========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.startup.homepage: "
www.google.com"FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: avg@igeared:4.504.019.002
FF - prefs.js..extensions.enabledItems: {2104C0F5-952D-443c-AFCD-8F892F991F55}:2.0.0.0
FF - prefs.js..extensions.enabledItems: {fa8cb1bd-1442-439c-8225-b8b16983d9b7}:1.0
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems:
toolbar@ask.com:3.6.6.117
FF - prefs.js..extensions.enabledItems: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd}:2.6.0.15
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.227.0
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.23
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/07/21 08:43:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/06/05 21:59:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2010/08/12 06:41:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Flock 2.5.6\extensions\\Components: C:\Program Files\Flock\components [2010/07/30 19:07:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Flock 2.5.6\extensions\\Plugins: C:\Program Files\Flock\plugins [2010/07/29 08:05:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components [2010/07/30 19:07:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins [2010/07/29 08:05:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/29 08:05:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/29 08:05:58 | 000,000,000 | ---D | M]
[2010/04/12 17:58:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/04/12 17:58:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2010/08/30 16:01:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions
[2010/02/22 16:05:57 | 000,000,000 | ---D | M] (Charter Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{2104C0F5-952D-443c-AFCD-8F892F991F55}
[2009/04/12 15:59:10 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/07/08 06:14:10 | 000,000,000 | ---D | M] (ZoneAlarm Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}
[2009/11/08 13:00:33 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/04/12 15:28:18 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/08/25 00:22:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/02/22 16:05:56 | 000,000,000 | ---D | M] (Charter Update) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\{fa8cb1bd-1442-439c-8225-b8b16983d9b7}
[2009/04/12 15:28:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\morningCoffee@shaneliesegang
[2010/06/05 22:01:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\extensions\toolbar@ask.com
[2010/06/08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5hx03zg8.default\searchplugins\conduit.xml
[2010/08/30 16:11:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2002/09/03 11:34:19 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZon1.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZon1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZon1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: DirectAnimation Java Classes
file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java
file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.177.176.38 97.81.22.195 24.178.162.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.189,93.188.166.189
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/11 22:04:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpFolder: C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Corel Registration.lnk - C:\Program Files\Corel\Graphics9\Register\Remind32.exe - (IntelliQuest Communications, Inc.)
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg:
Lexmark 1200 Series - hkey= - key= - C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
MsConfig - StartUpReg:
LogitechQuickCamRibbon - hkey= - key= - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
MsConfig - StartUpReg:
msnmsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: vsmon - C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (77982179300212736)
========== Files/Folders - Created Within 30 Days ========== [2010/08/31 08:05:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/31 08:05:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/31 08:05:03 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/31 08:05:00 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/31 08:03:28 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Owner\Desktop\mbam-setup-1.46.exe
[2010/08/31 07:36:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/31 07:23:02 | 036,317,320 | ---- | C] (PC Tools ) -- C:\Documents and Settings\Owner\Desktop\7.0.0.543e-sdsetup-Revenue(207).exe
[2010/08/30 17:48:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\from desktop
[2010/08/30 16:42:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\avenger
[2010/08/30 16:41:43 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.com
[2010/08/30 16:16:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\booths
[2010/08/30 15:48:45 | 000,292,352 | ---- | C] (iS3, Inc.) -- C:\Documents and Settings\Owner\Desktop\STOPzilla_Setup.exe
[2010/08/30 14:19:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\eflybdhl
[2010/08/25 21:53:52 | 000,017,744 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/08/25 21:53:49 | 000,165,456 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010/08/25 21:53:45 | 000,023,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/08/25 21:53:40 | 000,046,672 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/08/25 21:53:35 | 000,100,176 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/08/25 21:53:35 | 000,094,544 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010/08/25 21:53:35 | 000,028,880 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/08/25 21:52:57 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\WINDOWS\avastSS.scr
[2010/08/25 21:52:54 | 000,165,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010/08/25 21:51:38 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/08/25 21:51:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/08/25 21:13:40 | 001,870,496 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Owner\Desktop\HousecallLauncher(2).exe
[2010/08/25 00:54:47 | 000,532,480 | ---- | C] (Trend Micro Incorporated) -- C:\Documents and Settings\Owner\Desktop\cwshredder.exe
[2010/08/25 00:23:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\QuickScan
[2010/08/24 22:51:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\ohjslqgvy
[2010/08/22 11:58:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\railroad info
[2010/08/21 17:30:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\last-soundtrack_brown-bear-funk
[2010/08/21 17:30:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\divide-by-zero_two-turtle-doves
[2010/08/21 17:30:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\anke-art_acki-preschool
[2010/08/13 08:51:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\work
[2010/08/10 22:10:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\Walmart MP3 Music Downloads
[2010/08/10 22:09:38 | 000,977,304 | ---- | C] (Walmart.com) -- C:\Documents and Settings\Owner\My Documents\walmart-downloadManager-1.6.4.4.exe
[2010/08/03 20:35:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\Yahoo!
[2010/08/03 20:33:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2010/02/22 16:00:10 | 000,015,429 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\Sacm2A.sys
[2002/04/11 02:41:00 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/08/31 20:01:08 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/08/31 19:44:21 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\rkill.com
[2010/08/31 19:43:00 | 000,000,282 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/08/31 19:13:00 | 000,000,282 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/08/31 19:02:05 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1229272821-725345543-1003UA.job
[2010/08/31 18:04:09 | 064,139,718 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/31 08:50:57 | 000,000,306 | -HS- | M] () -- C:\WINDOWS\tasks\kmoh.job
[2010/08/31 08:50:57 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/31 08:50:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/31 08:44:02 | 000,971,782 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\avenger.zip
[2010/08/31 08:34:21 | 004,980,736 | -H-- | M] () -- C:\Documents and Settings\Owner\NTUSER.DAT
[2010/08/31 08:33:40 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Owner\ntuser.ini
[2010/08/31 08:05:29 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/31 08:03:26 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Owner\Desktop\mbam-setup-1.46.exe
[2010/08/31 07:34:05 | 036,317,320 | ---- | M] (PC Tools ) -- C:\Documents and Settings\Owner\Desktop\7.0.0.543e-sdsetup-Revenue(207).exe
[2010/08/30 20:02:32 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1229272821-725345543-1003Core.job
[2010/08/30 17:04:04 | 001,786,428 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2010/08/30 16:41:44 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.com
[2010/08/30 16:10:26 | 001,872,472 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\SmitfraudFix.exe
[2010/08/30 15:48:43 | 000,292,352 | ---- | M] (iS3, Inc.) -- C:\Documents and Settings\Owner\Desktop\STOPzilla_Setup.exe
[2010/08/30 11:38:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/29 17:30:43 | 000,002,501 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2010/08/29 17:28:34 | 000,104,362 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\spoon1_do1.jpg
[2010/08/29 14:12:14 | 000,081,983 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\img_0862.jpg
[2010/08/29 14:09:39 | 002,740,930 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\showsigns.cdr
[2010/08/29 14:08:40 | 002,740,906 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Backup_of_showsigns.cdr
[2010/08/26 17:14:12 | 000,055,081 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\dragon_01_clip.gif
[2010/08/26 17:12:39 | 000,050,239 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\dragon2.psp
[2010/08/26 17:08:43 | 000,567,167 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\dragon 1.psp
[2010/08/25 21:53:54 | 000,001,700 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/08/25 21:53:36 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/08/25 21:42:11 | 054,835,272 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\setup_av_free.exe
[2010/08/25 21:13:26 | 001,870,496 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Owner\Desktop\HousecallLauncher(2).exe
[2010/08/25 20:44:59 | 002,205,456 | -H-- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/08/25 01:08:23 | 000,532,480 | ---- | M] (Trend Micro Incorporated) -- C:\Documents and Settings\Owner\Desktop\cwshredder.exe
[2010/08/24 23:32:50 | 000,055,808 | RHS- | M] () -- C:\WINDOWS\System32\quartzc.dll
[2010/08/24 20:20:00 | 000,010,457 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Image1.jpg
[2010/08/24 20:19:39 | 000,019,502 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Image1.psp
[2010/08/23 18:24:58 | 000,022,046 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Watermelon-Daisies-Glass-lo-res.jpg
[2010/08/22 08:37:07 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/08/22 08:32:18 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/22 08:32:08 | 000,000,546 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to HousecallLauncher.exe.lnk
[2010/08/22 08:27:04 | 000,267,008 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/21 20:19:12 | 000,100,349 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Lorrainefinal002.jpg
[2010/08/21 17:19:11 | 000,094,816 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\last-soundtrack_brown-bear-funk.zip
[2010/08/21 17:18:17 | 000,020,164 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\anke-art_acki-preschool.zip
[2010/08/21 17:17:49 | 000,019,751 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\divide-by-zero_two-turtle-doves.zip
[2010/08/15 17:44:28 | 001,017,702 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Arab Football ad1.rtf
[2010/08/15 17:40:16 | 000,056,320 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Arab Football ad1.doc
[2010/08/15 14:50:56 | 000,005,004 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\geocaching(2).loc
[2010/08/15 14:49:36 | 000,005,337 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\geocaching.loc
[2010/08/13 09:08:34 | 004,195,367 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\FileZilla_3.3.4_win32-setup.exe
[2010/08/13 08:46:33 | 000,002,467 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft FrontPage.lnk
[2010/08/10 23:36:02 | 009,142,464 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\09-Mary,_Did_You_Know-Mary_Did_You_Know-Mark_Lowry.mp3
[2010/08/10 23:34:00 | 007,466,352 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\KRogers.mp3
[2010/08/10 22:09:41 | 000,977,304 | ---- | M] (Walmart.com) -- C:\Documents and Settings\Owner\My Documents\walmart-downloadManager-1.6.4.4.exe
[2010/08/04 08:38:35 | 000,039,936 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Class_Reunion.doc
[2010/08/03 20:29:54 | 000,000,818 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/08/03 09:44:39 | 000,002,031 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\westie.gif
[2010/08/03 09:14:11 | 000,630,628 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\dawnsparksart.pdf
[2010/08/03 09:13:52 | 006,333,534 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\art.cdr
[2010/08/03 09:12:31 | 006,333,350 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Backup_of_art.cdr
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/31 19:44:22 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\rkill.com
[2010/08/31 08:05:29 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/30 16:40:17 | 000,971,782 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\avenger.zip
[2010/08/30 16:10:21 | 001,872,472 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\SmitfraudFix.exe
[2010/08/29 17:28:32 | 000,104,362 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\spoon1_do1.jpg
[2010/08/29 14:12:09 | 000,081,983 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\img_0862.jpg
[2010/08/29 13:55:59 | 002,740,906 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Backup_of_showsigns.cdr
[2010/08/29 13:36:55 | 002,740,930 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\showsigns.cdr
[2010/08/26 17:14:11 | 000,055,081 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\dragon_01_clip.gif
[2010/08/26 17:12:39 | 000,050,239 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\dragon2.psp
[2010/08/26 17:08:42 | 000,567,167 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\dragon 1.psp
[2010/08/25 21:53:54 | 000,001,700 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/08/25 21:29:04 | 054,835,272 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\setup_av_free.exe
[2010/08/25 20:33:58 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2010/08/24 23:32:50 | 000,055,808 | RHS- | C] () -- C:\WINDOWS\System32\quartzc.dll
[2010/08/24 23:32:50 | 000,000,306 | -HS- | C] () -- C:\WINDOWS\tasks\kmoh.job
[2010/08/24 23:30:55 | 000,000,282 | -H-- | C] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/08/24 23:30:39 | 000,000,282 | -H-- | C] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/08/24 20:20:00 | 000,010,457 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Image1.jpg
[2010/08/24 20:19:38 | 000,019,502 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Image1.psp
[2010/08/23 18:24:57 | 000,022,046 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Watermelon-Daisies-Glass-lo-res.jpg
[2010/08/22 08:37:07 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/08/22 08:32:18 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/22 08:32:08 | 000,000,546 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to HousecallLauncher.exe.lnk
[2010/08/21 20:19:09 | 000,100,349 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Lorrainefinal002.jpg
[2010/08/21 17:19:11 | 000,094,816 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\last-soundtrack_brown-bear-funk.zip
[2010/08/21 17:18:17 | 000,020,164 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\anke-art_acki-preschool.zip
[2010/08/21 17:17:47 | 000,019,751 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\divide-by-zero_two-turtle-doves.zip
[2010/08/15 17:44:28 | 001,017,702 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Arab Football ad1.rtf
[2010/08/15 17:40:15 | 000,056,320 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Arab Football ad1.doc
[2010/08/15 14:50:56 | 000,005,004 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\geocaching(2).loc
[2010/08/15 14:49:35 | 000,005,337 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\geocaching.loc
[2010/08/13 09:08:00 | 004,195,367 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\FileZilla_3.3.4_win32-setup.exe
[2010/08/10 23:34:32 | 009,142,464 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\09-Mary,_Did_You_Know-Mary_Did_You_Know-Mark_Lowry.mp3
[2010/08/10 23:33:42 | 007,466,352 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\KRogers.mp3
[2010/08/04 08:38:35 | 000,039,936 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Class_Reunion.doc
[2010/08/03 20:29:54 | 000,000,818 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/08/03 09:44:35 | 000,002,031 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\westie.gif
[2010/08/03 09:14:08 | 000,630,628 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\dawnsparksart.pdf
[2010/08/03 09:13:48 | 006,333,350 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Backup_of_art.cdr
[2010/08/03 09:12:28 | 006,333,534 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\art.cdr
[2010/05/04 07:12:02 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/04/12 15:30:43 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\housecall.guid.cache
[2010/02/22 16:00:10 | 000,053,693 | R--- | C] () -- C:\WINDOWS\UNDPX2A.sys
[2009/11/20 09:55:32 | 001,786,428 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2009/07/19 10:42:03 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/06 07:27:05 | 000,066,482 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/06/30 23:33:58 | 000,000,073 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/05/20 08:09:11 | 000,000,184 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2009/05/20 08:09:09 | 000,000,514 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2009/05/20 08:08:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxczvs.dll
[2009/05/20 08:07:57 | 000,000,270 | ---- | C] () -- C:\WINDOWS\System32\lxczcoin.ini
[2009/04/14 10:41:16 | 000,000,052 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2009/04/12 16:48:42 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
[2009/04/12 16:44:17 | 000,027,648 | ---- | C] () -- C:\WINDOWS\PFPICK.DLL
[2009/04/12 16:28:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/07/26 08:25:02 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2003/07/08 15:41:48 | 000,047,616 | ---- | C] () -- C:\WINDOWS\System32\P16X.dll
[1995/10/27 14:06:09 | 000,000,127 | ---- | C] () -- C:\WINDOWS\kpcms.ini
[1995/10/24 13:28:53 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
========== Custom Scans ========== < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2010/08/24 23:32:50 | 000,055,808 | RHS- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\quartzc.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >[2010/08/31 08:50:57 | 000,000,306 | -HS- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\Tasks\kmoh.job
< %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2009/04/11 14:52:35 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/04/11 14:52:35 | 000,602,112 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/04/11 14:52:35 | 000,389,120 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >[2002/09/03 11:27:19 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2002/09/03 11:29:31 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2002/09/03 11:34:10 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2002/09/03 11:39:08 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2002/09/03 11:39:11 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2002/09/03 11:49:59 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2002/09/03 11:49:59 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2002/09/03 11:50:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2002/09/03 11:50:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2002/09/03 11:50:01 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/04 00:45:10 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/04 00:45:16 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/04 00:45:12 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/04 00:45:16 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/04 00:45:14 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2010/05/13 10:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\vsdatant.sys
[2008/04/13 13:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2009/08/14 08:21:25 | 001,850,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >[2008/04/13 19:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/13 19:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/13 19:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/13 19:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/13 19:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/13 19:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/13 19:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/13 19:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/13 19:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/13 19:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/13 19:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/13 19:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/13 19:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/13 19:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/13 19:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
< %systemroot%\system32\drivers\*.ini > < %systemroot%\system32\drivers\*.exe > < %SYSTEMDRIVE%\*.* >[2010/08/25 20:46:27 | 000,000,220 | ---- | M] () -- C:\aaw7boot.log
[2009/04/11 22:04:19 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/10/05 21:29:14 | 000,444,334 | ---- | M] () -- C:\Backup_of_giggle.cdr
[2009/04/22 23:08:37 | 000,022,882 | ---- | M] () -- C:\Backup_of_map.cdr
[2010/04/05 07:13:26 | 000,000,304 | RHS- | M] () -- C:\boot.ini
[2009/04/11 22:04:19 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/10/05 21:34:53 | 000,444,522 | ---- | M] () -- C:\giggle.cdr
[2010/05/11 18:35:22 | 000,021,955 | ---- | M] () -- C:\herring.pdf
[2009/04/12 11:58:06 | 000,000,281 | ---- | M] () -- C:\INSTALL.LOG
[2009/04/11 22:04:19 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/04/22 23:09:32 | 000,022,882 | ---- | M] () -- C:\map.cdr
[2009/04/11 22:04:19 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/10/19 18:18:42 | 000,050,299 | ---- | M] () -- C:\newcardmaybe.pdf
[2009/04/12 10:42:11 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/12/25 17:55:07 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/08/31 08:50:10 | 2013,265,920 | -HS- | M] () -- C:\pagefile.sys
[2010/08/31 19:55:02 | 000,000,369 | ---- | M] () -- C:\rkill.log
[2009/05/20 08:20:33 | 000,000,168 | ---- | M] () -- C:\setupfax.log
[2009/11/04 10:15:00 | 000,103,648 | ---- | M] () -- C:\sign.pdf
< %PROGRAMFILES%\*. >[2009/05/20 08:20:55 | 000,000,000 | ---D | M] -- C:\Program Files\ABBYY FineReader 5.0 Sprint
[2009/05/20 08:20:42 | 000,000,000 | ---D | M] -- C:\Program Files\ABBYY FineReader 6.0
[2010/05/04 07:11:51 | 000,000,000 | ---D | M] -- C:\Program Files\Acro Software
[2010/05/17 17:43:21 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010/08/25 21:51:38 | 000,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2009/04/12 15:56:53 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2009/09/15 20:06:37 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2010/06/05 22:02:07 | 000,000,000 | ---D | M] -- C:\Program Files\Ask.com
[2009/11/14 23:34:52 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2010/07/29 07:45:56 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2009/04/12 00:55:29 | 000,000,000 | ---D | M] -- C:\Program Files\Broadcom
[2010/02/22 16:06:36 | 000,000,000 | ---D | M] -- C:\Program Files\chartertoolbar
[2010/07/08 06:13:33 | 000,000,000 | ---D | M] -- C:\Program Files\CheckPoint
[2010/08/31 08:35:28 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/04/11 22:01:55 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010/07/08 06:13:50 | 000,000,000 | ---D | M] -- C:\Program Files\Conduit
[2009/04/12 16:48:47 | 000,000,000 | ---D | M] -- C:\Program Files\Corel
[2009/05/20 08:20:17 | 000,000,000 | ---D | M] -- C:\Program Files\FaxTools
[2010/03/02 07:21:15 | 000,000,000 | ---D | M] -- C:\Program Files\FileZilla FTP Client
[2010/08/31 17:28:01 | 000,000,000 | ---D | M] -- C:\Program Files\Flock
[2010/05/04 07:10:11 | 000,000,000 | ---D | M] -- C:\Program Files\GPLGS
[2009/04/20 19:19:38 | 000,000,000 | ---D | M] -- C:\Program Files\Hasbro Interactive
[2009/09/15 20:06:35 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2010/01/25 00:04:14 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/07/29 08:13:13 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/05/09 01:03:34 | 000,000,000 | ---D | M] -- C:\Program Files\IrfanView
[2010/07/29 08:14:34 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2009/04/12 15:54:54 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2009/04/12 13:32:01 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/05/20 08:08:21 | 000,000,000 | ---D | M] -- C:\Program Files\Lexmark 1200 Series
[2009/07/06 07:23:30 | 000,000,000 | ---D | M] -- C:\Program Files\Logitech
[2010/08/31 08:05:31 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/12/25 18:09:07 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/04/12 19:00:27 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2009/04/13 10:03:20 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2009/04/11 22:04:28 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2010/03/10 19:31:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009/04/12 16:25:11 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2010/03/28 03:52:41 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/08/30 16:01:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/03/10 19:31:04 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2009/04/11 22:01:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2009/04/11 22:01:17 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/12/25 17:59:20 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2009/04/11 23:39:59 | 000,000,000 | ---D | M] -- C:\Program Files\Netscape ISP Dialer
[2010/06/16 20:49:35 | 000,000,000 | ---D | M] -- C:\Program Files\NOS
[2009/04/11 22:01:26 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/12/25 18:16:30 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/08/28 18:17:43 | 000,000,000 | ---D | M] -- C:\Program Files\Paint Shop Pro 5
[2010/07/29 08:05:41 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/04/12 15:31:39 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2009/04/12 13:42:03 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2009/04/12 16:17:23 | 000,000,000 | ---D | M] -- C:\Program Files\SuperOthello
[2009/04/11 22:45:00 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/04/12 19:00:22 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2009/04/12 19:00:10 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2010/03/01 16:46:45 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2010/03/01 16:46:42 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/12/25 17:59:08 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/04/11 22:01:26 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2009/04/11 22:04:28 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/08/03 20:34:20 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2009/07/08 18:16:46 | 000,000,000 | ---D | M] -- C:\Program Files\ZC2.10
[2009/04/12 12:29:22 | 000,000,000 | ---D | M] -- C:\Program Files\Zone Labs
[2010/08/24 22:39:09 | 000,000,000 | ---D | M] -- C:\Program Files\ZoneAlarm
< %appdata%\*.* >[2009/04/11 14:53:53 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\desktop.ini
[2010/01/21 18:40:11 | 000,064,304 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
< MD5 for: AGP440.SYS >[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >[2002/09/03 12:04:09 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 00:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: DISK.SYS >[2002/09/03 12:04:09 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:disk.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:disk.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/04 00:59:56 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 13:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 13:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 02:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 02:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2004/08/04 02:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >[2002/09/03 12:04:09 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:usbstor.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2004/08/04 03:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:usbstor.sys
[2009/12/25 17:42:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 01:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 13:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 13:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-04-13 22:15:21
========== Alternate Data Streams ========== @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >