C:\WINDOWS\System32\ReinstallBackups
[2012/08/16 16:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2012/08/16 16:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2012/08/16 16:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2012/08/16 16:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2012/08/16 16:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\FxsTmp
[2012/08/16 16:04:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2012/08/16 16:04:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2012/08/16 16:04:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2012/08/16 16:04:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2012/08/16 16:03:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012/08/16 16:03:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2012/08/16 16:03:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2012/08/16 16:03:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2012/08/16 16:03:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\inf
[2012/08/16 16:03:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2012/08/16 16:03:07 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2012/08/16 16:03:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\Fonts
[2012/08/16 13:25:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Application Data\Intuit
[2012/08/16 13:25:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Application Data\Identities
[2012/08/16 13:25:21 | 000,000,000 | --SD | C] -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
[2012/08/16 13:25:21 | 000,000,000 | --SD | C] -- C:\Documents and Settings\HP_Administrator\Cookies
[2012/08/16 13:25:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HP_Administrator\SendTo
[2012/08/16 13:25:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HP_Administrator\Recent
[2012/08/16 13:25:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HP_Administrator\Application Data
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\Start Menu
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\My Documents\My Videos
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\My Documents\My Pictures
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\My Documents\My Music
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\My Documents
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\Favorites
[2012/08/16 13:25:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Accessories
[2012/08/16 13:25:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HP_Administrator\Templates
[2012/08/16 13:25:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HP_Administrator\PrintHood
[2012/08/16 13:25:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HP_Administrator\NetHood
[2012/08/16 13:25:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HP_Administrator\Local Settings
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\WINDOWS
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Wildtangent
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Application Data\Symantec
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Application Data\Real
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Online Services
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Desktop
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\ApplicationHistory
[2012/08/16 13:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
[2012/08/16 13:25:17 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\windows nt
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\windows media player
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\system
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\speechengines
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\outlook express
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\netmeeting
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\movie maker
[2012/08/16 13:25:16 | 000,000,000 | ---D | C] -- C:\Program Files\internet explorer
[2012/08/16 13:25:15 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2012/08/03 12:08:02 | 000,526,640 | ---- | C] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/17 11:04:01 | 000,001,022 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1193780334-1537497407-278222325-1008UA.job
[2012/08/17 11:02:29 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/08/17 11:02:29 | 000,000,178 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2012/08/17 11:02:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/08/17 10:09:59 | 000,001,128 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\My LastPass Vault.lnk
[2012/08/17 10:05:58 | 000,415,877 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/08/17 10:05:44 | 000,193,776 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/17 10:04:17 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoneAlarm Security.lnk
[2012/08/17 10:04:00 | 000,000,970 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1193780334-1537497407-278222325-1008Core.job
[2012/08/17 10:00:36 | 000,001,919 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/08/17 09:56:52 | 000,002,376 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Desktop\Google Chrome.lnk
[2012/08/17 09:56:52 | 000,002,354 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/17 09:48:24 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/08/16 13:29:41 | 000,381,692 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/08/16 13:29:41 | 000,053,436 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/08/16 13:25:48 | 000,000,601 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/16 13:25:44 | 000,001,489 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/08/16 13:25:19 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/08/16 13:24:40 | 000,001,197 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/08/16 13:24:38 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2012/08/03 12:08:02 | 000,526,640 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/17 10:09:59 | 000,001,128 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\My LastPass Vault.lnk
[2012/08/17 10:04:33 | 000,415,877 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/08/17 10:04:17 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoneAlarm Security.lnk
[2012/08/17 10:00:36 | 000,001,919 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/08/17 09:56:52 | 000,002,376 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Desktop\Google Chrome.lnk
[2012/08/17 09:56:52 | 000,002,354 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/17 09:54:55 | 000,001,022 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1193780334-1537497407-278222325-1008UA.job
[2012/08/17 09:54:55 | 000,000,970 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1193780334-1537497407-278222325-1008Core.job
[2012/08/17 09:48:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/08/16 17:23:16 | 000,000,178 | ---- | C] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2012/08/16 13:25:26 | 000,000,026 | RH-- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\AXEL.DAV
[2012/08/16 13:25:25 | 000,001,776 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Netscape Browser.lnk
[2012/08/16 13:25:25 | 000,001,659 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Desktop\3 Month Trial AOL Music Now.lnk
[2012/08/16 13:25:25 | 000,001,489 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/08/16 13:25:25 | 000,000,926 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2012/08/16 13:25:25 | 000,000,674 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\HP Rhapsody.lnk
[2012/08/16 13:25:25 | 000,000,601 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/16 13:25:25 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/08/16 13:25:25 | 000,000,026 | R--- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\AXEL.DAV
[2012/08/16 13:25:25 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Desktop\AXEL.DAV
[2012/08/16 13:25:25 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\AXEL.DAV
[2012/08/16 13:25:24 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2012/08/16 13:25:24 | 000,000,026 | R--- | C] () -- C:\Documents and Settings\HP_Administrator\My Documents\AXEL.DAV
[2012/08/16 13:25:24 | 000,000,026 | -H-- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\AXEL.DAV
[2012/08/16 13:25:22 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/08/16 13:25:22 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/08/16 13:25:22 | 000,000,589 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Internet Explorer.lnk
[2012/08/16 13:25:22 | 000,000,563 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Outlook Express.lnk
[2012/08/16 13:25:22 | 000,000,026 | R--- | C] () -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\AXEL.DAV
[2012/08/16 13:25:22 | 000,000,026 | R--- | C] () -- C:\Documents and Settings\HP_Administrator\Start Menu\Programs\AXEL.DAV
[2006/02/13 20:44:19 | 000,000,026 | -H-- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\AXEL.DAV
[2006/02/13 20:44:19 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\AXEL.DAV
[2006/02/13 20:44:18 | 000,000,026 | -H-- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\AXEL.DAV
[2006/02/13 20:44:18 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\NetworkService\Application Data\AXEL.DAV
[2005/11/14 21:08:44 | 000,000,026 | ---- | C] () -- C:\Program Files\AXEL.DAV
[2005/11/14 21:06:18 | 000,000,026 | ---- | C] () -- C:\Program Files\Common Files\AXEL.DAV
[2005/11/14 21:05:18 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\All Users\AXEL.DAV
[2005/11/14 21:04:36 | 000,000,026 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\AXEL.DAV
========== Custom Scans ==========
< %AppData%\Roaming\Mozilla\Firefox\Profiles\*.default\extensions\ /s /md5 >
< %AppData%\Local\ >
< %systemroot%\system32\sysprep >
< *.xpi /md5 >
< %systemroot%\Downloaded Program Files\ >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile >
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\InstallInfo\\ShowIconsCommand: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --show-icons [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\InstallInfo\\HideIconsCommand: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --hide-icons [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\InstallInfo\\ReinstallCommand: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\shell\open\command\\: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2004/08/10 00:00:00 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2004/08/10 00:00:00 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2004/08/10 00:00:00 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Netscape\Netscape Browser\NSSET.exe" HIDE
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Netscape\Netscape Browser\NSSET.exe" REGISTER
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Netscape\Netscape Browser\NSSET.EXE" SHOW
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\shell\open\command\\:
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\shell\properties\command\\: -chrome "chrome://browser/content/pref/pref.xul"
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\InstallInfo\\ShowIconsCommand: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --show-icons [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\InstallInfo\\HideIconsCommand: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --hide-icons [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\InstallInfo\\ReinstallCommand: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome.4WY56ANC2F6RZA7CDQU7UIP47Y\shell\open\command\\: "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/08/14 00:31:01 | 001,229,848 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2004/08/10 00:00:00 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2004/08/10 00:00:00 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2004/08/10 00:00:00 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Netscape\Netscape Browser\NSSET.exe" HIDE
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Netscape\Netscape Browser\NSSET.exe" REGISTER
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Netscape\Netscape Browser\NSSET.EXE" SHOW
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\shell\open\command\\:
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\netscape.exe\shell\properties\command\\: -chrome "chrome://browser/content/pref/pref.xul"
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\drivers\*.sys /90 >
< %systemroot%\System32\config\*.sav >
[2005/08/30 16:51:10 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005/08/30 16:51:10 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
< %SYSTEMDRIVE%\*.exe /md5 >
[2005/12/27 03:21:54 | 007,477,561 | ---- | M] (Intel Corporation ) MD5=9398064AECBFEA5565E341B99A5C8B3C -- C:\setup_all.exe
< "%WinDir%\$NtUninstallKB*$." /30 >
< %systemdrive%\Program Files\Common Files\ComObjects\*.* /s >
< %systemroot%\*. /mp /s >
< %systemroot%\*. /rp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\Installer\ /s >
< %systemroot%\system32\Cache\ /s >
< %systemroot%\system32\config\systemprofile\Application Data /s >
< %PROGRAMFILES%\*. >
[2012/08/16 16:09:55 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2012/08/17 10:04:22 | 000,000,000 | ---D | M] -- C:\Program Files\CheckPoint
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\internet explorer
[2012/08/17 10:10:02 | 000,000,000 | ---D | M] -- C:\Program Files\LastPass
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\movie maker
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\msn gaming zone
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\netmeeting
[2012/08/16 13:25:16 | 000,000,000 | ---D | M] -- C:\Program Files\outlook express
[2012/08/16 13:25:44 | 000,000,000 | ---D | M] -- C:\Program Files\windows media player
[2012/08/16 13:25:17 | 000,000,000 | ---D | M] -- C:\Program Files\windows nt
[2012/08/16 13:25:17 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
< %appdata%\*.* >
[2006/02/13 21:57:30 | 000,000,026 | RH-- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\AXEL.DAV
[2005/08/30 16:52:20 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\desktop.ini
< MD5 for: AFD.SYS >
[2004/08/10 00:00:00 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\system32\dllcache\afd.sys
[2004/08/10 00:00:00 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\system32\drivers\afd.sys
< MD5 for: ATAPI.SYS >
[2004/08/10 07:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/10 00:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys
[2004/08/04 09:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/04 09:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/10 00:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
< MD5 for: CRYPTSVC.DLL >
[2004/08/10 00:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- C:\WINDOWS\system32\cryptsvc.dll
[2004/08/10 00:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: DNSRSLVR.DLL >
[2004/08/10 00:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7379DE06FD196E396A00AA97B990C00D -- C:\WINDOWS\system32\dllcache\dnsrslvr.dll
[2004/08/10 00:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7379DE06FD196E396A00AA97B990C00D -- C:\WINDOWS\system32\dnsrslvr.dll
< MD5 for: ES.DLL >
[2005/07/26 07:39:45 | 000,243,200 | ---- | M] (Microsoft Corporation) MD5=34BBD9ACC1538818F2C878898C64E793 -- C:\WINDOWS\system32\dllcache\es.dll
[2005/07/26 07:39:45 | 000,243,200 | ---- | M] (Microsoft Corporation) MD5=34BBD9ACC1538818F2C878898C64E793 -- C:\WINDOWS\system32\es.dll
[2012/08/14 00:29:58 | 000,008,728 | ---- | M] () MD5=7AD37261A349BE597C2E4C58B093B63D -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.79\Locales\es.dll
[2005/07/26 07:20:28 | 000,243,200 | ---- | M] (Microsoft Corporation) MD5=95F5FEA4C6DE2C3F28784D0DCC8F0DD3 -- C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\es.dll
[2004/08/10 00:00:00 | 000,243,200 | ---- | M] (Microsoft Corporation) MD5=ACD36A2DD7D1E9D8A060AA651DC07E63 -- C:\WINDOWS\$NtUninstallKB902400$\es.dll
< MD5 for: EXPLORER.EXE >
[2004/08/10 00:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe
[2004/08/10 00:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe
[2008/04/29 11:42:08 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe
< MD5 for: IPNATHLP.DLL >
[2004/08/10 00:00:00 | 000,331,264 | ---- | M] (Microsoft Corporation) MD5=36CC8C01B5E50163037BEF56CB96DEFF -- C:\WINDOWS\system32\dllcache\ipnathlp.dll
[2004/08/10 00:00:00 | 000,331,264 | ---- | M] (Microsoft Corporation) MD5=36CC8C01B5E50163037BEF56CB96DEFF -- C:\WINDOWS\system32\ipnathlp.dll
< MD5 for: IPSEC.SYS >
[2004/08/10 00:00:00 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\system32\dllcache\ipsec.sys
[2004/08/10 00:00:00 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\system32\drivers\ipsec.sys
< MD5 for: NETBT.SYS >
[2004/08/10 00:00:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\system32\dllcache\netbt.sys
[2004/08/10 00:00:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\system32\drivers\netbt.sys
< MD5 for: NETMAN.DLL >
[2004/08/10 00:00:00 | 000,198,144 | ---- | M] (Microsoft Corporation) MD5=DAB9E6C7105D2EF49876FE92C524F565 -- C:\WINDOWS\system32\dllcache\netman.dll
[2004/08/10 00:00:00 | 000,198,144 | ---- | M] (Microsoft Corporation) MD5=DAB9E6C7105D2EF49876FE92C524F565 -- C:\WINDOWS\system32\netman.dll
< MD5 for: QMGR.DLL >
[2004/08/10 00:00:00 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\system32\dllcache\qmgr.dll
[2004/08/10 00:00:00 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\system32\qmgr.dll
< MD5 for: RPCSS.DLL >
[2004/08/10 00:00:00 | 000,395,776 | ---- | M] (Microsoft Corporation) MD5=5C83A4408604F737717AB96371201680 -- C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll
[2005/07/26 07:20:40 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=C369DF215D352B6F3A0B8C3469AA34F8 -- C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[2005/07/26 07:39:49 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=CE94A2BD25E3E9F4D46A7373FF455C6D -- C:\WINDOWS\system32\dllcache\rpcss.dll
[2005/07/26 07:39:49 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=CE94A2BD25E3E9F4D46A7373FF455C6D -- C:\WINDOWS\system32\rpcss.dll
< MD5 for: SERVICES.EXE >
[2004/08/10 00:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\system32\dllcache\services.exe
[2004/08/10 00:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\system32\services.exe
< MD5 for: SR.SYS >
[2004/08/10 00:00:00 | 000,073,472 | ---- | M] (Microsoft Corporation) MD5=E41B6D037D6CD08461470AF04500DC24 -- C:\WINDOWS\system32\dllcache\sr.sys
[2004/08/10 00:00:00 | 000,073,472 | ---- | M] (Microsoft Corporation) MD5=E41B6D037D6CD08461470AF04500DC24 -- C:\WINDOWS\system32\drivers\sr.sys
< MD5 for: SRSVC.DLL >
[2004/08/10 00:00:00 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\system32\dllcache\srsvc.dll
[2004/08/10 00:00:00 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\system32\srsvc.dll
< MD5 for: SVCHOST.EXE >
[2004/08/10 00:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004/08/10 00:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\svchost.exe
[2008/07/01 09:17:12 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Program Files\CheckPoint\ZAForceField\Heuristics\svchost.exe
< MD5 for: TCPIP.SYS >
[2005/03/14 03:55:08 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=0E66B538096A6529D1AC66E78EB0D5C8 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2005/03/14 03:55:08 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=0E66B538096A6529D1AC66E78EB0D5C8 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2005/03/14 04:17:17 | 000,359,936 | ---- | M] (Microsoft Corporation) MD5=6129E70F3D2F1E60860C930EBEAF92C2 -- C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[2004/08/10 00:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
< MD5 for: USERINIT.EXE >
[2004/08/10 00:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004/08/10 00:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe
< MD5 for: VOLSNAP.SYS >
[2004/08/10 00:00:00 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\dllcache\volsnap.sys
[2004/08/10 00:00:00 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\drivers\volsnap.sys
< MD5 for: WINLOGON.EXE >
[2004/08/10 00:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/10 00:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe
[2008/07/01 09:17:12 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe
< MD5 for: WMISVC.DLL >
[2004/08/10 00:00:00 | 000,144,896 | ---- | M] (Microsoft Corporation) MD5=F399242A80C4066FD155EFA4CF96658E -- C:\WINDOWS\system32\dllcache\wmisvc.dll
[2004/08/10 00:00:00 | 000,144,896 | ---- | M] (Microsoft Corporation) MD5=F399242A80C4066FD155EFA4CF96658E -- C:\WINDOWS\system32\wbem\wmisvc.dll
< MD5 for: WSCSVC.DLL >
[2004/08/10 00:00:00 | 000,081,408 | ---- | M] (Microsoft Corporation) MD5=4D59DAA66C60858CDF4F67A900F42D4A -- C:\WINDOWS\system32\dllcache\wscsvc.dll
[2004/08/10 00:00:00 | 000,081,408 | ---- | M] (Microsoft Corporation) MD5=4D59DAA66C60858CDF4F67A900F42D4A -- C:\WINDOWS\system32\wscsvc.dll
< MD5 for: WUAUSERV.DLL >
[2004/08/10 00:00:00 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=13D72740963CBA12D9FF76A7F218BCD8 -- C:\WINDOWS\system32\dllcache\wuauserv.dll
[2004/08/10 00:00:00 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=13D72740963CBA12D9FF76A7F218BCD8 -- C:\WINDOWS\system32\wuauserv.dll
< End of report >