NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: BITS - File not found
========== Files/Folders - Created Within 30 Days ==========
[2012/10/16 18:13:38 | 000,000,000 | ---D | C] -- C:\FRST
[2012/10/16 16:45:22 | 127,231,689 | ---- | C] (Igor Pavlov) -- C:\Documents and Settings\Owner\Desktop\OTLPENet.exe
[2012/10/16 02:59:32 | 000,177,496 | ---- | C] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\07292517.sys
[2012/10/16 02:59:00 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/10/15 19:13:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/15 04:26:58 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/10/14 20:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/10/14 17:31:07 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/10/14 16:13:50 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/10/14 16:09:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2012/10/14 15:55:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\DriverCure
[2012/10/14 15:54:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SpeedyPC Software
[2012/10/14 04:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2012/10/14 04:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/10/14 04:16:54 | 003,255,248 | ---- | C] (Javacool Software LLC ) -- C:\Documents and Settings\Owner\Desktop\spywareblastersetup46.exe
[2012/10/13 11:00:26 | 000,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\Favorites
[2012/10/13 09:05:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/10/13 09:05:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/10/13 07:51:10 | 000,386,560 | ---- | C] (COMODO inc.) -- C:\Documents and Settings\Owner\My Documents\7af3996f.exe
[2012/10/09 05:04:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2012/10/08 01:49:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\2csg+xl Turbo Lister2
[2012/10/06 00:44:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\sm 7-24 Turbo Lister2
[2012/10/02 01:36:32 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd101b.dll
[2012/10/02 01:36:32 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101b.dll
[2012/10/02 01:36:22 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd106.dll
[2012/10/02 01:36:22 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd106.dll
[2012/09/28 18:19:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Desktop
[2012/09/24 04:23:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2012/09/24 04:22:11 | 000,070,768 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTBD.sys
[2012/09/24 04:22:10 | 002,267,096 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
[2012/09/24 04:22:10 | 000,149,464 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
[2012/09/24 04:22:09 | 001,689,560 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
[2012/09/24 04:21:17 | 000,254,944 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/09/24 04:21:08 | 000,017,880 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctBTFix.sys
[2012/09/24 04:21:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/09/24 04:20:55 | 000,125,920 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplfw.sys
[2012/09/24 04:20:55 | 000,091,648 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.sys
[2012/09/24 04:20:55 | 000,057,536 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis.sys
[2012/09/24 04:20:55 | 000,032,936 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis-DNS.sys
[2012/09/24 04:20:51 | 000,070,568 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2012/09/24 04:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2012/09/24 04:18:59 | 000,909,728 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctEFA.sys
[2012/09/24 04:18:59 | 000,342,168 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctDS.sys
[2012/09/24 04:18:55 | 000,383,368 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2012/09/24 04:18:55 | 000,162,584 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/09/21 04:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\File Recover
[2012/09/21 04:12:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Product_FR
[2012/09/21 03:34:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Start Menu
[2012/09/21 01:47:35 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2012/09/21 01:47:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Start Menu\Programs\Revo Uninstaller
[2012/09/21 01:46:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Downloads
[2012/09/20 15:29:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP
========== Files - Modified Within 30 Days ==========
[2012/10/17 20:25:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/17 20:14:29 | 000,004,452 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/10/17 14:30:58 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\rd4cdpl7.exe
[2012/10/17 05:00:00 | 000,000,314 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2012/10/16 16:45:28 | 127,231,689 | ---- | M] (Igor Pavlov) -- C:\Documents and Settings\Owner\Desktop\OTLPENet.exe
[2012/10/16 15:26:51 | 000,000,049 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/10/16 05:47:55 | 000,000,211 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\java.com Java + You.url
[2012/10/16 03:18:49 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/10/16 02:59:32 | 000,177,496 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\07292517.sys
[2012/10/15 21:17:09 | 000,000,237 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\CSG Pay.url
[2012/10/15 19:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/15 19:13:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2012/10/15 13:00:49 | 000,004,091 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Restoring the registry in XP - CNET Computer newbies Forums.url
[2012/10/15 12:44:36 | 000,000,217 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to Windows Firewall.lnk
[2012/10/15 09:00:00 | 000,000,348 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2012/10/15 04:27:21 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/14 15:01:53 | 000,000,378 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\My eBay Watch List.url
[2012/10/14 05:09:01 | 000,444,321 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/10/14 04:16:56 | 003,255,248 | ---- | M] (Javacool Software LLC ) -- C:\Documents and Settings\Owner\Desktop\spywareblastersetup46.exe
[2012/10/13 07:57:11 | 083,023,306 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\87e2d931.pad
[2012/10/13 07:51:10 | 000,386,560 | ---- | M] (COMODO inc.) -- C:\Documents and Settings\Owner\My Documents\7af3996f.exe
[2012/10/12 07:13:04 | 000,003,510 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2012/10/12 04:25:19 | 000,003,781 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shop Verizon Deals & Compare TV, Internet, Phone Verizon.url
[2012/10/12 04:07:07 | 000,001,366 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Cablevision Optimum Triple Play for $70 or internet+io preferred for $76 YMMV - Slickdeals.net.url
[2012/10/11 00:58:22 | 000,001,677 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Woodfield 61288 Set of 2 Woodfield Cat Andirons with Glass Eyes.url
[2012/10/09 07:39:39 | 000,000,898 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\ctfmon.lnk
[2012/10/09 05:44:18 | 083,023,306 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\emorhc.pad
[2012/10/09 05:04:44 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/09 05:04:43 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/09 04:01:15 | 000,000,318 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\eBayISAPI.dllViewItemDescV4&item=140859960369&t=0&tid=10&category=29223&seller=2011purpleleaf&excSoj=1&rptdesc=1&excTrk=1&tto=1000.url
[2012/10/08 02:50:51 | 000,044,487 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\sscaredycat-2012-10-08-02-50-27.tlb
[2012/10/08 02:50:51 | 000,000,020 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\sscaredycat-2012-10-08-02-50-27.imb
[2012/10/04 20:16:49 | 000,000,416 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\spider.sav
[2012/10/02 01:09:40 | 000,000,204 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Bullet Stash Key Chain BuySmrt.com.url
[2012/10/01 22:26:07 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/01 03:51:04 | 000,002,016 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Why does search results say 157 but only shows 4 results Community Help Boards eBay Discussion Boards.url
[2012/09/24 04:43:24 | 000,601,593 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/09/24 04:21:09 | 000,001,815 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PC Tools Internet Security.lnk
[2012/09/24 04:21:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/09/24 03:53:09 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20121014-050901.backup
[2012/09/24 03:19:00 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120924-035309.backup
[2012/09/24 02:29:38 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/09/23 03:43:19 | 000,000,462 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[2012/09/23 03:43:19 | 000,000,079 | ---- | M] () -- C:\WINDOWS\BRPP2KA.INI
[2012/09/21 14:18:09 | 000,000,331 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Teachers Federal Credit Union - The Educated Choice.url
[2012/09/21 12:55:13 | 000,000,699 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Contact Us E-Mail Form.url
[2012/09/21 04:15:19 | 000,000,915 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Tools File Recover.lnk
[2012/09/21 02:22:56 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120924-031900.backup
[2012/09/21 01:57:43 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120921-022256.backup
[2012/09/21 01:53:18 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120921-015743.backup
[2012/09/20 15:13:05 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/09/20 15:03:33 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120921-015318.backup
[2012/09/20 13:52:51 | 000,444,321 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120920-150333.backup
========== Files Created - No Company Name ==========
[2012/10/17 14:30:57 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\rd4cdpl7.exe
[2012/10/16 05:47:55 | 000,000,211 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\java.com Java + You.url
[2012/10/15 13:00:48 | 000,004,091 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Restoring the registry in XP - CNET Computer newbies Forums.url
[2012/10/15 12:44:36 | 000,000,217 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to Windows Firewall.lnk
[2012/10/15 04:27:21 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/13 09:13:59 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/10/13 07:52:10 | 083,023,306 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\87e2d931.pad
[2012/10/12 04:25:19 | 000,003,781 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shop Verizon Deals & Compare TV, Internet, Phone Verizon.url
[2012/10/12 04:07:07 | 000,001,366 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Cablevision Optimum Triple Play for $70 or internet+io preferred for $76 YMMV - Slickdeals.net.url
[2012/10/11 00:58:22 | 000,001,677 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Woodfield 61288 Set of 2 Woodfield Cat Andirons with Glass Eyes.url
[2012/10/09 07:39:32 | 000,000,898 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ctfmon.lnk
[2012/10/09 05:28:36 | 083,023,306 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\emorhc.pad
[2012/10/09 04:01:15 | 000,000,318 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\eBayISAPI.dllViewItemDescV4&item=140859960369&t=0&tid=10&category=29223&seller=2011purpleleaf&excSoj=1&rptdesc=1&excTrk=1&tto=1000.url
[2012/10/08 02:50:51 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\sscaredycat-2012-10-08-02-50-27.imb
[2012/10/08 02:50:41 | 000,044,487 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\sscaredycat-2012-10-08-02-50-27.tlb
[2012/10/02 01:09:40 | 000,000,204 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Bullet Stash Key Chain BuySmrt.com.url
[2012/10/01 03:51:04 | 000,002,016 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Why does search results say 157 but only shows 4 results Community Help Boards eBay Discussion Boards.url
[2012/09/24 04:22:10 | 000,767,960 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2012/09/24 04:22:10 | 000,003,488 | ---- | C] () -- C:\WINDOWS\UDB.zip
[2012/09/24 04:22:10 | 000,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
[2012/09/24 04:22:10 | 000,000,879 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
[2012/09/24 04:22:10 | 000,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
[2012/09/24 04:21:09 | 000,001,815 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PC Tools Internet Security.lnk
[2012/09/21 12:55:13 | 000,000,699 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Contact Us E-Mail Form.url
[2012/09/21 04:15:19 | 000,000,915 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Tools File Recover.lnk
[2012/02/15 20:02:28 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/12 09:53:34 | 000,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2012/01/12 09:53:34 | 000,000,040 | ---- | C] () -- C:\WINDOWS\opt_2460.ini
[2012/01/06 16:55:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2012/01/06 16:44:43 | 000,000,234 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2012/01/06 16:44:43 | 000,000,092 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2012/01/06 16:44:43 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\BRIDF04A.dat
[2012/01/06 16:43:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brdfxspd.dat
[2012/01/06 09:49:33 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2011/12/31 15:37:59 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\WebpageIcons.db
[2011/12/31 10:55:37 | 000,029,904 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/12/15 02:10:53 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/12/08 16:45:44 | 000,000,462 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2011/12/08 16:45:44 | 000,000,079 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2011/12/01 15:57:21 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/01 15:57:21 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/11/29 23:20:10 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2011/11/28 07:47:53 | 000,003,510 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2011/11/27 02:06:53 | 000,149,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\ar5523.bin
[2011/11/27 02:06:53 | 000,149,392 | ---- | C] () -- C:\WINDOWS\System32\ar5523.bin
[2011/11/27 02:06:51 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\acs.exe
[2011/11/27 02:06:46 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2011/11/27 01:31:42 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2011/11/27 01:29:43 | 000,000,029 | ---- | C] () -- C:\WINDOWS\wwwbatch.ini
[2011/11/27 01:18:31 | 000,471,300 | ---- | C] () -- C:\WINDOWS\wallpe.exe
[2011/11/27 01:15:44 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/11/27 01:02:53 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\SYSDRV.DAT
[2008/08/11 05:02:00 | 000,047,616 | ---- | C] () -- C:\WINDOWS\System32\zmghpaso.dll
[2008/08/11 05:01:58 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\zmghpaudcp.exe
[2004/08/27 06:50:59 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/08/27 05:54:47 | 000,516,096 | ---- | C] () -- C:\WINDOWS\System32\HotlineClient.exe
[2004/08/26 14:07:50 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/26 14:01:37 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/26 12:12:43 | 000,001,086 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/08/26 12:12:43 | 000,000,490 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2004/08/26 12:12:13 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/26 12:12:10 | 000,445,924 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/26 12:12:10 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/26 12:12:10 | 000,073,524 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/26 12:12:10 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/26 12:12:08 | 000,005,151 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/26 12:12:07 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/26 12:12:05 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/26 12:12:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/26 12:11:59 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/26 12:11:54 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/26 12:11:46 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/26 06:54:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/26 06:54:01 | 000,165,912 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2011/11/27 01:21:50 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
[2011/11/27 01:21:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
[2012/03/27 16:34:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Spam Monitor
[2012/09/21 20:23:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\.minecraft
[2012/01/21 12:49:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Ableton
[2012/10/14 15:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DriverCure
[2012/04/04 07:48:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2012/01/04 08:39:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ICAClient
[2012/03/16 05:53:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\IObit
[2012/03/29 05:04:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Oracle
[2012/03/27 02:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PCTools
[2012/09/21 04:12:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Product_FR
[2011/11/27 01:21:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SampleView
[2012/09/24 04:23:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2012/10/14 15:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SpeedyPC Software
[2011/11/28 07:47:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
[2012/03/27 01:56:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\TestApp
[2012/01/21 12:49:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ableton
[2011/11/28 07:22:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/11/27 00:10:01 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/03/27 01:34:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/10/17 20:25:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/27 01:16:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/12/31 10:50:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
========== Purity Check ==========
========== Custom Scans ==========
< DRIVES >
< SHOWHIDDEN >
< CreateRestorePoint >
Invalid Environment Variable: %AppData%\Roaming\Mozilla\Firefox\Profiles\*.default\extensions\
Invalid Environment Variable: %AppData%\Local\
< %systemroot%\system32\sysprep >
< *.xpi /md5 >
< %systemroot%\Downloaded Program Files\ >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile >
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: firefox.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: firefox.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2012/05/11 07:38:19 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2012/05/11 07:38:19 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2012/05/11 07:38:19 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: iexplore.exe
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: firefox.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: firefox.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2012/05/11 07:38:19 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2012/05/11 07:38:19 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2012/05/11 07:38:19 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: iexplore.exe
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\drivers\*.sys /90 >
[2012/10/16 02:59:32 | 000,177,496 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\system32\drivers\07292517.sys
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2012/10/16 03:25:03 | 000,162,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\netbt.sys
< %systemroot%\System32\config\*.sav >
[2004/08/26 06:53:19 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2004/08/26 06:53:18 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004/08/26 06:53:18 | 000,864,256 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %SYSTEMDRIVE%\*.exe /md5 >
Invalid Environment Variable: %WinDir%\$NtUninstallKB*$. /30
< %systemdrive%\Program Files\Common Files\ComObjects\*.* /s >
< %systemroot%\*. /mp /s >
< %systemroot%\*. /rp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2011/03/03 02:55:19 | 000,149,504 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dnsapi.dll
[2012/05/11 20:12:34 | 011,111,424 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\ieframe.dll
[2012/05/11 10:42:33 | 002,000,384 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\iertutil.dll
[2008/04/13 20:12:00 | 000,274,944 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\mstask.dll
[2008/04/13 20:12:02 | 000,067,072 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\ntdsapi.dll
[2012/06/08 10:26:20 | 008,462,848 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\Installer\ /s >
< %systemroot%\system32\Cache\ /s >
< %systemroot%\system32\config\systemprofile\Application Data /s >
< %PROGRAMFILES%\*. >
[2012/01/21 12:37:27 | 000,000,000 | ---D | M] -- C:\Program Files\Ableton
[2012/03/29 01:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2011/11/27 01:17:26 | 000,000,000 | ---D | M] -- C:\Program Files\Ahead
[2011/12/31 10:49:11 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2012/05/31 17:28:35 | 000,000,000 | ---D | M] -- C:\Program Files\Audacity
[2011/11/27 00:17:31 | 000,000,000 | ---D | M] -- C:\Program Files\BigFix
[2011/12/31 10:48:21 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2012/01/06 16:44:11 | 000,000,000 | ---D | M] -- C:\Program Files\Brother
[2011/11/28 07:22:11 | 000,000,000 | ---D | M] -- C:\Program Files\CanonBJ
[2011/12/14 07:34:20 | 000,000,000 | ---D | M] -- C:\Program Files\Citrix
[2012/10/14 17:37:05 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2011/11/27 01:06:08 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2011/11/27 01:18:46 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2012/06/12 00:33:43 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX
[2011/11/27 01:20:47 | 000,000,000 | ---D | M] -- C:\Program Files\Digital Media Reader
[2012/08/15 03:42:19 | 000,000,000 | ---D | M] -- C:\Program Files\eBay
[2012/06/12 00:30:53 | 000,000,000 | ---D | M] -- C:\Program Files\EMC Corporation
[2012/10/14 16:13:50 | 000,000,000 | ---D | M] -- C:\Program Files\Enigma Software Group
[2012/03/29 00:35:02 | 000,000,000 | ---D | M] -- C:\Program Files\FileHippo.com
[2012/10/09 01:59:06 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2012/01/06 16:43:28 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2012/07/12 15:01:09 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2012/03/29 06:06:23 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2012/03/29 06:07:37 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2012/07/13 14:27:58 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2012/10/15 19:13:52 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/08/24 08:03:21 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2011/12/08 06:08:17 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2012/03/29 06:37:00 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2004/08/26 14:04:52 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2011/11/27 01:14:52 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Money
[2012/01/02 18:14:46 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2011/11/27 01:18:14 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2011/12/09 19:05:15 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2011/12/18 19:12:22 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2012/03/29 05:50:07 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2004/08/26 14:00:08 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2011/11/27 01:12:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Encarta Plus
[2004/08/26 14:00:22 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2011/11/28 06:57:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2011/12/08 05:58:01 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2011/11/27 01:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2011/11/29 23:20:28 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2011/12/09 19:01:21 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2012/09/24 04:20:42 | 000,000,000 | ---D | M] -- C:\Program Files\PC Tools
[2012/04/28 22:46:08 | 000,000,000 | ---D | M] -- C:\Program Files\Photoshop 5.5
[2011/11/27 01:42:26 | 000,000,000 | ---D | M] -- C:\Program Files\Pure Networks
[2012/02/16 02:31:30 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2011/12/18 19:12:09 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2012/03/29 05:13:36 | 000,000,000 | ---D | M] -- C:\Program Files\Secunia
[2011/11/27 02:06:45 | 000,000,000 | ---D | M] -- C:\Program Files\TP-LINK
[2011/11/27 02:31:18 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2011/12/15 02:10:26 | 000,000,000 | ---D | M] -- C:\Program Files\USPS
[2011/11/27 01:16:45 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2012/06/12 00:34:42 | 000,000,000 | ---D | M] -- C:\Program Files\VMware
[2012/09/21 01:47:35 | 000,000,000 | ---D | M] -- C:\Program Files\VS Revo Group
[2012/05/25 00:00:37 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2012/05/25 00:05:45 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2011/12/08 05:57:53 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2004/08/26 14:04:52 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2012/01/21 12:45:38 | 000,000,000 | ---D | M] -- C:\Program Files\ZOOM
Invalid Environment Variable: %appdata%\*.*
< MD5 for: AFD.SYS >
[2011/08/17 09:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\dllcache\afd.sys
[2011/08/17 09:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\drivers\afd.sys
[2008/04/13 15:19:23 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\$NtUninstallKB951748$\afd.sys
[2008/04/13 15:19:23 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\ServicePackFiles\i386\afd.sys
[2008/10/16 11:07:58 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=38D7B715504DA4741DF35E3594FE2099 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys
[2008/08/14 06:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys
[2008/08/14 06:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP3QFE\afd.sys
[2008/08/14 05:51:43 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=55E6E1C51B6D30E54335750955453702 -- C:\WINDOWS\$NtServicePackUninstall$\afd.sys
[2008/08/14 05:51:43 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=55E6E1C51B6D30E54335750955453702 -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP2GDR\afd.sys
[2004/08/04 15:00:00 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\$NtUninstallKB951748_0$\afd.sys
[2008/08/14 05:48:52 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=6A0397376853E604DE8E1E7A87FC08AC -- C:\WINDOWS\$hf_mig$\KB956803\SP2QFE\afd.sys
[2008/08/14 05:48:52 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=6A0397376853E604DE8E1E7A87FC08AC -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP2QFE\afd.sys
[2008/10/16 10:43:01 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7618D5218F2A614672EC61A80D854A37 -- C:\WINDOWS\$NtUninstallKB2592799$\afd.sys
[2008/08/14 06:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$hf_mig$\KB956803\SP3GDR\afd.sys
[2008/08/14 06:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$NtUninstallKB2509553$\afd.sys
[2008/08/14 06:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP3GDR\afd.sys
[2008/06/20 06:44:38 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=944CA435BFCFC82CC1ED9E3A7D731AA9 -- C:\WINDOWS\$NtUninstallKB956803_0$\afd.sys
[2008/06/20 06:44:38 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=944CA435BFCFC82CC1ED9E3A7D731AA9 -- C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2gdr\afd.sys
[2008/06/20 07:48:03 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys
[2008/06/20 07:48:03 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A -- C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3qfe\afd.sys
[2008/06/20 06:44:08 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=D99DDFFB33DEACDCF20717CB520379F6 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\afd.sys
[2008/06/20 06:44:08 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=D99DDFFB33DEACDCF20717CB520379F6 -- C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2qfe\afd.sys
[2008/06/20 07:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\afd.sys
[2008/06/20 07:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\$NtUninstallKB956803$\afd.sys
[2008/06/20 07:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\afd.sys
[2011/08/17 09:41:46 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=F6B7B1ECD7B41736BDB6FF4B092BCB79 -- C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
[2004/08/04 15:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/06 07:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 13:14:03 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 13:14:03 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE -- C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\services.exe
[2009/02/06 06:22:21 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD -- C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 06:22:21 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD -- C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe
[2004/08/04 15:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
< MD5 for: USERINIT.EXE >
[2004/08/04 15:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: VOLSNAP.SYS >
[2008/04/13 14:41:01 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\ServicePackFiles\i386\volsnap.sys
[2008/04/13 14:41:01 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\drivers\volsnap.sys
[2004/08/04 15:00:00 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\$NtServicePackUninstall$\volsnap.sys
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP
FC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24051EFF
< End of report >