CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/29 06:17:56 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/11/25 17:06:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/11/25 17:05:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/11/25 17:05:52 | 000,320,856 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/11/25 17:05:52 | 000,020,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/11/25 17:05:50 | 000,052,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/11/25 17:05:50 | 000,034,392 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/11/25 17:05:49 | 000,442,200 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/11/25 17:05:48 | 000,110,552 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/11/25 17:05:48 | 000,104,536 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/11/25 17:05:48 | 000,030,808 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/11/25 17:05:25 | 000,199,304 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/11/25 17:05:25 | 000,041,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/11/25 17:05:08 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/11/25 17:05:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/11/25 11:10:06 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Liz\Desktop\OTL.exe
[2011/11/22 21:11:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/11/22 21:11:00 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/11/22 21:01:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/22 21:01:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Liz\Start Menu\Programs\Administrative Tools
[2011/11/20 13:05:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liz\Application Data\Malwarebytes
[2011/11/20 12:12:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/20 12:12:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/11/20 12:12:21 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/20 12:12:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/20 10:01:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/11/20 10:01:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/11/20 10:01:51 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/11/20 09:56:22 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2011/11/19 21:03:11 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Liz\Recent
[2011/11/19 17:05:44 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Liz\Start Menu\Programs\System Fix
[2011/11/18 21:28:51 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Local Settings
[2011/11/18 19:59:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liz\Desktop\TMS
[2011/11/07 15:58:44 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Liz\Application Data\Catalina Marketing Corp
[2011/11/07 15:58:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Liz\Start Menu\Programs\Catalina Marketing Corp
[2011/11/05 12:54:05 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2011/11/05 12:53:49 | 000,472,808 | -H-- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2011/11/05 12:53:49 | 000,157,472 | -H-- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/11/05 12:53:49 | 000,145,184 | -H-- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/11/05 12:53:49 | 000,145,184 | -H-- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/11/05 12:53:49 | 000,073,728 | -H-- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2007/02/03 22:33:00 | 000,774,144 | -H-- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[42 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/30 15:00:25 | 000,000,886 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/30 10:27:15 | 000,000,882 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/30 08:59:09 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D9FE9395-3A27-43D4-9673-54E7E4E77818}.job
[2011/11/30 06:54:33 | 000,001,158 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/30 06:52:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/25 17:51:05 | 000,001,802 | ---- | M] () -- C:\Documents and Settings\Liz\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/25 17:06:51 | 000,001,824 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/11/25 17:05:53 | 000,001,700 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/11/25 17:03:42 | 061,657,064 | ---- | M] () -- C:\Documents and Settings\Liz\Desktop\setup_av_free_cnet.exe
[2011/11/25 11:10:06 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Liz\Desktop\OTL.exe
[2011/11/23 23:38:01 | 000,000,284 | -H-- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/20 12:12:27 | 000,000,795 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/20 10:01:54 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/19 20:59:54 | 008,509,440 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/11/19 20:59:53 | 006,301,696 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/11/19 20:39:58 | 000,000,022 | -H-- | M] () -- C:\WINDOWS\kodakpcd.HP_Administrator.ini
[2011/11/19 17:08:47 | 000,446,812 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/19 17:08:47 | 000,073,574 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/11/19 17:08:18 | 000,000,448 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\epSmiWdo1fgPAc
[2011/11/19 17:05:45 | 000,000,288 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~epSmiWdo1fgPAc
[2011/11/19 17:05:45 | 000,000,216 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~epSmiWdo1fgPAcr
[2011/11/19 16:55:26 | 000,864,800 | -H-- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/19 00:39:38 | 000,013,824 | -H-- | M] () -- C:\WINDOWS\System32\IdbuwjiLmodq.dll
[2011/11/18 19:59:40 | 000,017,408 | -H-- | M] () -- C:\Documents and Settings\Liz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/09 23:57:41 | 000,010,504 | -H-- | M] () -- C:\Documents and Settings\Liz\Application Data\wklnhst.dat
[2011/11/09 23:57:35 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Liz\My Documents\MID TERM ESSAY.wps
[2011/11/05 20:34:24 | 000,546,000 | ---- | M] () -- C:\Documents and Settings\Liz\My Documents\SSPX9999.jpg
[2011/11/05 12:53:30 | 000,472,808 | -H-- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2011/11/05 12:53:30 | 000,157,472 | -H-- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/11/05 12:53:30 | 000,145,184 | -H-- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/11/05 12:53:30 | 000,145,184 | -H-- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/11/05 12:53:30 | 000,073,728 | -H-- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2011/11/04 14:37:46 | 000,016,896 | ---- | M] () -- C:\Documents and Settings\Liz\My Documents\Exxon.wps
[2011/11/04 12:32:59 | 000,016,384 | ---- | M] () -- C:\Documents and Settings\Liz\My Documents\Rules.wps
[42 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/25 17:06:51 | 000,001,824 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/11/25 17:06:51 | 000,001,802 | ---- | C] () -- C:\Documents and Settings\Liz\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/25 17:05:53 | 000,001,700 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/11/25 17:03:11 | 061,657,064 | ---- | C] () -- C:\Documents and Settings\Liz\Desktop\setup_av_free_cnet.exe
[2011/11/20 12:12:27 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/20 10:01:54 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/19 20:39:58 | 000,000,022 | -H-- | C] () -- C:\WINDOWS\kodakpcd.HP_Administrator.ini
[2011/11/19 17:05:45 | 000,000,288 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~epSmiWdo1fgPAc
[2011/11/19 17:05:45 | 000,000,216 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~epSmiWdo1fgPAcr
[2011/11/19 17:05:36 | 000,000,448 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\epSmiWdo1fgPAc
[2011/11/19 00:39:38 | 000,013,824 | -H-- | C] () -- C:\WINDOWS\System32\IdbuwjiLmodq.dll
[2011/11/09 14:32:28 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Liz\My Documents\MID TERM ESSAY.wps
[2011/11/07 19:35:20 | 000,546,000 | ---- | C] () -- C:\Documents and Settings\Liz\My Documents\SSPX9999.jpg
[2011/11/07 19:26:22 | 002,215,914 | ---- | C] () -- C:\Documents and Settings\Liz\My Documents\100_0061.JPG
[2011/11/04 12:49:29 | 000,016,896 | ---- | C] () -- C:\Documents and Settings\Liz\My Documents\Exxon.wps
[2011/11/04 12:32:59 | 000,016,384 | ---- | C] () -- C:\Documents and Settings\Liz\My Documents\Rules.wps
[2011/08/01 17:32:32 | 000,001,129 | -H-- | C] () -- C:\WINDOWS\HBCIKRNL.INI
[2011/06/28 19:40:04 | 000,000,022 | -H-- | C] () -- C:\WINDOWS\kodakpcd.Liz.ini
[2011/06/10 13:18:14 | 000,012,378 | -HS- | C] () -- C:\Documents and Settings\Liz\Local Settings\Application Data\q4ta1hu2fuke6yb3bssy4t2ab
[2011/06/10 13:18:14 | 000,012,378 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\q4ta1hu2fuke6yb3bssy4t2ab
[2010/10/18 08:14:17 | 000,032,608 | -H-- | C] () -- C:\WINDOWS\king-uninstall.exe
[2010/06/19 07:02:50 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\MSDraw.ini
[2010/01/06 12:38:34 | 000,153,880 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/07/05 09:50:40 | 000,000,256 | -H-- | C] () -- C:\WINDOWS\System32\pool.bin
[2008/12/20 20:26:38 | 000,870,128 | -H-- | C] () -- C:\Documents and Settings\Liz\Application Data\mcs.rma
[2008/12/20 20:26:38 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Liz\Application Data\DF54DB
[2008/11/15 20:03:06 | 000,001,222 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/04/08 12:18:25 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\PTWebCam.INI
[2008/02/26 23:19:03 | 000,000,000 | -H-- | C] () -- C:\Program Files\temp01
[2007/12/20 18:45:57 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2007/11/29 19:14:32 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\Game.INI
[2007/08/12 17:40:20 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\popcreg.dat
[2007/07/04 18:20:44 | 000,000,112 | -H-- | C] () -- C:\WINDOWS\popcinfot.dat
[2007/06/14 02:01:32 | 000,000,127 | -H-- | C] () -- C:\WINDOWS\System32\MRT.INI
[2006/12/22 22:49:21 | 000,002,180 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/19 12:09:06 | 000,010,504 | -H-- | C] () -- C:\Documents and Settings\Liz\Application Data\wklnhst.dat
[2006/10/05 16:52:40 | 000,000,042 | -H-- | C] () -- C:\WINDOWS\VistaEmail.ini
[2006/09/23 21:27:29 | 000,017,408 | -H-- | C] () -- C:\Documents and Settings\Liz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/23 20:37:56 | 000,000,126 | -H-- | C] () -- C:\Documents and Settings\Liz\Local Settings\Application Data\fusioncache.dat
[2006/09/21 00:02:07 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\invupd.exe
[2006/09/20 22:08:32 | 000,000,419 | -H-- | C] () -- C:\WINDOWS\ukuld.dll
[2006/09/20 22:08:32 | 000,000,053 | -H-- | C] () -- C:\WINDOWS\qoowle.dat
[2006/09/20 22:02:05 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\invupdate.exe
[2006/09/19 17:04:50 | 000,000,227 | -H-- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/09/19 17:04:37 | 000,000,214 | -H-- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/19 17:02:19 | 000,204,800 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/09/19 17:02:19 | 000,200,704 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/09/19 17:02:19 | 000,192,512 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/09/19 17:02:19 | 000,192,512 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/09/19 17:02:19 | 000,188,416 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/09/19 17:02:19 | 000,020,480 | -H-- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/09/19 16:56:49 | 000,000,206 | -H-- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/09/14 13:57:25 | 000,004,096 | -H-- | C] () -- C:\WINDOWS\d3dx.dat
[2006/09/07 15:05:04 | 000,010,240 | -H-- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006/08/15 11:10:32 | 000,000,221 | -H-- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/07/30 18:05:11 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\bbbconfig.dat
[2006/07/21 21:17:53 | 000,000,029 | -H-- | C] () -- C:\WINDOWS\TLCAPPS.INI
[2006/07/21 21:12:32 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SETUP32.INI
[2006/06/17 14:20:22 | 000,000,199 | -H-- | C] () -- C:\WINDOWS\popcinfo.dat
[2006/06/11 17:48:46 | 000,077,824 | RH-- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/06/11 17:48:09 | 000,087,989 | -H-- | C] () -- C:\WINDOWS\hpoins06.dat.temp
[2006/06/11 17:48:09 | 000,005,389 | -H-- | C] () -- C:\WINDOWS\hpomdl06.dat.temp
[2006/06/11 17:21:59 | 000,000,037 | -H-- | C] () -- C:\WINDOWS\Acroread.ini
[2006/03/28 03:10:28 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/28 02:45:17 | 000,028,848 | -H-- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2006/03/28 02:40:42 | 000,118,842 | RH-- | C] () -- C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2006/03/28 02:39:54 | 000,014,316 | -H-- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2006/03/28 02:39:47 | 000,045,056 | -H-- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2006/03/28 02:37:23 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\Quicken.ini
[2006/03/28 02:34:22 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2006/03/28 02:23:03 | 000,000,108 | -H-- | C] () -- C:\WINDOWS\WININIT.INI
[2006/03/28 02:21:31 | 000,045,929 | -H-- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/03/28 02:21:31 | 000,000,698 | -H-- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/03/28 02:16:01 | 000,080,417 | -H-- | C] () -- C:\WINDOWS\HPHins08.dat
[2006/03/28 02:16:01 | 000,004,011 | -H-- | C] () -- C:\WINDOWS\hphmdl08.dat
[2006/03/28 02:14:57 | 000,072,881 | -H-- | C] () -- C:\WINDOWS\hpiins01.dat
[2006/03/28 02:14:57 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\hpimdl01.dat
[2006/03/28 02:10:34 | 000,087,276 | -H-- | C] () -- C:\WINDOWS\hpqins69.dat
[2006/03/28 02:08:47 | 000,112,873 | -H-- | C] () -- C:\WINDOWS\hpoins07.dat
[2006/03/28 02:08:47 | 000,021,124 | -H-- | C] () -- C:\WINDOWS\hpomdl07.dat
[2006/03/28 02:05:23 | 000,087,974 | -H-- | C] () -- C:\WINDOWS\hpoins06.dat
[2006/03/28 02:05:23 | 000,005,389 | -H-- | C] () -- C:\WINDOWS\hpomdl06.dat
[2006/03/28 02:04:14 | 000,001,793 | -H-- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/03/28 01:59:55 | 000,000,791 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2006/03/28 01:36:10 | 000,016,896 | -H-- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2005/12/09 06:03:52 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/30 13:17:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/08/30 13:07:46 | 000,446,812 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/08/30 13:07:46 | 000,073,574 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/08/30 13:05:30 | 000,864,800 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/30 13:01:42 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/30 12:58:02 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/08/05 14:01:54 | 000,239,104 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 16:19:16 | 000,050,176 | -H-- | C] () -- C:\WINDOWS\armcex.dll
[2004/08/09 20:00:00 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/09 13:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/09 13:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/09 13:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/09 13:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/09 13:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/09 13:00:00 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/09 13:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/07/25 23:51:38 | 000,000,560 | -H-- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 00:12:28 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 00:11:02 | 000,004,490 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/07/06 15:30:00 | 000,003,399 | -H-- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2000/09/08 16:53:50 | 000,073,839 | -H-- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
[2011/11/25 11:10:06 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Liz\Desktop\OTL.exe
[2011/11/25 17:03:42 | 061,657,064 | ---- | M] () -- C:\Documents and Settings\Liz\Desktop\setup_av_free_cnet.exe
< %PROGRAMFILES%\Common Files\*.* >
[2006/11/24 17:52:28 | 000,000,000 | -H-- | M] () -- C:\Program Files\Common Files\err.log
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
[2007/08/02 17:22:20 | 015,505,200 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Liz\My Documents\IE7-WindowsXP-x86-enu.exe
[2006/10/15 15:28:06 | 036,656,704 | ---- | M] (Apple Computer, Inc.) -- C:\Documents and Settings\Liz\My Documents\iTunesSetup.exe
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2011/11/08 18:43:57 | 000,110,040 | -H-- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2011/11/08 18:43:57 | 000,912,856 | -H-- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2011/11/08 18:43:57 | 000,016,856 | -H-- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2011/11/08 18:43:58 | 000,247,768 | -H-- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[42 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2006/07/23 12:13:56 | 000,000,000 | -H-D | M] -- C:\Program Files\Activision Value
[2011/07/10 10:05:04 | 000,000,000 | -H-D | M] -- C:\Program Files\Adobe
[2006/08/12 15:56:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Alphaqueue
[2006/12/17 22:32:22 | 000,000,000 | -H-D | M] -- C:\Program Files\AntiVerminsPro
[2011/07/05 21:03:52 | 000,000,000 | -H-D | M] -- C:\Program Files\Apple Software Update
[2011/11/25 17:05:08 | 000,000,000 | ---D | M] -- C:\Program Files\AVAST Software
[2011/07/03 18:43:48 | 000,000,000 | -H-D | M] -- C:\Program Files\AVS4YOU
[2006/07/21 21:01:53 | 000,000,000 | -H-D | M] -- C:\Program Files\Broderbund
[2011/09/17 09:07:18 | 000,000,000 | -H-D | M] -- C:\Program Files\Common Files
[2005/11/11 07:56:40 | 000,000,000 | -H-D | M] -- C:\Program Files\ComPlus Applications
[2006/03/28 02:02:11 | 000,000,000 | -H-D | M] -- C:\Program Files\CONEXANT
[2011/05/03 12:19:44 | 000,000,000 | -H-D | M] -- C:\Program Files\CouponAlert_2pEI
[2011/05/02 13:24:24 | 000,000,000 | -H-D | M] -- C:\Program Files\Coupons
[2010/12/28 00:27:39 | 000,000,000 | -H-D | M] -- C:\Program Files\CyberLink
[2008/04/20 11:53:25 | 000,000,000 | -H-D | M] -- C:\Program Files\Disney
[2006/07/21 21:23:22 | 000,000,000 | -H-D | M] -- C:\Program Files\DK Interactive Learning
[2009/07/15 02:02:56 | 000,000,000 | -H-D | M] -- C:\Program Files\driver
[2009/07/27 21:46:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Free Offers from Freeze.com
[2010/06/03 12:01:01 | 000,000,000 | -H-D | M] -- C:\Program Files\FreshGames
[2008/06/09 10:30:33 | 000,000,000 | -H-D | M] -- C:\Program Files\GameHouse
[2007/12/18 19:16:31 | 000,000,000 | -H-D | M] -- C:\Program Files\Games
[2011/11/25 17:06:38 | 000,000,000 | -H-D | M] -- C:\Program Files\Google
[2009/06/28 10:00:14 | 000,000,000 | -H-D | M] -- C:\Program Files\Groove Games
[2006/03/28 03:03:43 | 000,000,000 | -H-D | M] -- C:\Program Files\Hewlett-Packard
[2006/03/28 02:29:05 | 000,000,000 | -H-D | M] -- C:\Program Files\HP
[2008/12/10 16:51:58 | 000,000,000 | -H-D | M] -- C:\Program Files\HP Games
[2006/09/20 22:03:06 | 000,000,000 | -H-D | M] -- C:\Program Files\Icon Drop
[2011/07/03 20:06:46 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2006/12/17 22:19:19 | 000,000,000 | -H-D | M] -- C:\Program Files\IntelliMoverDemo
[2011/04/13 02:11:51 | 000,000,000 | -H-D | M] -- C:\Program Files\Internet Explorer
[2006/09/19 17:02:10 | 000,000,000 | -H-D | M] -- C:\Program Files\InterVideo
[2011/07/04 10:40:40 | 000,000,000 | -H-D | M] -- C:\Program Files\iPod
[2011/07/04 10:41:37 | 000,000,000 | -H-D | M] -- C:\Program Files\iTunes
[2008/09/30 19:24:10 | 000,000,000 | -H-D | M] -- C:\Program Files\iWin.com
[2011/11/05 12:53:26 | 000,000,000 | -H-D | M] -- C:\Program Files\Java
[2009/06/28 09:43:57 | 000,000,000 | -H-D | M] -- C:\Program Files\Kids Cam Show and Share Creativity Center
[2006/09/22 14:10:45 | 000,000,000 | -H-D | M] -- C:\Program Files\Kodak
[2008/05/20 09:02:26 | 000,000,000 | -H-D | M] -- C:\Program Files\LEGO Software
[2007/10/03 10:48:40 | 000,000,000 | -H-D | M] -- C:\Program Files\LimeWire
[2009/07/16 17:55:53 | 000,000,000 | -H-D | M] -- C:\Program Files\Lost Fortunes
[2007/02/03 18:16:48 | 000,000,000 | -H-D | M] -- C:\Program Files\Luxor
[2011/11/20 12:12:28 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2006/11/25 11:13:30 | 000,000,000 | -H-D | M] -- C:\Program Files\MalwareWiper
[2006/09/07 15:04:33 | 000,000,000 | -H-D | M] -- C:\Program Files\Mattel Media
[2010/11/13 22:41:25 | 000,000,000 | -H-D | M] -- C:\Program Files\Media Widget
[2009/06/28 10:19:22 | 000,000,000 | -H-D | M] -- C:\Program Files\Messenger
[2010/11/13 22:49:17 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft
[2009/06/29 02:05:26 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2005/11/14 10:06:48 | 000,000,000 | -H-D | M] -- C:\Program Files\microsoft frontpage
[2007/08/03 16:22:13 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft Money
[2011/07/28 20:58:36 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft Office
[2006/03/28 02:33:17 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft Visual Studio
[2011/07/28 20:53:55 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft Visual Studio 8
[2011/07/28 20:59:08 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft Works
[2011/07/28 20:57:28 | 000,000,000 | -H-D | M] -- C:\Program Files\Microsoft.NET
[2010/08/13 02:02:00 | 000,000,000 | -H-D | M] -- C:\Program Files\Movie Maker
[2011/11/17 21:59:28 | 000,000,000 | -H-D | M] -- C:\Program Files\Mozilla Firefox
[2011/07/28 20:58:53 | 000,000,000 | -H-D | M] -- C:\Program Files\MSBuild
[2010/05/16 08:52:40 | 000,000,000 | -H-D | M] -- C:\Program Files\MSN
[2006/03/28 02:19:53 | 000,000,000 | -H-D | M] -- C:\Program Files\MSN Encarta Standard
[2005/11/14 10:07:16 | 000,000,000 | -H-D | M] -- C:\Program Files\MSN Gaming Zone
[2006/11/16 03:00:51 | 000,000,000 | -H-D | M] -- C:\Program Files\MSXML 4.0
[2007/08/15 02:02:15 | 000,000,000 | -H-D | M] -- C:\Program Files\MSXML 6.0
[2006/03/28 02:21:05 | 000,000,000 | -H-D | M] -- C:\Program Files\music_now
[2010/05/16 08:53:13 | 000,000,000 | -H-D | M] -- C:\Program Files\muvee Technologies
[2009/05/19 15:38:29 | 000,000,000 | -H-D | M] -- C:\Program Files\MySpace
[2009/06/28 10:08:39 | 000,000,000 | -H-D | M] -- C:\Program Files\NetMeeting
[2006/03/28 02:21:19 | 000,000,000 | -H-D | M] -- C:\Program Files\Netscape
[2008/04/25 19:09:18 | 000,000,000 | -H-D | M] -- C:\Program Files\Nick Arcade
[2011/06/29 10:12:02 | 000,000,000 | -H-D | M] -- C:\Program Files\NortonInstaller
[2006/03/28 02:50:09 | 000,000,000 | -H-D | M] -- C:\Program Files\Online Services
[2010/12/15 03:02:02 | 000,000,000 | -H-D | M] -- C:\Program Files\Outlook Express
[2007/02/01 20:44:45 | 000,000,000 | -H-D | M] -- C:\Program Files\Paparazzi
[2006/03/28 02:45:18 | 000,000,000 | -H-D | M] -- C:\Program Files\PC-Doctor for DOS
[2011/07/03 20:29:38 | 000,000,000 | -H-D | M] -- C:\Program Files\PopCap Games
[2009/06/21 21:23:56 | 000,000,000 | -H-D | M] -- C:\Program Files\Quicken
[2011/07/04 10:37:33 | 000,000,000 | -H-D | M] -- C:\Program Files\QuickTime
[2011/07/03 20:35:21 | 000,000,000 | -H-D | M] -- C:\Program Files\Real
[2011/07/03 20:19:39 | 000,000,000 | -H-D | M] -- C:\Program Files\RealArcade
[2009/08/21 02:05:21 | 000,000,000 | -H-D | M] -- C:\Program Files\Reference Assemblies
[2007/02/01 19:01:08 | 000,000,000 | -H-D | M] -- C:\Program Files\ReflexiveArcade
[2010/05/16 08:55:23 | 000,000,000 | -H-D | M] -- C:\Program Files\Rhapsody
[2009/07/05 09:21:00 | 000,000,000 | -H-D | M] -- C:\Program Files\Roxio
[2011/07/03 20:23:25 | 000,000,000 | -H-D | M] -- C:\Program Files\Safari
[2009/06/28 10:04:01 | 000,000,000 | -H-D | M] -- C:\Program Files\Saints & Sinners Bowling
[2011/08/01 17:32:24 | 000,000,000 | -H-D | M] -- C:\Program Files\SCM Microsystems
[2006/03/28 02:27:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Sonic
[2010/12/11 08:12:16 | 000,000,000 | -H-D | M] -- C:\Program Files\Sony Online Entertainment
[2006/12/07 17:48:39 | 000,000,000 | -H-D | M] -- C:\Program Files\Spyware Doctor
[2011/11/20 10:02:38 | 000,000,000 | ---D | M] -- C:\Program Files\SUPERAntiSpyware
[2009/06/21 21:22:20 | 000,000,000 | -H-D | M] -- C:\Program Files\Symantec
[2006/08/26 02:42:01 | 000,000,000 | -H-D | M] -- C:\Program Files\SymNetDrv
[2010/11/13 22:54:24 | 000,000,000 | -H-D | M] -- C:\Program Files\The Learning Company
[2006/07/21 19:12:37 | 000,000,000 | -H-D | M] -- C:\Program Files\The Print Shop 20
[2009/12/17 13:27:41 | 000,000,000 | -H-D | M] -- C:\Program Files\Trillian
[2006/08/05 14:40:36 | 000,000,000 | -H-D | M] -- C:\Program Files\TryMedia
[2005/11/11 07:56:28 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/10/24 16:27:25 | 000,000,000 | -H-D | M] -- C:\Program Files\Unity
[2006/03/28 02:40:39 | 000,000,000 | -H-D | M] -- C:\Program Files\Updates from HP
[2006/07/21 22:56:15 | 000,000,000 | -H-D | M] -- C:\Program Files\ValuSoft
[2008/10/01 20:07:14 | 000,000,000 | -H-D | M] -- C:\Program Files\Virtual Earth 3D
[2006/09/23 22:00:41 | 000,000,000 | -H-D | M] -- C:\Program Files\Web Publish
[2008/12/10 16:52:03 | 000,000,000 | -H-D | M] -- C:\Program Files\WildTangent
[2009/06/28 10:08:37 | 000,000,000 | -H-D | M] -- C:\Program Files\Windows Media Player
[2009/06/28 10:08:37 | 000,000,000 | -H-D | M] -- C:\Program Files\Windows NT
[2005/11/14 10:08:32 | 000,000,000 | -H-D | M] -- C:\Program Files\Windows Plus
[2005/11/11 07:56:16 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2005/11/14 10:08:44 | 000,000,000 | -H-D | M] -- C:\Program Files\xerox
[2006/12/30 14:36:41 | 000,000,000 | -H-D | M] -- C:\Program Files\Yahoo!
[2011/11/20 14:43:06 | 000,000,000 | -H-D | M] -- C:\Program Files\Yahoo! Games
[2009/05/24 15:00:49 | 000,000,000 | -H-D | M] -- C:\Program Files\Yard Sale Hidden Treasures - Lucky Junction
[2010/11/06 17:08:08 | 000,000,000 | -H-D | M] -- C:\Program Files\Yontoo Layers Client
< MD5 for: AGP440.SYS >
[2004/08/09 20:00:00 | 016,971,599 | -H-- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/06/28 10:00:56 | 023,852,652 | -H-- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/09 13:00:00 | 016,971,599 | -H-- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2009/06/28 10:00:56 | 023,852,652 | -H-- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | -H-- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | -H-- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/09 20:00:00 | 016,971,599 | -H-- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/06/28 10:00:56 | 023,852,652 | -H-- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/09 13:00:00 | 016,971,599 | -H-- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys
[2009/06/28 10:00:56 | 023,852,652 | -H-- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | -H-- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | -H-- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | -H-- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/09 13:00:00 | 000,095,360 | -H-- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | -H-- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2004/08/09 20:00:00 | 016,971,599 | -H-- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2009/06/28 10:00:56 | 023,852,652 | -H-- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2004/08/09 13:00:00 | 016,971,599 | -H-- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:disk.sys
[2009/06/28 10:00:56 | 023,852,652 | -H-- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/09 13:00:00 | 000,036,352 | -H-- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 10:40:47 | 000,036,352 | -H-- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 10:40:47 | 000,036,352 | -H-- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | -H-- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | -H-- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | -H-- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | -H-- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/09 13:00:00 | 001,032,192 | -H-- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: IASTOR.SYS >
[2005/06/16 22:33:40 | 000,872,064 | -H-- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 -- C:\hp\drivers\Intel_5_1_0_1022_PV\iastor.sys
[2005/06/16 22:33:40 | 000,872,064 | -H-- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 -- C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | -H-- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | -H-- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/09 13:00:00 | 000,407,040 | -H-- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: USERINIT.EXE >
[2004/08/09 13:00:00 | 000,024,576 | -H-- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | -H-- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | -H-- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/09 13:00:00 | 000,502,272 | -H-- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | -H-- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | -H-- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
H