OTL.txt (part 2):
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.jp.msn.com/HPALL/14
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2790392&SearchSource=13"
FF - prefs.js..extensions.enabledItems:
pdfforge@mybrowserbar.com:4.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.023.001
FF - prefs.js..extensions.enabledItems: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:2.7.2.0
FF - prefs.js..extensions.enabledItems:
wtxpcom@mybrowserbar.com:4.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cbe443d&v=6.010.006.004&i=23&tp=ab&iy=b&ychte=au&lng=en-GB&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/09 13:59:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/09 13:59:37 | 000,000,000 | ---D | M]
[2010/02/10 13:04:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Cassandra\AppData\Roaming\Mozilla\Extensions
[2011/01/08 23:46:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Cassandra\AppData\Roaming\Mozilla\Firefox\Profiles\zkzfaviq.default\extensions
[2010/11/05 15:31:04 | 000,000,000 | ---D | M] (BitTorrentBar Toolbar) -- C:\Users\Cassandra\AppData\Roaming\Mozilla\Firefox\Profiles\zkzfaviq.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2010/11/05 15:31:04 | 000,000,863 | ---- | M] () -- C:\Users\Cassandra\AppData\Roaming\Mozilla\Firefox\Profiles\zkzfaviq.default\searchplugins\conduit.xml
[2010/12/20 07:10:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/20 17:31:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/20 07:10:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED
[2010/11/22 11:33:58 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM
[2010/11/22 11:33:58 | 000,000,000 | ---D | M] (pdfforge Toolbar) -- C:\PROGRAM FILES\PDFFORGE TOOLBAR\FF
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/01/09 13:59:35 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/01/09 13:59:35 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/01/09 13:59:35 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/01/09 13:59:35 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/01/10 15:07:12 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [BitTorrent] C:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [instanteyedropper] C:\Program Files\InstantEyedropper\InstantEyedropper.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 08:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/06/04 09:52:20 | 000,135,168 | R--- | M] (Huawei Technologies Co., Ltd.) - G:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008/05/28 04:48:52 | 000,000,047 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2011/01/10 17:42:55 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Cassandra\Desktop\OTL.exe
[2011/01/10 17:36:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2011/01/10 17:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Core Temp
[2011/01/10 15:59:26 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\Desktop\Stuff from 10-01-11
[2011/01/10 15:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/01/10 15:49:47 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011/01/10 15:08:20 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/01/10 15:08:18 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/01/10 15:08:18 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\AppData\Local\temp
[2011/01/10 15:01:20 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/01/10 15:01:20 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/01/10 15:01:20 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/01/10 15:01:16 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/01/10 15:00:57 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/01/10 14:59:52 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\AppData\Roaming\Avira
[2011/01/10 13:23:44 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\AppData\Roaming\Malwarebytes
[2011/01/10 13:23:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/01/10 13:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/10 13:23:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/01/10 13:23:36 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/01/10 13:23:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/10 12:58:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/01/10 12:58:05 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/01/10 12:58:05 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/01/10 12:58:05 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/01/10 12:58:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/01/10 12:58:04 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/01/10 11:13:41 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/01/10 09:36:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/01/10 09:36:33 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/01/10 09:22:50 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\AppData\Roaming\Uniblue
[2011/01/10 09:22:27 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\AppData\Local\PackageAware
[2011/01/10 09:06:02 | 000,000,000 | ---D | C] -- C:\ProgramData\RegCure
[2011/01/10 09:03:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSConfig CleanUp
[2011/01/10 09:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\MSConfig CleanUp
[2011/01/04 19:10:51 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\aqbanking
[2011/01/04 19:02:50 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\Documents\webkit
[2011/01/04 17:37:17 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\.gnome2_private
[2011/01/04 17:37:17 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\.gnome2
[2011/01/04 17:37:17 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\.gconfd
[2011/01/04 17:37:17 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\.gconf
[2011/01/04 17:37:16 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\.gnucash
[2011/01/04 17:10:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GnuCash
[2011/01/04 17:09:47 | 000,000,000 | ---D | C] -- C:\Program Files\gnucash
[2010/12/28 09:09:29 | 000,000,000 | ---D | C] -- C:\ProgramData\LightScribe
[2010/12/25 20:32:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2010/12/25 20:30:59 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2010/12/24 17:42:06 | 000,230,400 | ---- | C] (Realtek ) -- C:\Windows\System32\drivers\Rt86win7.sys
[2010/12/24 17:35:19 | 000,000,000 | ---D | C] -- C:\ProgramData\{23D58E70-3B83-4B83-A227-68770F84F5EC}
[2010/12/22 08:38:55 | 000,000,000 | ---D | C] -- C:\Users\Cassandra\Desktop\Christmas
[2010/12/20 07:10:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/12/20 07:00:34 | 000,000,000 | ---D | C] -- C:\5de82764470293c6af1b3df92d9f
========== Files - Modified Within 30 Days ==========
[2011/01/10 19:25:14 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/10 19:25:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/01/10 19:24:39 | 2408,734,720 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/10 17:42:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Cassandra\Desktop\OTL.exe
[2011/01/10 17:36:02 | 000,000,067 | ---- | M] () -- C:\Users\Cassandra\Desktop\Core Temp Gadget & Addons.url
[2011/01/10 17:36:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/10 17:35:30 | 000,023,248 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/10 17:35:30 | 000,023,248 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/10 17:28:17 | 000,628,460 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/01/10 17:28:17 | 000,110,612 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/01/10 16:48:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-500072233-4124755467-2701217599-1000UA.job
[2011/01/10 15:07:12 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/01/10 13:23:40 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/10 12:58:09 | 000,002,012 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011/01/10 11:56:19 | 000,000,362 | ---- | M] () -- C:\Users\Cassandra\Documents\cc_20110110_115615.reg
[2011/01/10 10:11:13 | 000,068,450 | ---- | M] () -- C:\Users\Cassandra\Documents\cc_20110110_100206.reg
[2011/01/10 09:48:00 | 000,000,872 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-500072233-4124755467-2701217599-1000Core.job
[2011/01/09 20:59:42 | 000,037,103 | ---- | M] () -- C:\Users\Cassandra\Desktop\A wise man.cdr
[2011/01/09 20:57:31 | 000,037,108 | ---- | M] () -- C:\Users\Cassandra\Desktop\Backup_of_A wise man.cdr
[2011/01/09 20:35:15 | 000,007,606 | ---- | M] () -- C:\Users\Cassandra\AppData\Local\Resmon.ResmonCfg
[2011/01/09 19:43:05 | 000,010,497 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash
[2011/01/09 19:43:05 | 000,009,605 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110109194305.gnucash
[2011/01/08 15:31:00 | 000,008,849 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110108153100.gnucash
[2011/01/07 14:44:33 | 000,008,647 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107144433.gnucash
[2011/01/07 14:42:56 | 000,007,739 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107144256.gnucash
[2011/01/06 15:36:09 | 000,007,646 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106153609.gnucash
[2011/01/06 15:30:52 | 000,007,459 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106153052.gnucash
[2011/01/06 15:24:46 | 000,007,360 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106152446.gnucash
[2011/01/06 15:19:01 | 000,006,547 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106151901.gnucash
[2011/01/05 18:41:24 | 000,006,316 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105184124.gnucash
[2011/01/05 17:38:28 | 000,006,340 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105173828.gnucash
[2011/01/05 17:33:09 | 000,006,267 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105173309.gnucash
[2011/01/05 17:26:17 | 000,005,711 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105172617.gnucash
[2011/01/05 12:06:28 | 000,005,717 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120628.gnucash
[2011/01/05 12:04:58 | 000,004,971 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120458.gnucash
[2011/01/04 19:21:57 | 000,004,900 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104192157.gnucash
[2011/01/04 19:20:35 | 000,000,161 | ---- | M] () -- C:\Users\Cassandra\.gtkrc-2.0
[2011/01/04 19:19:57 | 000,004,102 | ---- | M] () -- C:\Users\Cassandra\.recently-used.xbel
[2011/01/04 19:19:46 | 000,004,860 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104191946.gnucash
[2011/01/04 19:08:04 | 000,004,860 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104190804.gnucash
[2011/01/04 19:06:13 | 000,004,670 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104190613.gnucash
[2011/01/04 18:59:34 | 000,004,503 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104185934.gnucash
[2011/01/04 18:55:00 | 000,004,360 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104185500.gnucash
[2011/01/04 18:49:53 | 000,004,286 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104184953.gnucash
[2011/01/04 18:44:46 | 000,004,836 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104184446.gnucash
[2011/01/04 18:39:22 | 000,004,404 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104183922.gnucash
[2011/01/04 18:33:33 | 000,004,284 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104183333.gnucash
[2011/01/04 18:28:19 | 000,003,784 | ---- | M] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104182819.gnucash
[2011/01/04 18:11:19 | 000,003,780 | ---- | M] () -- C:\Users\Cassandra\CasFinance.gnucash
[2011/01/04 17:10:39 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\GnuCash.lnk
[2010/12/29 18:21:29 | 000,008,349 | ---- | M] () -- C:\Users\Cassandra\Documents\car.xlsx
[2010/12/24 17:41:40 | 000,230,400 | ---- | M] (Realtek ) -- C:\Windows\System32\drivers\Rt86win7.sys
[2010/12/24 17:41:40 | 000,073,728 | ---- | M] () -- C:\Windows\System32\RtNicProp32.dll
[2010/12/24 17:36:13 | 000,002,137 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/12/20 08:53:25 | 000,429,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/12/13 08:40:21 | 000,135,096 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2010/12/13 08:40:21 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
========== Files Created - No Company Name ==========
[2011/01/10 17:36:02 | 000,000,067 | ---- | C] () -- C:\Users\Cassandra\Desktop\Core Temp Gadget & Addons.url
[2011/01/10 15:01:20 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/01/10 15:01:20 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/01/10 15:01:20 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/01/10 15:01:20 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/01/10 15:01:20 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/01/10 13:23:40 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/10 12:58:09 | 000,002,012 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011/01/10 11:56:17 | 000,000,362 | ---- | C] () -- C:\Users\Cassandra\Documents\cc_20110110_115615.reg
[2011/01/10 10:02:09 | 000,068,450 | ---- | C] () -- C:\Users\Cassandra\Documents\cc_20110110_100206.reg
[2011/01/09 20:48:11 | 000,037,108 | ---- | C] () -- C:\Users\Cassandra\Desktop\Backup_of_A wise man.cdr
[2011/01/09 20:35:15 | 000,007,606 | ---- | C] () -- C:\Users\Cassandra\AppData\Local\Resmon.ResmonCfg
[2011/01/09 20:31:38 | 000,037,103 | ---- | C] () -- C:\Users\Cassandra\Desktop\A wise man.cdr
[2011/01/09 19:43:06 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110109194306.log
[2011/01/09 19:43:05 | 000,009,605 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110109194305.gnucash
[2011/01/09 19:38:55 | 000,007,142 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110109193855.log
[2011/01/08 15:31:00 | 000,008,849 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110108153100.gnucash
[2011/01/08 15:31:00 | 000,000,416 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110108153100.log
[2011/01/08 15:25:42 | 000,007,072 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110108152542.log
[2011/01/08 15:20:51 | 000,000,440 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110108152051.log
[2011/01/07 14:44:34 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107144434.log
[2011/01/07 14:44:33 | 000,008,647 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107144433.gnucash
[2011/01/07 14:42:56 | 000,007,739 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107144256.gnucash
[2011/01/07 14:42:56 | 000,001,939 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107144256.log
[2011/01/07 14:37:36 | 000,010,196 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110107143736.log
[2011/01/06 15:36:09 | 000,007,646 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106153609.gnucash
[2011/01/06 15:36:09 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106153609.log
[2011/01/06 15:30:52 | 000,014,247 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106153052.log
[2011/01/06 15:30:52 | 000,007,459 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106153052.gnucash
[2011/01/06 15:24:46 | 000,008,819 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106152446.log
[2011/01/06 15:24:46 | 000,007,360 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106152446.gnucash
[2011/01/06 15:19:01 | 000,006,547 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106151901.gnucash
[2011/01/06 15:19:01 | 000,003,924 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106151901.log
[2011/01/06 15:13:16 | 000,006,880 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110106151316.log
[2011/01/05 18:41:24 | 000,006,316 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105184124.gnucash
[2011/01/05 18:41:24 | 000,000,416 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105184124.log
[2011/01/05 18:40:36 | 000,001,721 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105184036.log
[2011/01/05 17:38:28 | 000,006,340 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105173828.gnucash
[2011/01/05 17:38:28 | 000,000,708 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105173828.log
[2011/01/05 17:33:09 | 000,070,450 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105173309.log
[2011/01/05 17:33:09 | 000,006,267 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105173309.gnucash
[2011/01/05 17:26:17 | 000,005,711 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105172617.gnucash
[2011/01/05 17:26:17 | 000,002,426 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105172617.log
[2011/01/05 17:20:37 | 000,004,680 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105172037.log
[2011/01/05 12:06:28 | 000,005,717 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120628.gnucash
[2011/01/05 12:06:28 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120628.log
[2011/01/05 12:04:58 | 000,004,971 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120458.gnucash
[2011/01/05 12:04:58 | 000,003,472 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120458.log
[2011/01/05 12:00:22 | 000,003,455 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110105120022.log
[2011/01/04 19:21:57 | 000,004,900 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104192157.gnucash
[2011/01/04 19:20:35 | 000,000,161 | ---- | C] () -- C:\Users\Cassandra\.gtkrc-2.0
[2011/01/04 19:19:57 | 000,004,102 | ---- | C] () -- C:\Users\Cassandra\.recently-used.xbel
[2011/01/04 19:19:46 | 000,004,860 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104191946.gnucash
[2011/01/04 19:19:46 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104191946.log
[2011/01/04 19:08:04 | 000,025,128 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104190804.log
[2011/01/04 19:08:04 | 000,004,860 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104190804.gnucash
[2011/01/04 19:06:13 | 000,004,670 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104190613.gnucash
[2011/01/04 19:06:13 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104190613.log
[2011/01/04 18:59:35 | 000,002,856 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104185935.log
[2011/01/04 18:59:34 | 000,004,503 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104185934.gnucash
[2011/01/04 18:55:00 | 000,004,360 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104185500.gnucash
[2011/01/04 18:55:00 | 000,000,849 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104185500.log
[2011/01/04 18:49:53 | 000,004,286 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104184953.gnucash
[2011/01/04 18:49:53 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104184953.log
[2011/01/04 18:44:46 | 000,004,836 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104184446.gnucash
[2011/01/04 18:44:46 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104184446.log
[2011/01/04 18:39:22 | 000,004,404 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104183922.gnucash
[2011/01/04 18:39:22 | 000,000,196 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104183922.log
[2011/01/04 18:33:33 | 000,004,284 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104183333.gnucash
[2011/01/04 18:33:33 | 000,002,939 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104183333.log
[2011/01/04 18:28:19 | 000,003,784 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104182819.gnucash
[2011/01/04 18:28:19 | 000,002,140 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104182819.log
[2011/01/04 18:22:32 | 000,010,497 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash
[2011/01/04 18:22:32 | 000,004,612 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104182232.log
[2011/01/04 18:22:31 | 000,000,172 | ---- | C] () -- C:\Users\Cassandra\CasExpenses.gnucash.20110104182231.log
[2011/01/04 18:20:43 | 000,002,877 | ---- | C] () -- C:\Users\Cassandra\CasFinance.gnucash.20110104182043.log
[2011/01/04 18:19:57 | 000,000,976 | ---- | C] () -- C:\Users\Cassandra\CasFinance.gnucash.20110104181957.log
[2011/01/04 18:14:24 | 000,008,642 | ---- | C] () -- C:\Users\Cassandra\CasFinance.gnucash.20110104181424.log
[2011/01/04 18:11:19 | 000,004,261 | ---- | C] () -- C:\Users\Cassandra\CasFinance.gnucash.20110104181119.log
[2011/01/04 18:11:19 | 000,003,780 | ---- | C] () -- C:\Users\Cassandra\CasFinance.gnucash
[2011/01/04 17:10:39 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\GnuCash.lnk
[2010/12/28 09:08:39 | 000,008,349 | ---- | C] () -- C:\Users\Cassandra\Documents\car.xlsx
[2010/12/25 20:31:05 | 000,000,892 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/25 20:31:05 | 000,000,888 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/24 17:42:06 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2010/12/24 17:36:13 | 000,002,137 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/08/11 10:11:10 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2010/04/14 15:25:28 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010/02/09 19:12:15 | 000,000,000 | ---- | C] () -- C:\Users\Cassandra\AppData\Local\QSwitch.txt
[2010/02/09 19:12:15 | 000,000,000 | ---- | C] () -- C:\Users\Cassandra\AppData\Local\DSwitch.txt
[2010/02/09 19:12:15 | 000,000,000 | ---- | C] () -- C:\Users\Cassandra\AppData\Local\AtStart.txt
[2010/02/09 19:12:12 | 000,000,279 | ---- | C] () -- C:\ProgramData\HPWALog.txt
[2010/01/19 20:50:04 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/01/19 20:49:58 | 000,000,032 | ---- | C] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/01/19 20:49:48 | 000,000,032 | ---- | C] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/01/19 20:49:32 | 000,000,032 | ---- | C] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/01/19 20:48:58 | 000,000,032 | ---- | C] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/01/19 20:32:52 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2010/01/19 20:28:41 | 000,000,283 | ---- | C] () -- C:\Windows\System32\RStoneLog2.ini
[2010/01/19 20:28:41 | 000,000,224 | ---- | C] () -- C:\Windows\System32\RStoneLog.ini
[2010/01/10 20:07:01 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/01/10 20:04:19 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/01/10 20:03:30 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/01/10 20:03:05 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2009/09/30 10:25:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/14 10:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 10:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== LOP Check ==========
[2010/10/20 12:23:36 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\AVG10
[2011/01/10 19:25:17 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\BitTorrent
[2010/07/15 13:43:12 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\com.adobe.ExMan
[2010/10/29 14:53:38 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\DriverCure
[2010/08/12 14:55:31 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\Epson
[2010/02/25 18:36:50 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\Gamelab
[2010/08/11 10:06:01 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\GetRightToGo
[2010/12/23 14:28:00 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\gtk-2.0
[2010/11/22 10:25:56 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\PhotoScape
[2010/06/03 21:42:39 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\School Zone Preferences
[2010/02/10 20:17:18 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\Skinux
[2010/06/13 19:44:19 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\SmartDraw
[2011/01/10 09:22:50 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\Uniblue
[2010/02/20 09:30:33 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\Vodafone
[2010/02/09 20:14:28 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\WildTangent
[2010/11/09 08:36:57 | 000,000,000 | ---D | M] -- C:\Users\Cassandra\AppData\Roaming\Windows Live Writer
[2010/09/12 21:16:53 | 000,032,588 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/11 08:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/07/14 12:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2011/01/10 15:08:17 | 000,014,349 | ---- | M] () -- C:\ComboFix.txt
[2009/06/11 08:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2011/01/10 19:24:39 | 2408,734,720 | -HS- | M] () -- C:\hiberfil.sys
[2010/06/22 19:33:13 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/06/22 19:33:13 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/01/10 19:24:42 | 3211,649,024 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 15:52:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:52:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:52:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:52:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 08:31:19 | 000,000,065 | -H-- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 12:16:19 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/09/23 00:32:56 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 15:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/09 19:55:01 | 000,000,221 | -HS- | M] () -- C:\Users\Cassandra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/01/10 17:42:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Cassandra\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 08:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/08/09 13:22:35 | 000,000,402 | -HS- | M] () -- C:\Users\Cassandra\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/01/10 19:25:38 | 000,000,279 | ---- | M] () -- C:\ProgramData\HPWALog.txt
[2010/01/19 20:49:58 | 000,000,032 | ---- | M] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/01/10 20:07:31 | 000,000,109 | ---- | M] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/01/19 20:49:32 | 000,000,032 | ---- | M] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/01/10 20:04:12 | 000,000,105 | ---- | M] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/01/19 20:48:58 | 000,000,032 | ---- | M] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/01/19 20:49:48 | 000,000,032 | ---- | M] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/01/10 20:03:24 | 000,000,107 | ---- | M] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2010/01/10 20:06:55 | 000,000,110 | ---- | M] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/01/19 20:50:05 | 000,000,105 | ---- | M] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-19 20:08:39
========== Alternate Data Streams ==========
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:0B4227B4
< End of report >