NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - Services: "AOL TopSpeedMonitor"
MsConfig - Services: "AOL ACS"
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk - C:\Program Files\BigFix\bigfix.exe - (BigFix Inc.)
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk - - File not found
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe - (Eastman Kodak Company)
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk - - File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - File not found
MsConfig - StartUpReg: Cleanup - hkey= - key= - File not found
MsConfig - StartUpReg: Google Desktop Search - hkey= - key= - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: Motive SmartBridge - hkey= - key= - C:\Program Files\verizon\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
MsConfig - StartUpReg: msci - hkey= - key= - File not found
MsConfig - StartUpReg: MSKDetectorExe - hkey= - key= - C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
MsConfig - StartUpReg: MSMSGS - hkey= - key= - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
MsConfig - StartUpReg: Power2GoExpress - hkey= - key= - File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
MsConfig - StartUpReg: Reminder - hkey= - key= - C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
MsConfig - StartUpReg: Yahoo! Pager - hkey= - key= - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: WebrootSpySweeperService - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootMin: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: WebrootSpySweeperService - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SafeBootNet: WRConsumerService - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {1325db73-d9f1-48f8-8895-6d814ec58889} - Security Update for Windows XP (KB913433)
ActiveX: {1BC46932-21B2-4130-86E0-B4EB4F7A7A7B} - Microsoft .NET Framework 1.0 Hotfix (KB887998)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.3
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {29E7D24F-BF30-45E7-8A40-AD27AFD8F5C6} - Microsoft .NET Framework 1.0 Hotfix (KB979904)
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.3
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {407408d4-94ed-4d86-ab69-a7f649d112ee} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - Reg Error: Value error.
ActiveX: {AA218328-0EA8-4D70-8972-E987A9190FF4} - Reg Error: Value error.
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {BDE0FA43-6952-4BA8-8C58-09AF690F88E1} - Microsoft .NET Framework 1.0 Hotfix (KB930494)
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E8EA5BD6-D931-4001-ABF6-81BAA500360A} - Microsoft .NET Framework 1.0 Hotfix (KB953295)
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {FDC11A6F-17D1-48f9-9EA3-9051954BAA24} - .NET Framework
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: KB910393 - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall
Drivers32: msacm.clmp3enc - C:\Program Files\CyberLink\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.enc - C:\WINDOWS\System32\ITIG726.acm (Ingenient Technologies, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\Iyvu9_32.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/08/12 18:02:00 | 000,000,000 | ---D | C] -- C:\2e06b6e211ddeffcd47732616bf711
[2011/08/12 16:46:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\uTorrent
[2011/08/12 16:46:24 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011/08/12 15:40:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2011/08/12 11:54:31 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2011/08/12 11:54:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2011/08/12 11:51:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Sammsoft
[2011/08/12 11:51:04 | 000,000,000 | ---D | C] -- C:\Program Files\ARO 2011
[53 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/12 18:01:02 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/08/12 17:08:13 | 000,028,982 | ---- | M] () -- C:\WINDOWS\hpoins03.dat
[2011/08/12 17:02:00 | 000,030,277 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/08/12 17:01:54 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/08/12 16:54:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/08/12 16:54:32 | 2012,794,880 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/12 15:58:33 | 000,012,124 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\v528oxe2480s33lio720x04eb6dr
[2011/08/12 15:58:32 | 000,012,124 | -HS- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Application Data\v528oxe2480s33lio720x04eb6dr
[2011/08/12 15:25:00 | 000,485,101 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\isla mujeres 1.jpg
[2011/08/12 15:25:00 | 000,484,020 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\isla mujeres 2.jpg
[2011/08/11 11:17:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/10 19:23:39 | 000,760,407 | ---- | M] () -- C:\logfile
[2011/08/10 19:23:01 | 022,787,072 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/08/10 19:23:01 | 011,627,520 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/08/09 17:46:51 | 001,904,156 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\005068400.jpg
[2011/07/13 22:56:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[53 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 000,011,168 | -H-- | C] () -- C:\WINDOWS\System32\nomenebu
[2011/08/12 15:57:33 | 2012,794,880 | -HS- | C] () -- C:\hiberfil.sys
[2011/08/12 15:31:23 | 000,484,020 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\isla mujeres 2.jpg
[2011/08/12 15:31:22 | 000,485,101 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\isla mujeres 1.jpg
[2011/08/12 12:00:12 | 000,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
[2011/08/12 12:00:12 | 000,000,879 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
[2011/08/12 12:00:11 | 001,152,444 | ---- | C] () -- C:\WINDOWS\UDB.zip
[2011/08/12 12:00:11 | 000,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
[2011/08/12 11:14:41 | 000,012,124 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\v528oxe2480s33lio720x04eb6dr
[2011/08/12 11:14:40 | 000,012,124 | -HS- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Application Data\v528oxe2480s33lio720x04eb6dr
[2011/08/09 17:47:22 | 001,904,156 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\005068400.jpg
[2010/12/11 20:02:51 | 000,000,020 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2010/12/11 20:02:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\popcreg.dat
[2009/11/06 13:00:28 | 000,031,088 | ---- | C] () -- C:\WINDOWS\System32\wrLZMA.dll
[2009/11/06 13:00:20 | 000,016,240 | ---- | C] () -- C:\WINDOWS\System32\SsiEfr.exe
[2009/11/02 19:47:36 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/10/16 18:47:26 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Application Data\housecall.guid.cache
[2009/09/18 17:52:32 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\RPVersion.ini
[2009/05/25 11:48:36 | 000,000,164 | ---- | C] () -- C:\WINDOWS\install.dat
[2008/12/22 12:49:58 | 000,000,015 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2008/12/09 22:07:10 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/03/11 14:15:10 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\uccspecc.sys
[2008/02/23 14:09:26 | 000,000,268 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2008/02/23 14:06:48 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\AthUnIns.exe
[2008/02/23 14:04:42 | 000,081,920 | R--- | C] () -- C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2008/02/23 14:03:22 | 000,014,938 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2008/01/19 00:32:55 | 000,002,216 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/12/16 14:22:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2007/03/28 19:09:53 | 000,017,920 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/05 13:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/03/04 00:28:35 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007/02/05 21:34:45 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/01/06 23:16:52 | 000,005,092 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\wklnhst.dat
[2006/12/10 16:56:19 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/12/09 14:02:32 | 000,038,867 | ---- | C] () -- C:\WINDOWS\hpomdl03.dat.temp
[2006/12/09 14:02:32 | 000,029,089 | ---- | C] () -- C:\WINDOWS\hpoins03.dat.temp
[2006/12/09 14:01:22 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Application Data\fusioncache.dat
[2006/12/09 13:51:26 | 000,038,867 | ---- | C] () -- C:\WINDOWS\hpomdl03.dat
[2006/12/09 13:51:26 | 000,028,982 | ---- | C] () -- C:\WINDOWS\hpoins03.dat
[2006/12/05 18:02:46 | 000,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2006/12/03 18:03:46 | 000,684,032 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2006/12/03 18:03:46 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2006/10/06 15:35:26 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\nicmgr.exe
[2006/10/06 15:35:26 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\nicmgr.dll
[2006/08/09 09:15:09 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\jesterss.dll
[2006/08/09 09:12:53 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/08/09 09:12:19 | 000,550,912 | ---- | C] () -- C:\WINDOWS\zHotkey.exe
[2006/08/09 09:12:19 | 000,532,544 | ---- | C] () -- C:\WINDOWS\PIC.dll
[2006/08/09 09:12:19 | 000,042,040 | ---- | C] () -- C:\WINDOWS\PatchWnd.exe
[2006/08/09 09:12:19 | 000,036,864 | ---- | C] () -- C:\WINDOWS\ShowWnd.exe
[2006/08/09 09:12:19 | 000,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2006/08/09 09:12:19 | 000,011,776 | ---- | C] () -- C:\WINDOWS\HIDMNT.dll
[2006/08/09 09:11:49 | 000,000,004 | ---- | C] () -- C:\WINDOWS\Pix11.dat
[2006/08/09 09:11:16 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/08/09 09:11:16 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2006/08/09 09:06:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/09 08:38:25 | 001,519,616 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006/08/09 08:38:24 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/08/09 08:38:23 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/09 08:38:22 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/08/09 08:38:20 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/08/09 08:38:20 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/08/09 08:38:20 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/08/09 08:38:19 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006/08/09 08:38:16 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006/08/09 08:38:16 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006/08/09 08:38:16 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006/06/21 02:48:15 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/06/21 02:12:42 | 000,352,256 | ---- | C] () -- C:\WINDOWS\System32\HotlineClient.exe
[2006/06/17 02:44:22 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/06/17 02:37:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/06/17 02:24:58 | 000,001,270 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/06/17 02:24:57 | 000,000,519 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2006/06/17 02:23:25 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/06/17 02:23:22 | 000,456,198 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/06/17 02:23:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/06/17 02:23:22 | 000,076,304 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/06/17 02:23:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/06/17 02:23:20 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/06/17 02:23:20 | 000,005,151 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/06/17 02:23:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/06/17 02:23:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/06/17 02:23:19 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/06/17 02:23:16 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/06/17 02:23:08 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/06/16 19:31:45 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/06/16 19:30:47 | 000,346,608 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/02 15:38:24 | 000,072,444 | ---- | C] () -- C:\WINDOWS\SetBrowser.exe
[2006/05/02 15:38:24 | 000,000,748 | ---- | C] () -- C:\WINDOWS\SetBrowser.ini
[2005/08/05 21:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 16:19:16 | 000,050,176 | ---- | C] () -- C:\WINDOWS\armcex.dll
[2004/01/05 00:30:18 | 000,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2003/02/26 16:47:14 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\MimicICM.dll
[1999/01/27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1999/01/22 11:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1997/06/13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
[2009/03/07 19:14:33 | 000,156,034 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\FHSetup.exe
[2010/09/30 10:56:26 | 008,534,336 | ---- | M] (Mozilla) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\Firefox Setup 3.6.10.exe
[2010/08/09 14:45:40 | 008,573,648 | ---- | M] (Mozilla) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\Firefox Setup 3.6.8.exe
[2009/03/07 19:18:52 | 007,522,240 | ---- | M] (Mozilla) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\Firefox%20Setup%203.0.7.exe
[2008/12/25 14:11:04 | 000,173,456 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\FixVundo.exe
[2009/09/01 18:37:51 | 000,046,157 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\GooredFix.exe
[2007/08/01 16:03:51 | 000,704,472 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\installer-31925-19-Messenger-Plus-Extension-4-20-262-English.exe
[2009/07/16 11:14:30 | 000,482,336 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\RealPlayerSPBeta.exe
[2009/10/04 22:33:09 | 002,069,088 | ---- | M] (ParetoLogic Inc.) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\RegCureSetup_RW.exe
[2009/10/13 11:34:27 | 041,688,928 | ---- | M] (Webroot Software, Inc. ) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\SpySweeperRegSetup_EN.exe
[2009/03/07 19:23:23 | 006,000,608 | ---- | M] (Sunbelt Software ) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\sunbelt-personal-firewall.exe
[2008/12/25 13:54:36 | 005,780,000 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\SUPERAntiSpyware.exe
[2008/05/30 11:40:47 | 025,755,448 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\wmp11-windowsxp-x86-enu.exe
[2009/03/07 19:25:17 | 014,824,216 | ---- | M] () -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\My Documents\ymsgr900_2136_us.exe
< %USERPROFILE%\*.exe >
[2007/12/07 23:52:35 | 000,439,296 | ---- | M] (Citrix Online) -- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\GoToAssist_phone__317_en.exe
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2011/06/21 22:43:12 | 000,125,912 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2011/06/21 22:42:09 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2011/06/21 22:41:52 | 000,265,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[2009/11/06 13:00:20 | 000,016,240 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\SsiEfr.exe
[2009/11/06 13:00:28 | 000,031,088 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\wrLZMA.dll
[53 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2010/08/31 13:22:57 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/03/07 19:35:15 | 000,000,000 | ---D | M] -- C:\Program Files\Agnitum
[2010/10/20 21:41:01 | 000,000,000 | ---D | M] -- C:\Program Files\AIM
[2010/11/28 14:12:38 | 000,000,000 | ---D | M] -- C:\Program Files\Amazon
[2006/08/09 09:15:04 | 000,000,000 | ---D | M] -- C:\Program Files\AMD Live!
[2009/08/30 10:29:20 | 000,000,000 | ---D | M] -- C:\Program Files\American Airlines DealFinder
[2008/12/17 17:39:26 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2011/08/12 16:46:03 | 000,000,000 | ---D | M] -- C:\Program Files\ARO 2011
[2011/05/30 13:02:23 | 000,000,000 | ---D | M] -- C:\Program Files\Ask.com
[2010/07/18 12:09:45 | 000,000,000 | ---D | M] -- C:\Program Files\Asoftech
[2010/09/07 09:31:45 | 000,000,000 | ---D | M] -- C:\Program Files\Avery Wizard 3.1
[2008/09/20 13:12:01 | 000,000,000 | ---D | M] -- C:\Program Files\AWS
[2006/08/09 09:08:14 | 000,000,000 | ---D | M] -- C:\Program Files\BigFix
[2011/04/09 11:05:36 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2009/11/29 18:01:58 | 000,000,000 | ---D | M] -- C:\Program Files\Canon
[2010/02/04 12:01:35 | 000,000,000 | ---D | M] -- C:\Program Files\Celebrity Toolbar
[2009/09/15 19:12:24 | 000,000,000 | ---D | M] -- C:\Program Files\Citrix
[2011/08/12 11:54:31 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2006/06/17 02:37:05 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2011/06/03 14:29:00 | 000,000,000 | ---D | M] -- C:\Program Files\Conduit
[2011/06/03 21:09:56 | 000,000,000 | ---D | M] -- C:\Program Files\ConduitEngine
[2006/08/09 08:53:51 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2011/03/09 20:20:04 | 000,000,000 | ---D | M] -- C:\Program Files\Coupons
[2009/03/05 18:53:59 | 000,000,000 | ---D | M] -- C:\Program Files\Crawler
[2006/08/09 09:05:09 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2006/12/06 17:36:55 | 000,000,000 | ---D | M] -- C:\Program Files\Design Science
[2008/04/15 17:30:55 | 000,000,000 | ---D | M] -- C:\Program Files\detest5
[2006/08/09 08:54:36 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX
[2006/08/09 09:07:18 | 000,000,000 | ---D | M] -- C:\Program Files\Digital Media Reader
[2008/02/23 14:08:53 | 000,000,000 | ---D | M] -- C:\Program Files\directx
[2009/04/05 13:56:14 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2007/01/13 18:35:19 | 000,000,000 | ---D | M] -- C:\Program Files\Flock
[2007/12/24 15:10:24 | 000,000,000 | ---D | M] -- C:\Program Files\Gateway Games
[2009/03/05 10:42:27 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2006/08/09 09:15:09 | 000,000,000 | ---D | M] -- C:\Program Files\gtw_logo
[2009/08/06 08:23:52 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2006/12/31 23:13:22 | 000,000,000 | ---D | M] -- C:\Program Files\illiminable
[2009/07/25 13:08:32 | 000,000,000 | ---D | M] -- C:\Program Files\Incomplete
[2010/07/18 12:10:10 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/03/07 20:21:14 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/06/26 21:18:28 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2006/12/31 00:20:06 | 000,000,000 | ---D | M] -- C:\Program Files\IrfanView
[2009/06/26 21:31:59 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2009/10/15 13:52:01 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2007/11/25 17:40:30 | 000,000,000 | ---D | M] -- C:\Program Files\Kodak
[2009/07/25 13:09:07 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2008/02/23 14:06:39 | 000,000,000 | ---D | M] -- C:\Program Files\Logitech
[2011/01/08 19:39:44 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2006/08/09 09:17:36 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2011/06/21 22:05:48 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee Security Scan
[2006/08/09 09:17:30 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2008/08/13 23:55:44 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2008/03/29 10:59:06 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger Plus! Live
[2009/06/12 16:37:41 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2007/05/08 16:38:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2006/08/09 09:11:55 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Digital Image 2006
[2011/03/04 16:13:05 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/08/30 16:30:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft IntelliPoint
[2009/08/30 16:28:02 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft IntelliType Pro
[2007/01/15 17:05:46 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Money 2006
[2011/03/04 22:37:47 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009/10/20 18:38:01 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office Outlook Connector
[2011/06/17 10:09:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2009/06/12 16:34:01 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2009/06/12 16:35:17 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Sync Framework
[2011/03/04 22:37:41 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2011/03/04 22:31:35 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 8
[2011/03/05 19:05:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2011/03/04 22:36:32 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2010/03/10 19:05:02 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2011/07/08 19:07:43 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/03/07 20:26:41 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2008/08/29 10:02:49 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2010/09/11 19:22:57 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2007/12/11 22:12:02 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Encarta Plus
[2009/04/05 13:54:07 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Games
[2006/06/17 02:35:49 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2008/04/22 16:30:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Messenger
[2006/12/04 23:44:47 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009/03/07 20:18:57 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2009/03/27 15:54:34 | 000,000,000 | ---D | M] -- C:\Program Files\MySpace
[2007/12/24 15:18:06 | 000,000,000 | ---D | M] -- C:\Program Files\Napster
[2006/06/17 02:38:42 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2008/12/22 12:48:10 | 000,000,000 | ---D | M] -- C:\Program Files\Oberon Media
[2006/06/17 02:36:43 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/12 18:44:31 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2006/12/10 16:53:10 | 000,000,000 | ---D | M] -- C:\Program Files\Overland
[2007/12/24 15:12:17 | 000,000,000 | ---D | M] -- C:\Program Files\Palm
[2007/05/25 12:03:28 | 000,000,000 | ---D | M] -- C:\Program Files\PhotoWorks
[2008/01/03 18:11:07 | 000,000,000 | ---D | M] -- C:\Program Files\Picaboo
[2008/07/12 19:46:17 | 000,000,000 | ---D | M] -- C:\Program Files\Picasa2
[2006/12/05 18:00:07 | 000,000,000 | ---D | M] -- C:\Program Files\PlayLinc
[2010/12/12 13:32:31 | 000,000,000 | ---D | M] -- C:\Program Files\PopCap Games
[2007/03/04 12:34:46 | 000,000,000 | ---D | M] -- C:\Program Files\Pure Networks
[2011/04/09 11:11:19 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2007/08/11 13:13:52 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2006/08/09 09:10:33 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek
[2010/07/20 15:16:16 | 000,000,000 | ---D | M] -- C:\Program Files\Recuva
[2009/03/07 20:26:29 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2009/09/18 19:06:21 | 000,000,000 | ---D | M] -- C:\Program Files\RegCleaner
[2009/09/18 18:21:23 | 000,000,000 | ---D | M] -- C:\Program Files\RegistryPatrol3.0
[2011/08/12 17:05:46 | 000,000,000 | ---D | M] -- C:\Program Files\SelectRebates
[2007/05/04 18:35:57 | 000,000,000 | ---D | M] -- C:\Program Files\Serious Magic
[2008/12/09 22:51:04 | 000,000,000 | ---D | M] -- C:\Program Files\Skype
[2009/09/04 11:13:02 | 000,000,000 | ---D | M] -- C:\Program Files\Southwest Airlines
[2007/12/06 18:53:26 | 000,000,000 | ---D | M] -- C:\Program Files\SplashData
[2011/08/12 16:46:03 | 000,000,000 | ---D | M] -- C:\Program Files\Spyware Doctor
[2010/07/18 09:41:32 | 000,000,000 | ---D | M] -- C:\Program Files\Stellar Phoenix Photo Recovery
[2010/11/30 20:36:55 | 000,000,000 | ---D | M] -- C:\Program Files\SUPERAntiSpyware
[2010/11/30 20:45:05 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2009/09/18 19:21:04 | 000,000,000 | ---D | M] -- C:\Program Files\Uniblue
[2006/06/17 02:46:08 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2011/08/12 16:46:24 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2011/06/03 21:10:10 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrentBar
[2010/05/10 12:10:26 | 000,000,000 | ---D | M] -- C:\Program Files\verizon
[2006/12/05 17:56:12 | 000,000,000 | ---D | M] -- C:\Program Files\VZBB Toolbar
[2010/11/30 20:58:07 | 000,000,000 | ---D | M] -- C:\Program Files\Webroot
[2007/01/19 20:13:56 | 000,000,000 | ---D | M] -- C:\Program Files\Western Digital Technologies
[2006/08/09 09:09:29 | 000,000,000 | ---D | M] -- C:\Program Files\WildTangent
[2009/03/06 18:16:44 | 000,000,000 | ---D | M] -- C:\Program Files\WinClamAVShield
[2010/12/16 19:13:28 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2007/11/30 11:43:28 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live Favorites
[2009/06/12 16:30:18 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2009/06/12 16:35:47 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live Toolbar
[2008/05/28 16:52:19 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2008/05/28 16:52:17 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2006/06/17 02:35:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2006/06/17 02:36:24 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Plus
[2006/06/17 02:39:10 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2006/06/17 02:41:40 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2009/04/28 19:56:37 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2008/01/20 14:39:39 | 000,000,000 | ---D | M] -- C:\Program Files\Zune
< MD5 for: AGP440.SYS >
[2004/08/10 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/10 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SDTemp\Download.old\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2009/10/13 12:21:20 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\AGP440.SYS
[2009/10/13 12:21:20 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\dllcache\agp440.sys
[2009/10/13 12:21:20 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/10 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/10 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SDTemp\Download.old\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004/08/04 05:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: DISK.SYS >
[2004/08/10 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2004/08/10 12:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:disk.sys
[2004/08/10 12:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys
[2008/04/13 11:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SDTemp\Download.old\dd9ab5193501484cf5e6884fa1d22f9e\disk.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SDTemp\Download.old\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/10 12:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtUninstallKB968389$\netlogon.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-13 01:21:33
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/06/21 22:41:55 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/06/21 22:41:55 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/06/21 22:41:55 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Flock\FLSET.exe" HIDE [2006/05/02 15:38:24 | 000,064,093 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Flock\flock\flock.exe" -silent -nosplash -setDefaultBrowser\
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Flock\FLSET.EXE" SHOW [2006/05/02 15:38:24 | 000,064,093 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\shell\open\command\\: C:\PROGRA~1\Flock\flock\flock.exe [2006/12/19 06:17:00 | 007,042,624 | ---- | M] (Flock Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\shell\properties\command\\: C:\PROGRA~1\Flock\flock\flock.exe -chrome "chrome://browser/content/pref/pref.xul" [2006/12/19 06:17:00 | 007,042,624 | ---- | M] (Flock Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2009/01/15 03:03:28 | 000,172,544 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2009/01/15 03:03:28 | 000,172,544 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2009/01/15 03:03:28 | 000,172,544 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/01/15 03:17:22 | 000,636,264 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2009/01/15 03:17:22 | 000,636,264 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\MSN Explorer\shell\open\command\\: "C:\Program Files\MSN\MSNCoreFiles\MSN.EXE" [2010/07/26 05:49:56 | 000,102,400 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/06/21 22:41:55 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/06/21 22:41:55 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/06/21 22:41:55 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/06/21 22:43:08 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Flock\FLSET.exe" HIDE [2006/05/02 15:38:24 | 000,064,093 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Flock\flock\flock.exe" -silent -nosplash -setDefaultBrowser\
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Flock\FLSET.EXE" SHOW [2006/05/02 15:38:24 | 000,064,093 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\shell\open\command\\: C:\PROGRA~1\Flock\flock\flock.exe [2006/12/19 06:17:00 | 007,042,624 | ---- | M] (Flock Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\flock.exe\shell\properties\command\\: C:\PROGRA~1\Flock\flock\flock.exe -chrome "chrome://browser/content/pref/pref.xul" [2006/12/19 06:17:00 | 007,042,624 | ---- | M] (Flock Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2009/01/15 03:03:28 | 000,172,544 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2009/01/15 03:03:28 | 000,172,544 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2009/01/15 03:03:28 | 000,172,544 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/01/15 03:17:22 | 000,636,264 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2009/01/15 03:17:22 | 000,636,264 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\MSN Explorer\shell\open\command\\: "C:\Program Files\MSN\MSNCoreFiles\MSN.EXE" [2010/07/26 05:49:56 | 000,102,400 | ---- | M] (Microsoft Corporation)
========== Alternate Data Streams ==========
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:813B8EB6
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7631EA83
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >