CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 30 Days ==========
[2011/01/17 21:41:49 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Dad\Recent
[2011/01/13 23:33:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dad\Desktop\A&P Report
[2011/01/13 00:03:53 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/01/13 00:03:53 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/01/13 00:03:53 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/01/11 22:38:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dad\Desktop\IO Chem Report
[2011/01/09 21:37:02 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Dad\My Documents\My Web Sites
[2011/01/01 23:10:20 | 000,000,000 | ---D | C] -- C:\Program Files\real
[2010/12/31 00:47:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dad\Application Data\Sony Creative Software
[2010/04/14 21:38:45 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\cphc700.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/17 22:01:05 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/17 21:28:37 | 000,000,313 | ---- | M] () -- C:\hpqp.ini
[2011/01/17 21:11:13 | 000,000,467 | ---- | M] () -- C:\WINDOWS\smscfg.ini
[2011/01/17 21:10:32 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/17 21:09:41 | 000,000,040 | ---- | M] () -- C:\XP_TV.ini
[2011/01/17 21:09:08 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/17 21:09:07 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1138291920-1722871507-670032271-1005.job
[2011/01/17 21:08:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/17 21:08:22 | 2673,987,584 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/16 22:37:49 | 000,010,504 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\Things we have in club.xlsx
[2011/01/16 21:47:46 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\M&N Game.doc
[2011/01/13 07:28:39 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\To be printed.doc
[2011/01/13 07:22:53 | 000,019,638 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\chart.jpg
[2011/01/11 22:20:44 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\Sunday Youth Planning.doc
[2011/01/09 17:36:36 | 000,038,400 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\CLS FO Camp Meeting 1 Summary.doc
[2011/01/09 17:35:39 | 000,012,707 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\DUTY AT SPCC FOR JAE 2011.pdf
[2011/01/07 02:34:23 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\Calender-of-events-2011.xls
[2011/01/06 00:20:08 | 000,071,680 | ---- | M] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/01 22:49:22 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1138291920-1722871507-670032271-1005.job
[2010/12/31 01:48:51 | 030,837,995 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\First Video.wmv
[2010/12/31 00:52:51 | 020,311,760 | ---- | M] () -- C:\Documents and Settings\Dad\My Documents\Singing.mpg
[2010/12/30 23:59:34 | 000,207,048 | ---- | M] () -- C:\Documents and Settings\Dad\My Documents\ts3_clientui-win32-12369-2010-12-30 23_59_34.484375.dmp
[2010/12/30 23:45:17 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\Homework.doc
[2010/12/29 17:13:37 | 000,021,754 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\DFDNHW (2).xlsx
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/16 22:37:48 | 000,010,504 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\Things we have in club.xlsx
[2011/01/16 21:40:19 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\M&N Game.doc
[2011/01/13 07:22:52 | 000,019,638 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\chart.jpg
[2011/01/13 02:47:14 | 000,056,832 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\To be printed.doc
[2011/01/11 22:20:44 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\Sunday Youth Planning.doc
[2011/01/09 17:36:37 | 000,038,400 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\CLS FO Camp Meeting 1 Summary.doc
[2011/01/09 17:35:42 | 000,012,707 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\DUTY AT SPCC FOR JAE 2011.pdf
[2011/01/07 02:34:23 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\Calender-of-events-2011.xls
[2010/12/31 01:55:12 | 030,837,995 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\First Video.wmv
[2010/12/31 00:51:23 | 020,311,760 | ---- | C] () -- C:\Documents and Settings\Dad\My Documents\Singing.mpg
[2010/12/30 23:59:34 | 000,207,048 | ---- | C] () -- C:\Documents and Settings\Dad\My Documents\ts3_clientui-win32-12369-2010-12-30 23_59_34.484375.dmp
[2010/12/30 23:45:17 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\Homework.doc
[2010/12/30 22:48:57 | 000,000,274 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1138291920-1722871507-670032271-1005.job
[2010/12/29 17:13:36 | 000,021,754 | ---- | C] () -- C:\Documents and Settings\Dad\Desktop\DFDNHW (2).xlsx
[2010/10/07 12:00:16 | 000,000,175 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2010/07/26 00:24:17 | 000,547,392 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/15 10:59:53 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Robota.INI
[2010/07/15 10:58:02 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\mgxasio2.dll
[2010/07/15 10:56:52 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2010/07/15 10:56:29 | 000,006,211 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2010/04/14 21:38:45 | 000,541,568 | ---- | C] () -- C:\WINDOWS\System32\drivers\phc700.sys
[2010/04/14 21:38:45 | 000,015,488 | ---- | C] () -- C:\WINDOWS\phc700.ini
[2010/03/24 14:07:42 | 000,000,162 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/03/05 08:15:32 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2010/02/28 23:29:53 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2010/02/20 21:03:16 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/12/19 00:17:30 | 000,000,724 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/11/20 23:38:31 | 000,000,156 | ---- | C] () -- C:\Documents and Settings\Dad\Application Data\wklnhst.dat
[2009/11/20 23:08:57 | 000,000,078 | ---- | C] () -- C:\Documents and Settings\Dad\Application Data\RSBot Accounts.ini
[2008/04/08 10:38:26 | 000,001,069 | ---- | C] () -- C:\WINDOWS\disney.ini
[2007/08/11 12:49:09 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2007/06/20 11:41:37 | 000,682,232 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/01/31 11:20:06 | 000,000,319 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2007/01/28 09:29:05 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\FnF4.txt
[2007/01/26 14:17:05 | 000,071,680 | ---- | C] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/26 10:58:31 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\fusioncache.dat
[2007/01/26 10:58:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\DSwitch.txt
[2007/01/26 10:58:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\AtStart.txt
[2007/01/26 10:58:30 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dad\Local Settings\Application Data\QSwitch.txt
[2007/01/05 14:27:51 | 000,028,836 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/06/30 03:18:14 | 000,000,467 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/06/30 02:49:18 | 000,003,871 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/06/30 02:46:56 | 000,000,059 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/06/30 02:43:40 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/06/30 02:13:00 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/03/04 15:07:34 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/12/03 02:09:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/05/06 10:06:32 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2004/09/17 04:24:26 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[1997/06/14 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== Custom Scans ==========
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2005/09/24 23:49:16 | 000,012,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2006/06/30 02:12:30 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 20:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/10/28 12:49:30 | 000,321,536 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp696.dll
[2006/10/26 19:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 18:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2009/12/30 16:29:47 | 000,001,642 | -H-- | M] () -- C:\Documents and Settings\Dad\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/10/25 22:46:56 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/10/25 23:04:31 | 000,000,170 | -HS- | M] () -- C:\Documents and Settings\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/06/30 02:19:24 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/02/21 17:57:48 | 000,283,987 | ---- | M] () -- C:\Documents and Settings\Dad\Desktop\connect to p.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2004/02/27 17:36:18 | 000,013,023 | ---- | M] () -- C:\WINDOWS\phc700.src
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2010/12/12 01:38:01 | 000,107,480 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2010/12/12 01:38:01 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2010/12/12 01:38:03 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2010/12/12 01:38:06 | 000,245,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008/10/25 23:04:31 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Dad\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/03/24 09:52:30 | 000,001,008 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/14 08:11:51 | 001,267,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
[2010/03/18 17:34:12 | 000,087,368 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\FwsVpn.dll
[2010/03/18 17:34:12 | 000,107,848 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\SymVPN.dll
[2010/03/18 17:34:12 | 000,357,704 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\sysfer.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2007/06/20 11:41:38 | 000,682,232 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
[2010/03/18 17:34:06 | 000,092,488 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\SysPlant.sys
[2010/03/18 17:34:06 | 000,050,064 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\Teefer2.sys
[2010/03/18 17:34:12 | 000,042,312 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys
[2010/09/10 22:32:20 | 000,167,936 | ---- | M] (Symantec Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\wpshelper.sys
< %systemroot%\System32\config\*.sav >
[2006/06/29 18:59:22 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/06/29 18:59:22 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
< %systemroot%\system32\*.sys >
[2006/03/16 12:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2006/03/16 12:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2006/03/16 12:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2006/03/16 12:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2006/03/16 12:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2005/01/05 02:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) -- C:\WINDOWS\system32\npptNT2.sys
[2006/03/16 12:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2006/03/16 12:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2006/03/16 12:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2006/03/16 12:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2006/03/16 12:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2006/03/16 12:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2006/03/16 12:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2006/03/16 12:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2006/03/16 12:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2006/03/16 12:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2002/10/15 11:13:34 | 000,032,356 | ---- | M] (Phoenix Technologies K.K.) -- C:\WINDOWS\system32\pusbfd1.sys
[2008/04/14 02:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/10/26 21:25:00 | 001,853,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2008/04/14 08:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/14 08:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/14 08:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/14 08:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/14 08:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/14 08:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/14 08:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/14 08:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/14 08:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/14 08:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/14 08:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/14 08:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/14 08:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/14 08:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/14 08:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 20:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/10/28 12:49:30 | 000,321,536 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp696.dll
[2006/10/26 19:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
< %SYSTEMDRIVE%\*.* >
[2009/12/04 17:53:55 | 000,000,209 | RHS- | M] () -- C:\boot.ini
[2007/03/02 14:58:46 | 000,000,182 | ---- | M] () -- C:\drwtsn32.log
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2011/01/17 21:08:22 | 2673,987,584 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/17 21:28:37 | 000,000,313 | ---- | M] () -- C:\hpqp.ini
[2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2007/03/09 20:44:36 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/03/09 20:44:36 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/03/16 12:00:00 | 000,047,564 | RHS- | M] () -- C:\ntdetect.com
[2008/10/25 22:35:55 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2008/10/17 20:30:59 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2008/10/17 20:30:59 | 000,001,024 | -H-- | M] () -- C:\ntuser.dat.LOG
[2011/01/17 21:08:19 | 792,723,456 | -HS- | M] () -- C:\pagefile.sys
[2008/12/19 16:09:37 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2009/01/29 21:25:58 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2009/05/15 22:47:01 | 000,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/05/15 22:49:37 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/05/18 15:08:45 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/08/15 22:13:37 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/08/17 14:33:06 | 000,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2009/08/18 16:20:04 | 000,000,232 | -H-- | M] () -- C:\sqmdata07.sqm
[2009/10/19 10:53:57 | 000,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
[2009/10/21 23:06:58 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2009/10/23 15:25:23 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2009/10/25 15:58:13 | 000,000,232 | -H-- | M] () -- C:\sqmdata11.sqm
[2009/10/30 21:35:36 | 000,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2008/10/23 21:02:16 | 000,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2008/11/05 11:51:37 | 000,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2008/11/07 14:43:13 | 000,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2008/11/07 14:58:38 | 000,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2008/11/09 20:10:14 | 000,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2008/11/15 16:33:09 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2008/11/19 23:28:26 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2008/12/19 16:09:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009/01/29 21:25:58 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2009/05/15 22:47:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/05/15 22:49:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/05/18 15:08:45 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/08/15 22:13:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/08/17 14:33:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009/08/18 16:20:04 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2009/10/19 10:53:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2009/10/21 23:06:58 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2009/10/23 15:25:23 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2009/10/25 15:58:13 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2009/10/30 21:35:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2008/10/23 21:02:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2008/11/05 11:51:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008/11/07 14:43:13 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2008/11/07 14:58:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008/11/09 20:10:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008/11/15 16:33:09 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008/11/19 23:28:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
[2011/01/17 21:09:41 | 000,000,040 | ---- | M] () -- C:\XP_TV.ini
< %PROGRAMFILES%\*. >
[2010/10/10 22:35:01 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/12/14 23:54:25 | 000,000,000 | ---D | M] -- C:\Program Files\AhnLab
[2010/03/16 23:16:24 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/09/04 00:19:16 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/04/13 14:46:40 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/03/24 09:02:50 | 000,000,000 | ---D | M] -- C:\Program Files\Cisco
[2011/01/01 23:10:06 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2007/01/06 06:00:49 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2007/01/05 14:33:04 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2007/06/20 11:50:57 | 000,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools
[2010/03/17 13:42:42 | 000,000,000 | ---D | M] -- C:\Program Files\DAP
[2008/05/02 14:14:50 | 000,000,000 | ---D | M] -- C:\Program Files\DIGStream
[2007/01/28 19:04:00 | 000,000,000 | ---D | M] -- C:\Program Files\directx
[2010/02/28 23:29:24 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2007/12/05 20:04:42 | 000,000,000 | ---D | M] -- C:\Program Files\eGames
[2007/04/24 20:06:47 | 000,000,000 | ---D | M] -- C:\Program Files\EnglishOtto
[2007/04/24 20:06:47 | 000,000,000 | ---D | M] -- C:\Program Files\ESPNMotion
[2007/02/25 15:36:08 | 000,000,000 | ---D | M] -- C:\Program Files\GameFlier
[2008/05/02 14:15:12 | 000,000,000 | ---D | M] -- C:\Program Files\GameSpy Arcade
[2011/01/09 18:20:31 | 000,000,000 | ---D | M] -- C:\Program Files\Garena
[2007/04/24 20:06:47 | 000,000,000 | ---D | M] -- C:\Program Files\GemMaster
[2010/03/04 21:40:52 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2008/02/18 16:02:35 | 000,000,000 | ---D | M] -- C:\Program Files\Graphmatica
[2008/05/02 13:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Grisoft
[2007/01/05 15:13:14 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2010/08/29 22:22:32 | 000,000,000 | ---D | M] -- C:\Program Files\HoN
[2010/12/29 19:34:12 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2007/01/05 15:02:43 | 000,000,000 | ---D | M] -- C:\Program Files\HPQ
[2010/07/26 01:03:07 | 000,000,000 | ---D | M] -- C:\Program Files\ImTOO
[2007/12/05 20:16:59 | 000,000,000 | ---D | M] -- C:\Program Files\Infogrames Interactive, Inc
[2010/12/29 20:18:01 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2007/01/05 14:08:19 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2010/12/03 00:10:33 | 000,000,000 | ---D | M] -- C:\Program Files\InterLok
[2010/12/17 14:31:12 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/12/01 00:17:06 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2010/12/01 00:17:57 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2011/01/13 00:03:42 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/02/20 21:50:07 | 000,000,000 | ---D | M] -- C:\Program Files\Liquid Entertainment
[2007/07/05 20:16:13 | 000,000,000 | ---D | M] -- C:\Program Files\LittleFighter2
[2010/03/01 13:45:36 | 000,000,000 | ---D | M] -- C:\Program Files\LucasArts
[2010/07/15 10:58:26 | 000,000,000 | ---D | M] -- C:\Program Files\MAGIX
[2008/10/25 22:55:58 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/11/06 12:41:08 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2007/12/17 22:11:16 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/03/24 10:40:23 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Expression
[2007/01/06 06:00:50 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2008/11/26 19:26:42 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2010/01/25 16:59:44 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Money 2005
[2010/03/24 13:39:48 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/03/24 13:40:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2010/03/24 13:36:06 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 8
[2010/03/24 13:19:13 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2010/03/24 10:41:47 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2007/01/28 19:00:57 | 000,000,000 | ---D | M] -- C:\Program Files\Monte Cristo
[2010/08/14 16:28:31 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/12/12 01:38:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/03/24 13:40:57 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/03/24 09:37:32 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2007/06/20 12:35:29 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2007/01/06 06:00:50 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2007/01/28 22:25:25 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2007/01/05 14:44:26 | 000,000,000 | ---D | M] -- C:\Program Files\muvee Technologies
[2008/10/25 22:39:01 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2008/01/13 18:50:25 | 000,000,000 | ---D | M] -- C:\Program Files\NetWaiting
[2007/12/05 21:06:44 | 000,000,000 | ---D | M] -- C:\Program Files\NHN USA
[2008/12/15 00:11:11 | 000,000,000 | ---D | M] -- C:\Program Files\NOS
[2010/12/29 19:32:59 | 000,000,000 | ---D | M] -- C:\Program Files\Oberon Media
[2007/01/05 14:43:54 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/04/14 20:22:29 | 000,000,000 | ---D | M] -- C:\Program Files\ooVoo
[2008/09/13 19:58:55 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.4
[2010/12/17 14:23:42 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/07/20 13:51:54 | 000,000,000 | ---D | M] -- C:\Program Files\Paint.NET
[2010/04/14 21:38:45 | 000,000,000 | ---D | M] -- C:\Program Files\Philips
[2010/10/07 12:44:13 | 000,000,000 | ---D | M] -- C:\Program Files\Project 3 Interactive
[2007/08/28 17:22:10 | 000,000,000 | ---D | M] -- C:\Program Files\Puzzle Bobble 2x
[2010/12/01 00:13:44 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2011/01/01 23:10:20 | 000,000,000 | ---D | M] -- C:\Program Files\real
[2010/02/20 21:36:07 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/03/24 11:22:23 | 000,000,000 | ---D | M] -- C:\Program Files\Respondus LockDown Browser
[2007/06/18 18:30:31 | 000,000,000 | ---D | M] -- C:\Program Files\RGB
[2010/10/07 12:00:49 | 000,000,000 | ---D | M] -- C:\Program Files\Sierra On-Line
[2010/01/05 19:00:51 | 000,000,000 | R--D | M] -- C:\Program Files\Skype
[2008/02/09 21:50:12 | 000,000,000 | ---D | M] -- C:\Program Files\Softnyx
[2007/01/06 06:00:50 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2010/03/05 12:00:51 | 000,000,000 | ---D | M] -- C:\Program Files\Sony
[2010/03/24 09:01:08 | 000,000,000 | ---D | M] -- C:\Program Files\sp XP wifihelper
[2010/12/29 20:18:01 | 000,000,000 | ---D | M] -- C:\Program Files\Surreal
[2010/03/24 09:32:19 | 000,000,000 | ---D | M] -- C:\Program Files\Symantec
[2007/01/05 14:36:18 | 000,000,000 | ---D | M] -- C:\Program Files\Synaptics
[2007/12/05 19:35:14 | 000,000,000 | ---D | M] -- C:\Program Files\TimeSink
[2007/01/31 21:31:36 | 000,000,000 | ---D | M] -- C:\Program Files\Trymedia
[2007/01/06 06:00:51 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2008/12/05 22:03:49 | 000,000,000 | ---D | M] -- C:\Program Files\Unity
[2008/02/18 20:27:43 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2011/01/09 19:47:01 | 000,000,000 | ---D | M] -- C:\Program Files\Warcraft III
[2010/10/07 22:21:14 | 000,000,000 | ---D | M] -- C:\Program Files\Waywardxs
[2009/11/06 12:42:33 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2008/06/02 11:53:41 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live Safety Center
[2009/11/06 12:40:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2008/01/13 18:50:25 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2010/02/20 21:43:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/10/25 22:38:55 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2007/01/06 06:00:51 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Plus
[2008/05/29 02:03:39 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2007/01/06 06:00:51 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/03/17 14:57:56 | 000,000,000 | ---D | M] -- C:\Program Files\Xfire
[2007/05/09 16:42:06 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
< %appdata%\*.* >
[2006/06/29 19:00:22 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Dad\Application Data\desktop.ini
[2009/11/20 23:09:04 | 000,000,078 | ---- | M] () -- C:\Documents and Settings\Dad\Application Data\RSBot Accounts.ini
[2009/11/20 23:47:09 | 000,000,156 | ---- | M] () -- C:\Documents and Settings\Dad\Application Data\wklnhst.dat
< MD5 for: AGP440.SYS >
[2006/03/16 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2006/03/16 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 02:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 02:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/03/16 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2006/03/16 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 02:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 02:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: DISK.SYS >
[2006/03/16 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\I386\sp2.cab:disk.sys
[2006/03/16 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2006/03/16 12:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/14 02:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/14 02:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 08:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 08:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2006/03/16 12:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2005/10/13 17:07:12 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\SWSetup\HDD\iastor.sys
[2005/10/13 17:07:12 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/14 08:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 08:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2006/03/16 12:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/03/16 12:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 08:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 08:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2006/03/16 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\I386\sp2.cab:usbstor.sys
[2006/03/16 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2008/10/25 22:31:46 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/03 23:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/14 02:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/14 02:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-12 19:01:59
========== Alternate Data Streams ==========
@Alternate Data Stream - 1398 bytes -> C:\Program Files\Common Files\Microsoft Shared:RNWjzorwuMw6lwmwBiRyEt3
@Alternate Data Stream - 1375 bytes -> C:\Documents and Settings\Dad\Local Settings\Application Data\kMKF2vQRc8df:czfrCkQG1oMphqYcPdmg
@Alternate Data Stream - 1298 bytes -> C:\Documents and Settings\Dad\Cookies:Vnw5k3UZ1mp62ivJZ8mm
@Alternate Data Stream - 1297 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:XhkKCVBHMFI9ymHcDJM
@Alternate Data Stream - 1231 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:wS9mStM92stFTgAAEOeI
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:010ADD2C
< End of report >