OTL Part 2
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Burger%20Island/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://connect2.environment-agency.gov.uk/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://www.connect2ea.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A545EDF-3EBE-41C5-B268-01AB4F12860F}: DhcpNameServer = 15.243.128.51 15.243.160.51
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) -C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/HP_Owner/LOCALS~1/Temp/msoclip1/01/clip_image002.gif
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/11/09 20:20:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/04/30 23:01:14 | 000,000,053 | -HS- | M] () - D:\AUTORUN.FCB -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/03 17:31:04 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2012/02/03 17:28:23 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/02/02 23:40:54 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/02/02 19:21:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/02 19:21:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/02 19:21:39 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/02 19:21:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/02 19:21:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/02/02 19:21:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/02 18:53:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Family Tree Stuff
[2012/02/02 18:49:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Desktop
[2012/02/01 23:42:52 | 004,393,886 | R--- | C] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2012/01/31 19:07:01 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Documents and Settings\HP_Owner\Desktop\boot_cleaner.exe
[2012/01/31 19:07:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\bootkit_remover
[2012/01/31 19:01:35 | 004,733,440 | ---- | C] (AVAST Software) -- C:\Documents and Settings\HP_Owner\Desktop\aswMBR.exe
[2012/01/30 18:50:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Owner\Start Menu\Programs\Administrative Tools
[2012/01/30 18:49:43 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\dds.scr
[2012/01/30 18:23:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Log
[2012/01/29 21:32:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Owner\Recent
[2012/01/16 20:57:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/16 20:57:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CPA_VA
[2012/01/16 20:56:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\COMODO
[2012/01/16 20:54:54 | 000,000,000 | ---D | C] -- C:\VritualRoot
[2012/01/16 19:45:52 | 000,000,000 | ---D | C] -- C:\f8b78a383eb017763c
[2012/01/16 19:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Comodo
[2012/01/16 19:34:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Comodo
[2012/01/16 19:34:46 | 000,000,000 | ---D | C] -- C:\Program Files\Comodo
[2012/01/11 17:09:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/11 17:08:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/01/09 21:31:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2012/01/09 20:38:25 | 000,000,000 | ---D | C] -- C:\Program Files\75D9E
[2012/01/09 20:37:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\44575
[2007/07/27 15:18:59 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2007/07/27 15:18:59 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2007/07/27 15:18:59 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2007/05/12 13:59:14 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2007/04/13 16:15:30 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd2.dll
[2007/04/13 16:15:30 | 000,040,960 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd2.dll
[2007/04/13 16:15:30 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd2.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/03 17:33:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2012/02/03 17:23:22 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/03 17:23:10 | 000,000,248 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.dat
[2012/02/03 17:23:05 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc8adaf4a818e4.job
[2012/02/03 17:22:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/03 17:22:52 | 1073,074,176 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/03 00:08:42 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/02 20:14:53 | 000,002,205 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012/02/02 19:35:17 | 000,545,636 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/02/02 19:35:17 | 000,096,886 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/02/02 19:14:24 | 004,393,886 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2012/02/02 18:15:26 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2012/02/02 00:09:51 | 000,000,187 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\rk-proxy.reg
[2012/02/02 00:08:48 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\rkill.com
[2012/02/02 00:07:12 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\jww.exe
[2012/02/01 23:25:09 | 001,474,832 | ---- | M] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2012/02/01 23:17:16 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Norton_Removal_Tool.exe
[2012/02/01 18:51:02 | 000,303,059 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\ListParts.exe
[2012/02/01 13:42:00 | 000,000,820 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/01/31 19:01:14 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\HP_Owner\Desktop\aswMBR.exe
[2012/01/31 18:54:58 | 000,044,607 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\bootkit_remover.zip
[2012/01/30 18:45:28 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\dds.scr
[2012/01/30 18:29:50 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\snsi9chm.exe
[2012/01/29 22:16:45 | 000,000,795 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/29 20:48:18 | 000,136,192 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/16 20:09:28 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\COMODO Antivirus.lnk
[2012/01/16 20:06:35 | 000,000,928 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\COMODO GeekBuddy.lnk
[2012/01/16 19:37:41 | 000,000,774 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Comodo Dragon.lnk
[2012/01/16 19:35:03 | 000,000,910 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\COMODO GeekBuddy.lnk
[2012/01/11 17:19:15 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/09 20:51:34 | 000,000,844 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/07 14:23:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/02 19:47:28 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/02 19:47:28 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2012/02/02 19:47:28 | 000,000,972 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk
[2012/02/02 19:47:28 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\camtool.lnk
[2012/02/02 19:21:39 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/02 19:21:39 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/02 19:21:39 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/02 19:21:39 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/02 19:21:39 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/02 19:15:16 | 1073,074,176 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/02 18:15:43 | 000,920,384 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Norton_Removal_Tool.exe
[2012/02/02 00:09:51 | 000,000,187 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\rk-proxy.reg
[2012/02/02 00:08:31 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\rkill.com
[2012/02/02 00:08:24 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\jww.exe
[2012/02/01 18:56:27 | 000,303,059 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\ListParts.exe
[2012/01/31 19:01:40 | 000,044,607 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\bootkit_remover.zip
[2012/01/30 18:38:23 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\snsi9chm.exe
[2012/01/29 22:15:04 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/29 18:27:38 | 000,001,736 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012/01/29 18:27:38 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
[2012/01/29 18:27:37 | 000,000,997 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/01/16 20:17:14 | 001,474,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2012/01/16 20:09:28 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\COMODO Antivirus.lnk
[2012/01/16 20:06:35 | 000,000,928 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\COMODO GeekBuddy.lnk
[2012/01/16 20:06:34 | 000,000,910 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\COMODO GeekBuddy.lnk
[2012/01/16 20:05:33 | 000,000,774 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Comodo Dragon.lnk
[2012/01/10 12:38:05 | 000,000,844 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/08/18 10:51:23 | 000,208,100 | ---- | C] () -- C:\WINDOWS\hpoins47.dat
[2011/08/18 10:51:23 | 000,000,574 | ---- | C] () -- C:\WINDOWS\hpomdl47.dat
[2010/09/28 17:30:10 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/28 17:30:07 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/28 17:30:07 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/09/28 17:29:00 | 002,195,030 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/07/17 18:11:05 | 000,035,952 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/28 22:11:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DbgOut.INI
[2009/01/03 23:47:27 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/01/03 23:47:21 | 000,564,224 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2009/01/03 23:47:19 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/12 22:47:22 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/10/22 16:55:35 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2008/09/17 14:38:10 | 000,000,023 | ---- | C] () -- C:\WINDOWS\Mahjongg Variations.INI
[2008/05/27 14:58:37 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2008/05/26 20:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/02/26 18:32:44 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/01/13 17:53:45 | 000,000,390 | ---- | C] () -- C:\WINDOWS\Lexstat.ini
[2008/01/13 17:52:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxczcnv7.dll
[2008/01/13 17:52:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxczcnv6.dll
[2008/01/13 17:52:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxczcnv5.dll
[2008/01/13 17:52:50 | 000,039,899 | ---- | C] () -- C:\WINDOWS\System32\rtsicis.ini
[2007/10/12 14:56:13 | 000,000,016 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2007/09/27 09:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/07/28 09:18:37 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2007/07/28 09:17:08 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2007/07/27 15:18:59 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd3.exe
[2007/07/27 15:18:59 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2007/06/30 09:38:41 | 000,000,291 | ---- | C] () -- C:\WINDOWS\msfsetup.ini
[2007/06/17 22:48:59 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\vidccleaner.exe
[2007/06/17 22:48:24 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/06/17 22:48:24 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/06/16 18:12:46 | 000,136,192 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/21 15:28:53 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\fusioncache.dat
[2007/05/17 22:31:46 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\proc625010911.bin
[2007/04/23 00:15:29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/23 00:01:47 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/04/13 16:15:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\dsnpstd2.dll
[2007/04/13 16:15:32 | 000,302,720 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd2.sys
[2007/04/13 10:20:13 | 000,127,456 | ---- | C] () -- C:\WINDOWS\System32\IPDETECT.EXE
[2007/04/13 10:20:10 | 000,046,892 | ---- | C] () -- C:\WINDOWS\System32\ADADIX16.DLL
[2007/04/13 10:20:09 | 000,022,395 | ---- | C] () -- C:\WINDOWS\System32\drivers\fpga.bin
[2007/02/25 15:50:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/02/12 13:19:51 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2007/01/26 17:45:18 | 000,000,071 | ---- | C] () -- C:\WINDOWS\pex.INI
[2007/01/26 17:33:55 | 000,000,151 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2007/01/09 01:20:19 | 000,002,586 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/05 21:39:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\vsnpstd2.exe
[2006/12/05 21:39:39 | 000,015,541 | ---- | C] () -- C:\WINDOWS\snpstd2.ini
[2006/12/05 21:39:31 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd2.exe
[2006/12/05 20:51:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/12/04 00:10:37 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/12/03 15:28:46 | 000,000,154 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2006/12/03 15:28:40 | 000,000,295 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2005/08/21 16:47:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/05/09 23:52:32 | 000,022,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2005/01/03 04:31:54 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/01/03 04:11:48 | 000,016,359 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2005/01/03 04:11:40 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2005/01/03 04:06:43 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/01/03 04:06:43 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/01/03 04:06:43 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/01/03 04:06:43 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/01/03 04:06:43 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/01/03 04:06:43 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/01/03 04:04:47 | 000,000,100 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005/01/03 03:58:59 | 000,112,870 | ---- | C] () -- C:\WINDOWS\hpoins07.dat
[2005/01/03 03:58:58 | 000,021,124 | ---- | C] () -- C:\WINDOWS\hpomdl07.dat
[2005/01/03 03:54:16 | 000,080,418 | ---- | C] () -- C:\WINDOWS\HPHins08.dat
[2005/01/03 03:54:16 | 000,004,011 | ---- | C] () -- C:\WINDOWS\hphmdl08.dat
[2005/01/03 03:52:17 | 000,072,881 | ---- | C] () -- C:\WINDOWS\hpiins01.dat
[2005/01/03 03:52:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpimdl01.dat
[2005/01/03 03:51:25 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/01/03 03:36:54 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/01/03 03:33:24 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2005/01/03 03:33:24 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2005/01/03 03:33:02 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2004/11/09 20:39:12 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/11/09 20:25:42 | 000,545,636 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/11/09 20:25:42 | 000,096,886 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/11/09 20:22:42 | 000,158,752 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/11/09 20:19:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/11/09 20:17:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 18:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/06/25 02:10:06 | 000,000,567 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 23:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 23:11:02 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/07/06 22:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PLAYROOM\Application Data\SampleView
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PLAYROOM.000\Application Data\SampleView
[2012/01/11 17:48:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PLAYROOM.000\Application Data\Windows Search
[2008/01/17 15:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\7Wonders2
[2008/12/17 17:40:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2007/07/14 09:06:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Aliasworlds
[2008/03/21 11:14:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astar Games
[2007/12/02 15:36:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2009/05/23 17:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2008/12/29 13:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Burger Island 2
[2007/08/02 22:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Channel4
[2008/04/07 13:11:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Chasing Dogs Studios
[2009/07/13 14:34:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2012/01/16 20:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CPA_VA
[2008/09/14 12:48:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2007/07/25 13:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FireGlow
[2008/07/03 15:53:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fitn17
[2007/11/23 15:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2008/12/27 20:14:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreshGames
[2008/02/28 15:00:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Friends Games
[2007/11/10 17:32:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/10/14 15:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2007/09/28 13:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Genimo
[2011/03/06 17:58:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gHeOpOk06300
[2008/02/18 13:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Go Go Gourmet
[2009/08/16 15:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GoBit Games
[2007/12/24 15:58:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii
[2008/06/17 19:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii Games
[2007/12/08 15:14:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grey Alien Games
[2010/04/26 20:24:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HTC
[2008/11/04 16:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intenium
[2008/10/22 16:55:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/04/21 18:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2010/02/16 17:51:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/01/24 07:52:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/11/27 16:10:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/01/19 17:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MythPeople
[2008/09/30 14:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Games
[2009/02/25 19:59:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/12/06 14:32:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2007/12/27 20:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rionix
[2008/08/09 15:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/01/22 15:33:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpecialBit
[2008/05/25 14:50:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/01/26 11:19:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTopV1005
[2008/03/09 14:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SugarGames
[2010/04/26 20:24:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca
[2008/08/08 10:23:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TheRace_dev
[2007/01/26 17:33:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/01/23 14:07:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Valusoft
[2007/08/28 16:34:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2010/07/03 21:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/06 23:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\SampleView
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/01/03 04:17:10 | 000,000,104 | ---- | M] () -- C:\.lnk
[2004/11/09 20:20:04 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007/04/13 01:49:56 | 000,000,213 | RHS- | M] () -- C:\BOOT.BAK
[2012/02/02 18:15:26 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/02/26 00:01:38 | 000,000,076 | ---- | M] () -- C:\Catalog.LiveSubscribe
[2004/08/04 12:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2012/02/03 00:17:58 | 000,919,903 | ---- | M] () -- C:\ComboFix.txt
[2004/11/09 20:20:04 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/04/03 00:00:19 | 000,000,000 | ---- | M] () -- C:\conmgr.log
[2007/07/18 19:13:55 | 000,000,093 | ---- | M] () -- C:\DownloadLog.txt
[2008/04/07 16:41:29 | 000,003,532 | ---- | M] () -- C:\drmHeader.bin
[2011/03/02 09:39:02 | 001,228,854 | ---- | M] () -- C:\fsqwr.bmp
[2012/02/03 17:22:52 | 1073,074,176 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/12 21:46:34 | 000,304,152 | ---- | M] () -- C:\img2-001.raw
[2007/07/28 18:46:28 | 000,230,424 | ---- | M] () -- C:\img2-002.raw
[2007/07/27 20:45:48 | 000,230,424 | ---- | M] () -- C:\img2-004.raw
[2004/11/09 20:20:04 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/02/24 14:53:44 | 000,000,139 | ---- | M] () -- C:\ioSpecial.ini
[2007/04/12 22:28:21 | 000,000,979 | ---- | M] () -- C:\IPH.PH
[2008/10/15 17:18:15 | 000,401,280 | ---- | M] () -- C:\logfile
[2011/04/03 07:54:20 | 000,001,111 | ---- | M] () -- C:\lxcz.log
[2004/11/09 20:20:04 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/09/04 00:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
[2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/09/26 21:55:20 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/02/03 06:55:28 | 000,136,918 | ---- | M] () -- C:\OTL.Txt
[2012/02/03 17:22:50 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2008/04/07 15:29:44 | 000,104,550 | ---- | M] () -- C:\playground.log
[2012/02/02 18:42:02 | 000,000,359 | ---- | M] () -- C:\rkill.log
[2008/08/11 23:06:48 | 000,000,268 | ---- | M] () -- C:\sqmdata00.sqm
[2008/08/12 12:50:00 | 000,000,268 | ---- | M] () -- C:\sqmdata01.sqm
[2008/08/20 13:06:53 | 000,000,268 | ---- | M] () -- C:\sqmdata02.sqm
[2008/08/20 17:46:32 | 000,000,268 | ---- | M] () -- C:\sqmdata03.sqm
[2008/08/29 13:35:29 | 000,000,268 | ---- | M] () -- C:\sqmdata04.sqm
[2008/08/30 22:50:48 | 000,000,268 | ---- | M] () -- C:\sqmdata05.sqm
[2008/09/01 11:15:28 | 000,000,268 | ---- | M] () -- C:\sqmdata06.sqm
[2008/10/01 16:34:46 | 000,000,268 | ---- | M] () -- C:\sqmdata07.sqm
[2008/09/18 14:58:37 | 000,000,268 | ---- | M] () -- C:\sqmdata08.sqm
[2008/09/14 23:46:24 | 000,000,268 | ---- | M] () -- C:\sqmdata09.sqm
[2008/10/20 13:55:22 | 000,000,268 | ---- | M] () -- C:\sqmdata10.sqm
[2008/05/16 16:41:23 | 000,000,268 | ---- | M] () -- C:\sqmdata11.sqm
[2008/06/03 11:33:00 | 000,000,268 | ---- | M] () -- C:\sqmdata12.sqm
[2008/06/12 21:00:09 | 000,000,268 | ---- | M] () -- C:\sqmdata13.sqm
[2008/06/15 22:34:06 | 000,000,268 | ---- | M] () -- C:\sqmdata14.sqm
[2008/06/18 23:29:41 | 000,000,268 | ---- | M] () -- C:\sqmdata15.sqm
[2008/06/19 10:14:40 | 000,000,268 | ---- | M] () -- C:\sqmdata16.sqm
[2008/07/10 02:06:56 | 000,000,268 | ---- | M] () -- C:\sqmdata17.sqm
[2008/08/02 07:17:38 | 000,000,268 | ---- | M] () -- C:\sqmdata18.sqm
[2008/08/11 17:48:26 | 000,000,268 | ---- | M] () -- C:\sqmdata19.sqm
[2008/08/11 23:06:48 | 000,000,244 | ---- | M] () -- C:\sqmnoopt00.sqm
[2008/08/12 12:50:00 | 000,000,244 | ---- | M] () -- C:\sqmnoopt01.sqm
[2008/08/20 13:06:53 | 000,000,244 | ---- | M] () -- C:\sqmnoopt02.sqm
[2008/08/20 17:46:32 | 000,000,244 | ---- | M] () -- C:\sqmnoopt03.sqm
[2008/08/29 13:35:29 | 000,000,244 | ---- | M] () -- C:\sqmnoopt04.sqm
[2008/08/30 22:50:48 | 000,000,244 | ---- | M] () -- C:\sqmnoopt05.sqm
[2008/09/01 11:15:28 | 000,000,244 | ---- | M] () -- C:\sqmnoopt06.sqm
[2008/10/01 16:34:45 | 000,000,244 | ---- | M] () -- C:\sqmnoopt07.sqm
[2008/09/18 14:58:37 | 000,000,244 | ---- | M] () -- C:\sqmnoopt08.sqm
[2008/09/14 23:46:24 | 000,000,244 | ---- | M] () -- C:\sqmnoopt09.sqm
[2008/10/20 13:55:22 | 000,000,244 | ---- | M] () -- C:\sqmnoopt10.sqm
[2008/05/16 16:41:23 | 000,000,244 | ---- | M] () -- C:\sqmnoopt11.sqm
[2008/06/03 11:33:00 | 000,000,244 | ---- | M] () -- C:\sqmnoopt12.sqm
[2008/06/12 21:00:09 | 000,000,244 | ---- | M] () -- C:\sqmnoopt13.sqm
[2008/06/15 22:34:06 | 000,000,244 | ---- | M] () -- C:\sqmnoopt14.sqm
[2008/06/18 23:29:41 | 000,000,244 | ---- | M] () -- C:\sqmnoopt15.sqm
[2008/06/19 10:14:40 | 000,000,244 | ---- | M] () -- C:\sqmnoopt16.sqm
[2008/07/10 02:06:56 | 000,000,244 | ---- | M] () -- C:\sqmnoopt17.sqm
[2008/08/02 07:17:38 | 000,000,244 | ---- | M] () -- C:\sqmnoopt18.sqm
[2008/08/11 17:48:25 | 000,000,244 | ---- | M] () -- C:\sqmnoopt19.sqm
[2012/01/15 20:30:03 | 000,058,506 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_20.26.20_log.txt
[2012/01/15 20:52:21 | 000,059,492 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_20.48.06_log.txt
[2012/01/15 21:00:11 | 000,058,376 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_20.59.41_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2005/05/12 06:36:48 | 000,012,288 | ---- | M] (Hewlett-Packard Co.) -- C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2004/11/09 20:19:36 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/10/21 14:29:40 | 000,320,512 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp101.dll
[2008/07/06 10:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2007/07/28 17:53:11 | 000,001,698 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2007/05/12 13:59:02 | 000,774,144 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2008/02/26 18:32:44 | 000,000,000 | ---- | M] () -- C:\Program Files\temp01
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/11/09 20:10:20 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2004/11/09 20:10:20 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004/11/09 20:10:20 | 000,897,024 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/26 22:01:52 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/13 01:53:27 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/11/09 20:23:22 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/01/31 19:01:14 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\HP_Owner\Desktop\aswMBR.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Documents and Settings\HP_Owner\Desktop\boot_cleaner.exe
[2012/02/02 19:14:24 | 004,393,886 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2012/02/02 00:07:12 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\jww.exe
[2012/02/01 18:51:02 | 000,303,059 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\ListParts.exe
[2012/02/01 23:17:16 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Norton_Removal_Tool.exe
[2012/02/03 17:33:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2012/01/30 18:29:50 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\snsi9chm.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2003/01/17 16:35:40 | 000,013,023 | ---- | M] () -- C:\WINDOWS\snpstd2.src
[2004/02/27 15:36:18 | 000,013,023 | ---- | M] () -- C:\WINDOWS\snpstd3.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2007/11/03 13:03:59 | 051,422,520 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\HP_Owner\My Documents\iTunes743Setup.exe
[2007/05/21 13:27:29 | 004,301,387 | ---- | M] (Shareaza Development Team ) -- C:\Documents and Settings\HP_Owner\My Documents\Shareaza_2.2.5.0.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/04 12:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\ADDINS\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2007/04/13 01:53:26 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010/08/13 01:22:34 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Cookies\desktop.ini
[2012/02/03 17:31:01 | 000,835,584 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007/06/26 21:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008/04/14 00:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2004/08/04 07:06:34 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
[2004/08/04 07:06:34 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2008/05/02 14:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2008/04/13 17:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/04/14 00:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2004/08/04 07:06:36 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2004/08/04 07:06:36 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2004/08/04 07:06:36 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2004/08/04 07:06:36 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2004/08/04 07:06:36 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
[1998/05/07 16:04:38 | 000,052,736 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system\hpsysdrv.exe
[1999/09/10 12:06:00 | 000,004,672 | ---- | M] (Adaptec) -- C:\WINDOWS\system\WOWPOST.EXE
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Burger%20Island/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://connect2.environment-agency.gov.uk/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://www.connect2ea.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A545EDF-3EBE-41C5-B268-01AB4F12860F}: DhcpNameServer = 15.243.128.51 15.243.160.51
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) -C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/HP_Owner/LOCALS~1/Temp/msoclip1/01/clip_image002.gif
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/11/09 20:20:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/04/30 23:01:14 | 000,000,053 | -HS- | M] () - D:\AUTORUN.FCB -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/03 17:31:04 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2012/02/03 17:28:23 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/02/02 23:40:54 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/02/02 19:21:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/02 19:21:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/02 19:21:39 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/02 19:21:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/02 19:21:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/02/02 19:21:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/02 18:53:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Family Tree Stuff
[2012/02/02 18:49:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Desktop
[2012/02/01 23:42:52 | 004,393,886 | R--- | C] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2012/01/31 19:07:01 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Documents and Settings\HP_Owner\Desktop\boot_cleaner.exe
[2012/01/31 19:07:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\bootkit_remover
[2012/01/31 19:01:35 | 004,733,440 | ---- | C] (AVAST Software) -- C:\Documents and Settings\HP_Owner\Desktop\aswMBR.exe
[2012/01/30 18:50:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Owner\Start Menu\Programs\Administrative Tools
[2012/01/30 18:49:43 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\dds.scr
[2012/01/30 18:23:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Log
[2012/01/29 21:32:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HP_Owner\Recent
[2012/01/16 20:57:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/16 20:57:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CPA_VA
[2012/01/16 20:56:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\COMODO
[2012/01/16 20:54:54 | 000,000,000 | ---D | C] -- C:\VritualRoot
[2012/01/16 19:45:52 | 000,000,000 | ---D | C] -- C:\f8b78a383eb017763c
[2012/01/16 19:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Comodo
[2012/01/16 19:34:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Comodo
[2012/01/16 19:34:46 | 000,000,000 | ---D | C] -- C:\Program Files\Comodo
[2012/01/11 17:09:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/11 17:08:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/01/09 21:31:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2012/01/09 20:38:25 | 000,000,000 | ---D | C] -- C:\Program Files\75D9E
[2012/01/09 20:37:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\44575
[2007/07/27 15:18:59 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2007/07/27 15:18:59 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2007/07/27 15:18:59 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2007/05/12 13:59:14 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2007/04/13 16:15:30 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd2.dll
[2007/04/13 16:15:30 | 000,040,960 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd2.dll
[2007/04/13 16:15:30 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd2.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/03 17:33:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2012/02/03 17:23:22 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/03 17:23:10 | 000,000,248 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.dat
[2012/02/03 17:23:05 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc8adaf4a818e4.job
[2012/02/03 17:22:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/03 17:22:52 | 1073,074,176 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/03 00:08:42 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/02 20:14:53 | 000,002,205 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012/02/02 19:35:17 | 000,545,636 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/02/02 19:35:17 | 000,096,886 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/02/02 19:14:24 | 004,393,886 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2012/02/02 18:15:26 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2012/02/02 00:09:51 | 000,000,187 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\rk-proxy.reg
[2012/02/02 00:08:48 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\rkill.com
[2012/02/02 00:07:12 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\jww.exe
[2012/02/01 23:25:09 | 001,474,832 | ---- | M] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2012/02/01 23:17:16 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Norton_Removal_Tool.exe
[2012/02/01 18:51:02 | 000,303,059 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\ListParts.exe
[2012/02/01 13:42:00 | 000,000,820 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/01/31 19:01:14 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\HP_Owner\Desktop\aswMBR.exe
[2012/01/31 18:54:58 | 000,044,607 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\bootkit_remover.zip
[2012/01/30 18:45:28 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\dds.scr
[2012/01/30 18:29:50 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\snsi9chm.exe
[2012/01/29 22:16:45 | 000,000,795 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/29 20:48:18 | 000,136,192 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/16 20:09:28 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\COMODO Antivirus.lnk
[2012/01/16 20:06:35 | 000,000,928 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\COMODO GeekBuddy.lnk
[2012/01/16 19:37:41 | 000,000,774 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Comodo Dragon.lnk
[2012/01/16 19:35:03 | 000,000,910 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\COMODO GeekBuddy.lnk
[2012/01/11 17:19:15 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/09 20:51:34 | 000,000,844 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/07 14:23:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/02 19:47:28 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/02 19:47:28 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2012/02/02 19:47:28 | 000,000,972 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk
[2012/02/02 19:47:28 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\camtool.lnk
[2012/02/02 19:21:39 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/02 19:21:39 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/02 19:21:39 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/02 19:21:39 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/02 19:21:39 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/02 19:15:16 | 1073,074,176 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/02 18:15:43 | 000,920,384 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Norton_Removal_Tool.exe
[2012/02/02 00:09:51 | 000,000,187 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\rk-proxy.reg
[2012/02/02 00:08:31 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\rkill.com
[2012/02/02 00:08:24 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\jww.exe
[2012/02/01 18:56:27 | 000,303,059 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\ListParts.exe
[2012/01/31 19:01:40 | 000,044,607 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\bootkit_remover.zip
[2012/01/30 18:38:23 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\snsi9chm.exe
[2012/01/29 22:15:04 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/29 18:27:38 | 000,001,736 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012/01/29 18:27:38 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
[2012/01/29 18:27:37 | 000,000,997 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/01/16 20:17:14 | 001,474,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2012/01/16 20:09:28 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\COMODO Antivirus.lnk
[2012/01/16 20:06:35 | 000,000,928 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\COMODO GeekBuddy.lnk
[2012/01/16 20:06:34 | 000,000,910 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\COMODO GeekBuddy.lnk
[2012/01/16 20:05:33 | 000,000,774 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Comodo Dragon.lnk
[2012/01/10 12:38:05 | 000,000,844 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/08/18 10:51:23 | 000,208,100 | ---- | C] () -- C:\WINDOWS\hpoins47.dat
[2011/08/18 10:51:23 | 000,000,574 | ---- | C] () -- C:\WINDOWS\hpomdl47.dat
[2010/09/28 17:30:10 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/28 17:30:07 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/28 17:30:07 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/09/28 17:29:00 | 002,195,030 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/07/17 18:11:05 | 000,035,952 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/28 22:11:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DbgOut.INI
[2009/01/03 23:47:27 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/01/03 23:47:21 | 000,564,224 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2009/01/03 23:47:19 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/12 22:47:22 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/10/22 16:55:35 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2008/09/17 14:38:10 | 000,000,023 | ---- | C] () -- C:\WINDOWS\Mahjongg Variations.INI
[2008/05/27 14:58:37 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2008/05/26 20:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/02/26 18:32:44 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/01/13 17:53:45 | 000,000,390 | ---- | C] () -- C:\WINDOWS\Lexstat.ini
[2008/01/13 17:52:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxczcnv7.dll
[2008/01/13 17:52:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxczcnv6.dll
[2008/01/13 17:52:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxczcnv5.dll
[2008/01/13 17:52:50 | 000,039,899 | ---- | C] () -- C:\WINDOWS\System32\rtsicis.ini
[2007/10/12 14:56:13 | 000,000,016 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2007/09/27 09:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/07/28 09:18:37 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2007/07/28 09:17:08 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2007/07/27 15:18:59 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd3.exe
[2007/07/27 15:18:59 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2007/06/30 09:38:41 | 000,000,291 | ---- | C] () -- C:\WINDOWS\msfsetup.ini
[2007/06/17 22:48:59 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\vidccleaner.exe
[2007/06/17 22:48:24 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/06/17 22:48:24 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/06/16 18:12:46 | 000,136,192 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/21 15:28:53 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\fusioncache.dat
[2007/05/17 22:31:46 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\proc625010911.bin
[2007/04/23 00:15:29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/23 00:01:47 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/04/13 16:15:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\dsnpstd2.dll
[2007/04/13 16:15:32 | 000,302,720 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd2.sys
[2007/04/13 10:20:13 | 000,127,456 | ---- | C] () -- C:\WINDOWS\System32\IPDETECT.EXE
[2007/04/13 10:20:10 | 000,046,892 | ---- | C] () -- C:\WINDOWS\System32\ADADIX16.DLL
[2007/04/13 10:20:09 | 000,022,395 | ---- | C] () -- C:\WINDOWS\System32\drivers\fpga.bin
[2007/02/25 15:50:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/02/12 13:19:51 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2007/01/26 17:45:18 | 000,000,071 | ---- | C] () -- C:\WINDOWS\pex.INI
[2007/01/26 17:33:55 | 000,000,151 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2007/01/09 01:20:19 | 000,002,586 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/05 21:39:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\vsnpstd2.exe
[2006/12/05 21:39:39 | 000,015,541 | ---- | C] () -- C:\WINDOWS\snpstd2.ini
[2006/12/05 21:39:31 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd2.exe
[2006/12/05 20:51:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/12/04 00:10:37 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/12/03 15:28:46 | 000,000,154 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2006/12/03 15:28:40 | 000,000,295 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2005/08/21 16:47:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/05/09 23:52:32 | 000,022,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2005/01/03 04:31:54 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/01/03 04:11:48 | 000,016,359 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2005/01/03 04:11:40 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2005/01/03 04:06:43 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/01/03 04:06:43 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/01/03 04:06:43 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/01/03 04:06:43 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/01/03 04:06:43 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/01/03 04:06:43 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/01/03 04:04:47 | 000,000,100 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005/01/03 03:58:59 | 000,112,870 | ---- | C] () -- C:\WINDOWS\hpoins07.dat
[2005/01/03 03:58:58 | 000,021,124 | ---- | C] () -- C:\WINDOWS\hpomdl07.dat
[2005/01/03 03:54:16 | 000,080,418 | ---- | C] () -- C:\WINDOWS\HPHins08.dat
[2005/01/03 03:54:16 | 000,004,011 | ---- | C] () -- C:\WINDOWS\hphmdl08.dat
[2005/01/03 03:52:17 | 000,072,881 | ---- | C] () -- C:\WINDOWS\hpiins01.dat
[2005/01/03 03:52:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpimdl01.dat
[2005/01/03 03:51:25 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/01/03 03:36:54 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/01/03 03:33:24 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2005/01/03 03:33:24 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2005/01/03 03:33:02 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2004/11/09 20:39:12 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/11/09 20:25:42 | 000,545,636 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/11/09 20:25:42 | 000,096,886 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/11/09 20:22:42 | 000,158,752 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/11/09 20:19:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/11/09 20:17:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 18:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/06/25 02:10:06 | 000,000,567 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 23:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 23:11:02 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/07/06 22:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PLAYROOM\Application Data\SampleView
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PLAYROOM.000\Application Data\SampleView
[2012/01/11 17:48:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PLAYROOM.000\Application Data\Windows Search
[2008/01/17 15:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\7Wonders2
[2008/12/17 17:40:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2007/07/14 09:06:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Aliasworlds
[2008/03/21 11:14:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astar Games
[2007/12/02 15:36:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2009/05/23 17:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2008/12/29 13:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Burger Island 2
[2007/08/02 22:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Channel4
[2008/04/07 13:11:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Chasing Dogs Studios
[2009/07/13 14:34:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2012/01/16 20:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CPA_VA
[2008/09/14 12:48:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2007/07/25 13:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FireGlow
[2008/07/03 15:53:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fitn17
[2007/11/23 15:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2008/12/27 20:14:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreshGames
[2008/02/28 15:00:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Friends Games
[2007/11/10 17:32:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/10/14 15:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2007/09/28 13:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Genimo
[2011/03/06 17:58:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gHeOpOk06300
[2008/02/18 13:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Go Go Gourmet
[2009/08/16 15:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GoBit Games
[2007/12/24 15:58:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii
[2008/06/17 19:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii Games
[2007/12/08 15:14:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grey Alien Games
[2010/04/26 20:24:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HTC
[2008/11/04 16:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intenium
[2008/10/22 16:55:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/04/21 18:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2010/02/16 17:51:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/01/24 07:52:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/11/27 16:10:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/01/19 17:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MythPeople
[2008/09/30 14:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Games
[2009/02/25 19:59:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/12/06 14:32:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2007/12/27 20:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rionix
[2008/08/09 15:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/01/22 15:33:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpecialBit
[2008/05/25 14:50:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/01/26 11:19:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTopV1005
[2008/03/09 14:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SugarGames
[2010/04/26 20:24:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca
[2008/08/08 10:23:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TheRace_dev
[2007/01/26 17:33:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/01/23 14:07:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Valusoft
[2007/08/28 16:34:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2010/07/03 21:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/06 23:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/01/03 04:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\SampleView
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/01/03 04:17:10 | 000,000,104 | ---- | M] () -- C:\.lnk
[2004/11/09 20:20:04 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007/04/13 01:49:56 | 000,000,213 | RHS- | M] () -- C:\BOOT.BAK
[2012/02/02 18:15:26 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/02/26 00:01:38 | 000,000,076 | ---- | M] () -- C:\Catalog.LiveSubscribe
[2004/08/04 12:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2012/02/03 00:17:58 | 000,919,903 | ---- | M] () -- C:\ComboFix.txt
[2004/11/09 20:20:04 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/04/03 00:00:19 | 000,000,000 | ---- | M] () -- C:\conmgr.log
[2007/07/18 19:13:55 | 000,000,093 | ---- | M] () -- C:\DownloadLog.txt
[2008/04/07 16:41:29 | 000,003,532 | ---- | M] () -- C:\drmHeader.bin
[2011/03/02 09:39:02 | 001,228,854 | ---- | M] () -- C:\fsqwr.bmp
[2012/02/03 17:22:52 | 1073,074,176 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/12 21:46:34 | 000,304,152 | ---- | M] () -- C:\img2-001.raw
[2007/07/28 18:46:28 | 000,230,424 | ---- | M] () -- C:\img2-002.raw
[2007/07/27 20:45:48 | 000,230,424 | ---- | M] () -- C:\img2-004.raw
[2004/11/09 20:20:04 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/02/24 14:53:44 | 000,000,139 | ---- | M] () -- C:\ioSpecial.ini
[2007/04/12 22:28:21 | 000,000,979 | ---- | M] () -- C:\IPH.PH
[2008/10/15 17:18:15 | 000,401,280 | ---- | M] () -- C:\logfile
[2011/04/03 07:54:20 | 000,001,111 | ---- | M] () -- C:\lxcz.log
[2004/11/09 20:20:04 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/09/04 00:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
[2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/09/26 21:55:20 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/02/03 06:55:28 | 000,136,918 | ---- | M] () -- C:\OTL.Txt
[2012/02/03 17:22:50 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2008/04/07 15:29:44 | 000,104,550 | ---- | M] () -- C:\playground.log
[2012/02/02 18:42:02 | 000,000,359 | ---- | M] () -- C:\rkill.log
[2008/08/11 23:06:48 | 000,000,268 | ---- | M] () -- C:\sqmdata00.sqm
[2008/08/12 12:50:00 | 000,000,268 | ---- | M] () -- C:\sqmdata01.sqm
[2008/08/20 13:06:53 | 000,000,268 | ---- | M] () -- C:\sqmdata02.sqm
[2008/08/20 17:46:32 | 000,000,268 | ---- | M] () -- C:\sqmdata03.sqm
[2008/08/29 13:35:29 | 000,000,268 | ---- | M] () -- C:\sqmdata04.sqm
[2008/08/30 22:50:48 | 000,000,268 | ---- | M] () -- C:\sqmdata05.sqm
[2008/09/01 11:15:28 | 000,000,268 | ---- | M] () -- C:\sqmdata06.sqm
[2008/10/01 16:34:46 | 000,000,268 | ---- | M] () -- C:\sqmdata07.sqm
[2008/09/18 14:58:37 | 000,000,268 | ---- | M] () -- C:\sqmdata08.sqm
[2008/09/14 23:46:24 | 000,000,268 | ---- | M] () -- C:\sqmdata09.sqm
[2008/10/20 13:55:22 | 000,000,268 | ---- | M] () -- C:\sqmdata10.sqm
[2008/05/16 16:41:23 | 000,000,268 | ---- | M] () -- C:\sqmdata11.sqm
[2008/06/03 11:33:00 | 000,000,268 | ---- | M] () -- C:\sqmdata12.sqm
[2008/06/12 21:00:09 | 000,000,268 | ---- | M] () -- C:\sqmdata13.sqm
[2008/06/15 22:34:06 | 000,000,268 | ---- | M] () -- C:\sqmdata14.sqm
[2008/06/18 23:29:41 | 000,000,268 | ---- | M] () -- C:\sqmdata15.sqm
[2008/06/19 10:14:40 | 000,000,268 | ---- | M] () -- C:\sqmdata16.sqm
[2008/07/10 02:06:56 | 000,000,268 | ---- | M] () -- C:\sqmdata17.sqm
[2008/08/02 07:17:38 | 000,000,268 | ---- | M] () -- C:\sqmdata18.sqm
[2008/08/11 17:48:26 | 000,000,268 | ---- | M] () -- C:\sqmdata19.sqm
[2008/08/11 23:06:48 | 000,000,244 | ---- | M] () -- C:\sqmnoopt00.sqm
[2008/08/12 12:50:00 | 000,000,244 | ---- | M] () -- C:\sqmnoopt01.sqm
[2008/08/20 13:06:53 | 000,000,244 | ---- | M] () -- C:\sqmnoopt02.sqm
[2008/08/20 17:46:32 | 000,000,244 | ---- | M] () -- C:\sqmnoopt03.sqm
[2008/08/29 13:35:29 | 000,000,244 | ---- | M] () -- C:\sqmnoopt04.sqm
[2008/08/30 22:50:48 | 000,000,244 | ---- | M] () -- C:\sqmnoopt05.sqm
[2008/09/01 11:15:28 | 000,000,244 | ---- | M] () -- C:\sqmnoopt06.sqm
[2008/10/01 16:34:45 | 000,000,244 | ---- | M] () -- C:\sqmnoopt07.sqm
[2008/09/18 14:58:37 | 000,000,244 | ---- | M] () -- C:\sqmnoopt08.sqm
[2008/09/14 23:46:24 | 000,000,244 | ---- | M] () -- C:\sqmnoopt09.sqm
[2008/10/20 13:55:22 | 000,000,244 | ---- | M] () -- C:\sqmnoopt10.sqm
[2008/05/16 16:41:23 | 000,000,244 | ---- | M] () -- C:\sqmnoopt11.sqm
[2008/06/03 11:33:00 | 000,000,244 | ---- | M] () -- C:\sqmnoopt12.sqm
[2008/06/12 21:00:09 | 000,000,244 | ---- | M] () -- C:\sqmnoopt13.sqm
[2008/06/15 22:34:06 | 000,000,244 | ---- | M] () -- C:\sqmnoopt14.sqm
[2008/06/18 23:29:41 | 000,000,244 | ---- | M] () -- C:\sqmnoopt15.sqm
[2008/06/19 10:14:40 | 000,000,244 | ---- | M] () -- C:\sqmnoopt16.sqm
[2008/07/10 02:06:56 | 000,000,244 | ---- | M] () -- C:\sqmnoopt17.sqm
[2008/08/02 07:17:38 | 000,000,244 | ---- | M] () -- C:\sqmnoopt18.sqm
[2008/08/11 17:48:25 | 000,000,244 | ---- | M] () -- C:\sqmnoopt19.sqm
[2012/01/15 20:30:03 | 000,058,506 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_20.26.20_log.txt
[2012/01/15 20:52:21 | 000,059,492 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_20.48.06_log.txt
[2012/01/15 21:00:11 | 000,058,376 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_20.59.41_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2005/05/12 06:36:48 | 000,012,288 | ---- | M] (Hewlett-Packard Co.) -- C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2004/11/09 20:19:36 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/10/21 14:29:40 | 000,320,512 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp101.dll
[2008/07/06 10:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2007/07/28 17:53:11 | 000,001,698 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2007/05/12 13:59:02 | 000,774,144 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2008/02/26 18:32:44 | 000,000,000 | ---- | M] () -- C:\Program Files\temp01
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/11/09 20:10:20 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2004/11/09 20:10:20 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004/11/09 20:10:20 | 000,897,024 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/26 22:01:52 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/13 01:53:27 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/11/09 20:23:22 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/01/31 19:01:14 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\HP_Owner\Desktop\aswMBR.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Documents and Settings\HP_Owner\Desktop\boot_cleaner.exe
[2012/02/02 19:14:24 | 004,393,886 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2012/02/02 00:07:12 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\jww.exe
[2012/02/01 18:51:02 | 000,303,059 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\ListParts.exe
[2012/02/01 23:17:16 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Norton_Removal_Tool.exe
[2012/02/03 17:33:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2012/01/30 18:29:50 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\snsi9chm.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2003/01/17 16:35:40 | 000,013,023 | ---- | M] () -- C:\WINDOWS\snpstd2.src
[2004/02/27 15:36:18 | 000,013,023 | ---- | M] () -- C:\WINDOWS\snpstd3.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2007/11/03 13:03:59 | 051,422,520 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\HP_Owner\My Documents\iTunes743Setup.exe
[2007/05/21 13:27:29 | 004,301,387 | ---- | M] (Shareaza Development Team ) -- C:\Documents and Settings\HP_Owner\My Documents\Shareaza_2.2.5.0.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/04 12:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\ADDINS\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2007/04/13 01:53:26 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010/08/13 01:22:34 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Cookies\desktop.ini
[2012/02/03 17:31:01 | 000,835,584 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007/06/26 21:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008/04/14 00:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2004/08/04 07:06:34 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
[2004/08/04 07:06:34 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2008/05/02 14:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2008/04/13 17:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/04/14 00:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2004/08/04 07:06:36 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2004/08/04 07:06:36 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2004/08/04 07:06:36 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2004/08/04 07:06:36 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2004/08/04 07:06:36 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
[1998/05/07 16:04:38 | 000,052,736 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system\hpsysdrv.exe
[1999/09/10 12:06:00 | 000,004,672 | ---- | M] (Adaptec) -- C:\WINDOWS\system\WOWPOST.EXE
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >