | 000,000,000 | ---D | M] -- C:\Program Files\Brother
[2007/12/25 17:35:55 | 000,000,000 | ---D | M] -- C:\Program Files\Canon
[2010/07/25 15:40:39 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/07/25 13:25:39 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2002/08/21 04:12:42 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2002/08/21 05:38:36 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2009/06/29 13:04:04 | 000,000,000 | ---D | M] -- C:\Program Files\delaydots
[2002/08/05 00:09:03 | 000,000,000 | ---D | M] -- C:\Program Files\Dell
[2002/08/21 05:56:36 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Computer
[2009/07/06 23:46:19 | 000,000,000 | ---D | M] -- C:\Program Files\Digidesign
[2005/01/05 21:42:07 | 000,000,000 | ---D | M] -- C:\Program Files\directx
[2007/05/15 22:39:53 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/04/05 21:29:51 | 000,000,000 | ---D | M] -- C:\Program Files\Easy CD & DVD Cover Creator
[2010/01/17 19:35:48 | 000,000,000 | ---D | M] -- C:\Program Files\EDIROL
[2010/02/28 23:32:53 | 000,000,000 | ---D | M] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2010/01/17 19:36:51 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/01/19 03:38:01 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2010/02/14 16:33:38 | 000,000,000 | ---D | M] -- C:\Program Files\Hitman Pro 3.5
[2010/01/19 03:44:33 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2010/01/18 00:45:58 | 000,000,000 | ---D | M] -- C:\Program Files\HP Wireless Printer Adapter
[2010/01/18 00:45:31 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2002/08/21 05:52:19 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2007/08/26 18:02:27 | 000,000,000 | ---D | M] -- C:\Program Files\InterActual
[2009/07/08 23:51:04 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/07/13 23:43:59 | 000,000,000 | ---D | M] -- C:\Program Files\IObit
[2003/10/15 17:43:46 | 000,000,000 | ---D | M] -- C:\Program Files\ISODisk
[2002/08/21 05:52:49 | 000,000,000 | ---D | M] -- C:\Program Files\Jasc Software Inc
[2010/03/07 15:03:03 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2006/07/30 14:23:21 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2003/01/15 06:01:59 | 000,000,000 | ---D | M] -- C:\Program Files\LEGO Media
[2008/11/17 17:45:50 | 000,000,000 | ---D | M] -- C:\Program Files\Line6
[2009/10/13 18:29:55 | 000,000,000 | ---D | M] -- C:\Program Files\Linksys
[2010/07/25 15:25:00 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2004/02/01 20:58:18 | 000,000,000 | ---D | M] -- C:\Program Files\Merriam-Webster
[2009/07/09 00:52:58 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2006/07/01 12:15:51 | 000,000,000 | ---D | M] -- C:\Program Files\MGI
[2010/01/18 03:23:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2007/05/09 20:26:11 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2002/08/21 04:15:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Encarta
[2002/11/18 04:51:40 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2002/08/21 04:13:12 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Money
[2007/06/25 19:26:45 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2003/08/16 21:40:22 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Picture It! 2002
[2002/08/21 04:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2002/08/21 04:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works Suite 2002
[2010/02/28 23:32:56 | 000,000,000 | ---D | M] -- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
[2002/08/21 05:52:40 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Helper
[2010/03/11 00:57:24 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/07/25 15:09:38 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/07/09 01:11:59 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/02/03 18:12:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2002/08/21 05:56:31 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2002/08/21 04:12:38 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2006/11/01 22:14:44 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2007/12/29 13:39:53 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2010/07/25 13:27:57 | 000,000,000 | ---D | M] -- C:\Program Files\Native Instruments
[2009/07/08 23:36:41 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2004/01/06 22:17:24 | 000,000,000 | ---D | M] -- C:\Program Files\Netscape
[2009/06/30 14:55:11 | 000,000,000 | ---D | M] -- C:\Program Files\Network Associates
[2002/08/21 04:12:42 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/06/16 14:27:36 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2007/12/27 15:34:18 | 000,000,000 | ---D | M] -- C:\Program Files\PCFriendly
[2006/03/17 22:54:22 | 000,000,000 | ---D | M] -- C:\Program Files\Photo Finale
[2010/01/24 18:15:05 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/07/09 01:11:37 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2008/11/17 16:53:51 | 000,000,000 | ---D | M] -- C:\Program Files\SCMD20
[2010/02/28 23:32:59 | 000,000,000 | ---D | M] -- C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2010/07/24 00:10:22 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/25 15:49:43 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2005/01/07 12:28:14 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/07/25 14:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2010/01/17 19:35:48 | 000,000,000 | ---D | M] -- C:\Program Files\VST
[2008/12/24 22:27:20 | 000,000,000 | ---D | M] -- C:\Program Files\Western Digital Technologies
[2007/03/10 16:57:02 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/07/08 23:36:36 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/11/17 18:23:54 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2008/11/28 14:48:30 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2005/01/21 12:15:51 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2002/08/21 04:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\XEROX
< %appdata%\*.* >
[2007/06/25 19:50:26 | 000,002,508 | ---- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\$_hpcst$.hpc
[2003/10/17 17:49:08 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\.C18A67926659B183.sys
[2001/11/14 19:23:32 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\DESKTOP.INI
[2010/03/15 02:23:56 | 000,089,784 | ---- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\GDIPFONTCACHEV1.DAT
[2008/12/24 22:25:46 | 000,000,008 | ---- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\usb.dat
< MD5 for: AGP440.SYS >
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\AGP440.SYS
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\I386\AGP440.SYS
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:atapi.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002/01/30 02:49:08 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=48BC2767CEEC6E8B0E15B0289F18232E -- C:\I386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: DISK.SYS >
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:disk.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:disk.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:disk.sys
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:disk.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:disk.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/04 01:59:54 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SYSTEM32\DRIVERS\disk.sys
[2001/08/17 18:00:00 | 000,033,664 | ---- | M] (Microsoft Corporation) MD5=43A10CD19D648E57ED039A6CAA667A56 -- C:\I386\DISK.SYS
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2001/08/17 18:00:00 | 000,047,616 | ---- | M] (Microsoft Corporation) MD5=A510B91253544D56B5712D66BE8371E9 -- C:\I386\EVENTLOG.DLL
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SYSTEM32\netlogon.dll
[2004/08/04 03:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2001/08/17 18:00:00 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=F41C1602DC79AB72035F2388FCA0255F -- C:\I386\NETLOGON.DLL
< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2001/08/17 18:00:00 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=73968C834C316ADC7A2F07DC4B5F3665 -- C:\I386\SCECLI.DLL
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SYSTEM32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:usbstor.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:usbstor.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:usbstor.sys
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:usbstor.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:usbstor.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 02:08:46 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\SYSTEM32\DRIVERS\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-17 21:57:30
========== Alternate Data Streams ==========
@Alternate Data Stream - 1172 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:XgNDQ8DoV0FKsmFQ23IN
@Alternate Data Stream - 1083 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:JHSq4tg36zwn2MexRUXR
< End of report >
Here is the HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:07:15 PM, on 7/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys\WUSB300N\WLService.exe
C:\Program Files\Linksys\WUSB300N\WUSB300N.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Hojjat Adeli\My Documents\Downloads\OTL.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.netscape.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.226 osguardpro.microsoft.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HitmanPro35] "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" /scan:boot
O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Mozilla Firefox.lnk = C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: connection manager.lnk = ?
O4 - Global Startup: hpzrcv01.LNK = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247105164671
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1247105132184
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Network Associates McShield (McShield) - Unknown owner - C:\Program Files\Network Associates\VirusScan\mcshield.exe (file missing)
O23 - Service: Network Associates Task Manager (McTaskManager) - Unknown owner - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe (file missing)
O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe
O24 - Desktop Component 0: (no name) - http://www.pbs.org/wnet/gperf/alvinailey/assets/duplicate6/backgroundplain.gif
--
End of file - 7666 bytes
C:\Documents and Settings\Hojjat Adeli\Desktop\CCleaner.lnk
[2010/07/25 15:24:59 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/25 14:01:33 | 000,001,663 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Hitman Pro 3.5.lnk
[2010/07/13 23:44:12 | 000,000,892 | ---- | C] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/07/13 23:44:12 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2010/02/14 16:33:48 | 000,015,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/01/21 21:18:10 | 000,000,398 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2010/01/21 21:17:49 | 000,001,205 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2010/01/21 21:16:29 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\HPPCPR01.DLL
[2009/10/13 18:29:18 | 000,001,044 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2009/10/13 18:15:05 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2009/10/11 12:54:01 | 000,520,267 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2009/07/06 23:51:16 | 000,000,079 | ---- | C] () -- C:\WINDOWS\uascasio.INI
[2009/07/06 23:47:57 | 000,557,056 | ---- | C] () -- C:\WINDOWS\System32\UascAsio.dll
[2009/06/21 14:51:09 | 000,000,371 | ---- | C] () -- C:\WINDOWS\GearBox.ini
[2009/02/17 16:59:10 | 000,106,496 | ---- | C] () -- C:\WINDOWS\acufutls.dll
[2008/05/16 03:10:13 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/08/26 18:19:59 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2006/01/15 12:00:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/06/12 20:59:10 | 000,001,827 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005/04/25 14:31:35 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A6W.INI
[2005/01/21 12:54:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcf.INI
[2005/01/07 14:09:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2005/01/04 15:14:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PCFriend.INI
[2003/10/15 17:43:46 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\ISODisk.sys
[2003/08/23 13:59:34 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Brpcfx.ini
[2003/08/23 13:59:29 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2003/08/23 13:59:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2003/08/18 20:21:59 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2003/08/18 20:21:51 | 000,000,037 | ---- | C] () -- C:\WINDOWS\TB50.INI
[2003/08/17 11:20:33 | 000,001,253 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2003/08/17 11:20:22 | 000,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
[2003/08/17 11:20:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
[2003/08/17 11:20:22 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
[2003/08/17 11:20:00 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
[2003/08/16 15:33:16 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\mdcgina.dll
[2003/02/22 14:07:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2003/02/22 13:42:06 | 000,000,134 | ---- | C] () -- C:\WINDOWS\KIDSOFT.INI
[2003/02/21 23:17:59 | 000,000,603 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2003/02/21 23:17:55 | 000,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI
[2003/02/18 22:06:19 | 000,000,451 | ---- | C] () -- C:\WINDOWS\yukon.ini
[2002/08/21 05:59:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2002/08/21 05:52:40 | 000,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2002/08/21 05:48:49 | 000,000,788 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/08/21 04:24:00 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2002/08/05 00:29:52 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2002/05/08 07:43:25 | 000,000,188 | -H-- | C] () -- C:\WINDOWS\Mmob864g5s3d6p.dll
[2002/03/26 21:18:24 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[2001/11/14 20:19:38 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1999/01/22 21:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/11 01:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 20:12:00 | 001,384,479 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\SYSTEM32\msvbvm60.dll
[28 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[28 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2001/11/14 19:22:22 | 000,090,112 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2001/11/14 19:22:22 | 000,606,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2001/11/14 19:22:22 | 000,380,928 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %systemroot%\system32\*.sys >
[2001/08/17 18:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ANSI.SYS
[2002/03/15 02:14:16 | 000,005,376 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\SYSTEM32\ATIICDXX.SYS
[2001/08/17 18:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\SYSTEM32\COUNTRY.SYS
[2003/09/25 22:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\SYSTEM32\GTNDIS5.sys
[2001/08/17 18:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\SYSTEM32\HIMEM.SYS
[2006/12/19 17:00:56 | 000,011,648 | ---- | M] (Hewlett-Packard Development Company) -- C:\WINDOWS\SYSTEM32\hpnucmp.sys
[2007/10/31 12:54:06 | 000,039,552 | ---- | M] (Hewlett-Packard Development Company) -- C:\WINDOWS\SYSTEM32\hpnuhub.sys
[2007/11/23 00:50:10 | 000,018,560 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\SYSTEM32\HPWPAUSB.sys
[2001/08/17 18:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\SYSTEM32\KEY01.SYS
[2002/08/29 00:23:06 | 000,042,537 | ---- | M] () -- C:\WINDOWS\SYSTEM32\keyboard.sys
[2007/09/27 01:00:02 | 000,470,912 | ---- | M] (Marvell Semiconductor, Inc) -- C:\WINDOWS\SYSTEM32\Mrvw243.sys
[2007/09/27 00:58:54 | 000,461,952 | ---- | M] (Marvell Semiconductor, Inc) -- C:\WINDOWS\SYSTEM32\Mrvw245.sys
[2001/08/17 18:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS.SYS
[2001/08/17 18:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS404.SYS
[2001/08/17 18:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS411.SYS
[2001/08/17 18:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS412.SYS
[2001/08/17 18:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\SYSTEM32\NTDOS804.SYS
[2004/08/04 01:45:08 | 000,033,840 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio.sys
[2004/08/04 01:45:14 | 000,034,560 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio404.sys
[2004/08/04 01:45:10 | 000,035,648 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio411.sys
[2004/08/04 01:45:15 | 000,035,424 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio412.sys
[2004/08/04 01:45:12 | 000,034,560 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ntio804.sys
[2003/10/22 12:54:14 | 000,016,848 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\SYSTEM32\Pcandis4.sys
[2003/10/22 12:54:18 | 000,017,162 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\SYSTEM32\Pcandis5.sys
[2008/04/13 14:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\watchdog.sys
[2010/05/02 01:22:50 | 001,851,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\win32k.sys
[28 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2008/04/13 20:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv01nt5.dll
[2008/04/13 20:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv02nt5.dll
[2008/04/13 20:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv05nt5.dll
[2008/04/13 20:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv07nt5.dll
[2008/04/13 20:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv08nt5.dll
[2008/04/13 20:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv09nt5.dll
[2008/04/13 20:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\adv11nt5.dll
[2008/04/13 20:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv01nt5.dll
[2008/04/13 20:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv02nt5.dll
[2008/04/13 20:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv04nt5.dll
[2008/04/13 20:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv06nt5.dll
[2008/04/13 20:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\atv10nt5.dll
[2008/04/13 20:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ch7xxnt5.dll
[2003/09/02 00:00:00 | 000,184,320 | ---- | M] (Digidesign, A Division of Avid Teechnology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\Digiasio.dll
[2008/04/13 20:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\siint5.dll
[2008/04/13 20:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\vchnt5.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2001/11/14 19:31:14 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/06/30 14:38:43 | 000,000,212 | -HS- | M] () -- C:\BOOT.INI
[2001/11/14 04:35:22 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS
[2001/11/14 19:31:14 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2002/08/21 04:28:04 | 000,003,775 | RH-- | M] () -- C:\DELL.SDR
[2008/05/11 14:52:18 | 000,015,982 | ---- | M] () -- C:\drwtsn32.log
[2001/11/14 19:31:14 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2002/08/21 05:56:19 | 000,000,317 | -H-- | M] () -- C:\IPH.PH
[2001/11/14 19:31:14 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2006/09/18 16:59:48 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/07/08 23:32:47 | 000,250,048 | RHS- | M] () -- C:\NTLDR
[2010/07/25 15:34:28 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys
[2010/03/30 21:59:29 | 000,000,452 | ---- | M] () -- C:\rkill.log
[2010/07/25 15:34:57 | 000,000,746 | ---- | M] () -- C:\test.txt
< %PROGRAMFILES%\*. >
[2010/03/07 14:52:43 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica Beatcraft
[2010/07/25 13:14:41 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica Mixcraft 4
[2010/07/25 13:30:48 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica Shared Effects
[2009/10/11 20:38:07 | 000,000,000 | ---D | M] -- C:\Program Files\Addictive Drums
[2010/04/04 15:09:30 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2005/03/18 15:23:47 | 000,000,000 | ---D | M] -- C:\Program Files\Allen
[2010/02/28 23:38:03 | 000,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2005/03/03 16:27:11 | 000,000,000 | ---D | M] -- C:\Program Files\aod
[2010/01/24 18:11:22 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2003/10/24 20:17:26 | 000,000,000 | ---D | M] -- C:\Program Files\ASIO4ALL v2
[2010/04/17 22:40:07 | 000,000,000 | ---D | M] -- C:\Program Files\ATT
[2010/04/17 22:41:21 | 000,000,000 | ---D | M] -- C:\Program Files\ATT-PRT22-WISE
[2008/01/06 13:41:18 | 000,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2010/01/24 18:16:12 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2003/08/23 13:59:18 | 000,000,000 | ---D | M] -- C:\Program Files\Brother
[2007/12/25 17:35:55 | 000,000,000 | ---D | M] -- C:\Program Files\Canon
[2010/07/25 15:40:39 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/07/25 13:25:39 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2002/08/21 04:12:42 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2002/08/21 05:38:36 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2009/06/29 13:04:04 | 000,000,000 | ---D | M] -- C:\Program Files\delaydots
[2002/08/05 00:09:03 | 000,000,000 | ---D | M] -- C:\Program Files\Dell
[2002/08/21 05:56:36 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Computer
[2009/07/06 23:46:19 | 000,000,000 | ---D | M] -- C:\Program Files\Digidesign
[2005/01/05 21:42:07 | 000,000,000 | ---D | M] -- C:\Program Files\directx
[2007/05/15 22:39:53 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/04/05 21:29:51 | 000,000,000 | ---D | M] -- C:\Program Files\Easy CD & DVD Cover Creator
[2010/01/17 19:35:48 | 000,000,000 | ---D | M] -- C:\Program Files\EDIROL
[2010/02/28 23:32:53 | 000,000,000 | ---D | M] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2010/01/17 19:36:51 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/01/19 03:38:01 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2010/02/14 16:33:38 | 000,000,000 | ---D | M] -- C:\Program Files\Hitman Pro 3.5
[2010/01/19 03:44:33 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2010/01/18 00:45:58 | 000,000,000 | ---D | M] -- C:\Program Files\HP Wireless Printer Adapter
[2010/01/18 00:45:31 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2002/08/21 05:52:19 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2007/08/26 18:02:27 | 000,000,000 | ---D | M] -- C:\Program Files\InterActual
[2009/07/08 23:51:04 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/07/13 23:43:59 | 000,000,000 | ---D | M] -- C:\Program Files\IObit
[2003/10/15 17:43:46 | 000,000,000 | ---D | M] -- C:\Program Files\ISODisk
[2002/08/21 05:52:49 | 000,000,000 | ---D | M] -- C:\Program Files\Jasc Software Inc
[2010/03/07 15:03:03 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2006/07/30 14:23:21 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2003/01/15 06:01:59 | 000,000,000 | ---D | M] -- C:\Program Files\LEGO Media
[2008/11/17 17:45:50 | 000,000,000 | ---D | M] -- C:\Program Files\Line6
[2009/10/13 18:29:55 | 000,000,000 | ---D | M] -- C:\Program Files\Linksys
[2010/07/25 15:25:00 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2004/02/01 20:58:18 | 000,000,000 | ---D | M] -- C:\Program Files\Merriam-Webster
[2009/07/09 00:52:58 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2006/07/01 12:15:51 | 000,000,000 | ---D | M] -- C:\Program Files\MGI
[2010/01/18 03:23:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2007/05/09 20:26:11 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2002/08/21 04:15:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Encarta
[2002/11/18 04:51:40 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2002/08/21 04:13:12 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Money
[2007/06/25 19:26:45 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2003/08/16 21:40:22 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Picture It! 2002
[2002/08/21 04:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2002/08/21 04:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works Suite 2002
[2010/02/28 23:32:56 | 000,000,000 | ---D | M] -- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
[2002/08/21 05:52:40 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Helper
[2010/03/11 00:57:24 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/07/25 15:09:38 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/07/09 01:11:59 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/02/03 18:12:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2002/08/21 05:56:31 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2002/08/21 04:12:38 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2006/11/01 22:14:44 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2007/12/29 13:39:53 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2010/07/25 13:27:57 | 000,000,000 | ---D | M] -- C:\Program Files\Native Instruments
[2009/07/08 23:36:41 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2004/01/06 22:17:24 | 000,000,000 | ---D | M] -- C:\Program Files\Netscape
[2009/06/30 14:55:11 | 000,000,000 | ---D | M] -- C:\Program Files\Network Associates
[2002/08/21 04:12:42 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/06/16 14:27:36 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2007/12/27 15:34:18 | 000,000,000 | ---D | M] -- C:\Program Files\PCFriendly
[2006/03/17 22:54:22 | 000,000,000 | ---D | M] -- C:\Program Files\Photo Finale
[2010/01/24 18:15:05 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/07/09 01:11:37 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2008/11/17 16:53:51 | 000,000,000 | ---D | M] -- C:\Program Files\SCMD20
[2010/02/28 23:32:59 | 000,000,000 | ---D | M] -- C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2010/07/24 00:10:22 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/25 15:49:43 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2005/01/07 12:28:14 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/07/25 14:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2010/01/17 19:35:48 | 000,000,000 | ---D | M] -- C:\Program Files\VST
[2008/12/24 22:27:20 | 000,000,000 | ---D | M] -- C:\Program Files\Western Digital Technologies
[2007/03/10 16:57:02 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/07/08 23:36:36 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/11/17 18:23:54 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2008/11/28 14:48:30 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2005/01/21 12:15:51 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2002/08/21 04:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\XEROX
< %appdata%\*.* >
[2007/06/25 19:50:26 | 000,002,508 | ---- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\$_hpcst$.hpc
[2003/10/17 17:49:08 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\.C18A67926659B183.sys
[2001/11/14 19:23:32 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\DESKTOP.INI
[2010/03/15 02:23:56 | 000,089,784 | ---- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\GDIPFONTCACHEV1.DAT
[2008/12/24 22:25:46 | 000,000,008 | ---- | M] () -- C:\Documents and Settings\Hojjat Adeli\Application Data\usb.dat
< MD5 for: AGP440.SYS >
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\AGP440.SYS
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\I386\AGP440.SYS
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:atapi.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002/01/30 02:49:08 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=48BC2767CEEC6E8B0E15B0289F18232E -- C:\I386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: DISK.SYS >
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:disk.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:disk.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:disk.sys
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:disk.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:disk.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/04 01:59:54 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SYSTEM32\DRIVERS\disk.sys
[2001/08/17 18:00:00 | 000,033,664 | ---- | M] (Microsoft Corporation) MD5=43A10CD19D648E57ED039A6CAA667A56 -- C:\I386\DISK.SYS
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2001/08/17 18:00:00 | 000,047,616 | ---- | M] (Microsoft Corporation) MD5=A510B91253544D56B5712D66BE8371E9 -- C:\I386\EVENTLOG.DLL
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SYSTEM32\netlogon.dll
[2004/08/04 03:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2001/08/17 18:00:00 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=F41C1602DC79AB72035F2388FCA0255F -- C:\I386\NETLOGON.DLL
< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2001/08/17 18:00:00 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=73968C834C316ADC7A2F07DC4B5F3665 -- C:\I386\SCECLI.DLL
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SYSTEM32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:usbstor.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:usbstor.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:usbstor.sys
[2003/08/20 15:30:04 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:usbstor.sys
[2006/09/18 16:41:39 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:usbstor.sys
[2009/07/08 23:25:40 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 02:08:46 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\SYSTEM32\DRIVERS\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-17 21:57:30
========== Alternate Data Streams ==========
@Alternate Data Stream - 1172 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:XgNDQ8DoV0FKsmFQ23IN
@Alternate Data Stream - 1083 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:JHSq4tg36zwn2MexRUXR
< End of report >