OTL logfile created on: 6/8/2011 4:31:01 PM - Run
OTLPE by OldTimer - Version 3.1.46.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.00 Mb Total Physical Memory | 740.00 Mb Available Physical Memory | 77.00% Memory free
859.00 Mb Paging File | 770.00 Mb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.54 Gb Total Space | 157.37 Gb Free Space | 70.09% Space Free | Partition Type: NTFS
Drive H: | 8.33 Gb Total Space | 0.36 Gb Free Space | 4.30% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet002
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto] -- -- (Viewpoint Manager Service)
SRV - File not found [Disabled] -- -- (HidServ)
SRV - [2010/09/07 11:11:59 | 000,040,384 | -H-- | M] (AVAST Software) [On_Demand] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 11:11:59 | 000,040,384 | -H-- | M] (AVAST Software) [On_Demand] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 11:11:59 | 000,040,384 | -H-- | M] (AVAST Software) [Auto] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2009/10/27 07:19:46 | 000,895,696 | -H-- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/09/16 07:23:32 | 000,365,072 | -H-- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2009/09/16 06:22:08 | 000,144,704 | -H-- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2009/09/16 05:28:38 | 000,606,736 | -H-- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/07/09 20:26:20 | 000,865,832 | -H-- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/07/08 07:54:34 | 000,359,952 | -H-- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 15:10:02 | 002,482,848 | -H-- | M] (McAfee, Inc.) [Auto] -- C:\program files\common files\mcafee\mna\mcnasvc.exe -- (McNASvc)
SRV - [2008/02/02 05:34:50 | 001,251,720 | -H-- | M] () [Auto] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2006/07/25 20:03:42 | 002,119,360 | -H-- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate)
SRV - [2006/07/25 20:03:42 | 000,100,032 | -H-- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2006/03/30 10:15:44 | 000,096,341 | -H-- | M] (Canon Inc.) [Auto] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2006/03/03 17:03:10 | 000,069,632 | -H-- | M] (HP) [Auto] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2005/08/03 02:19:16 | 000,058,880 | -H-- | M] (Microsoft) [Auto] -- C:\WINDOWS\arservice.exe -- (ARSVC)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (kbiwkmmlthritq)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | Boot] -- -- (ftsata2)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2010/09/07 10:52:25 | 000,046,672 | -H-- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 10:52:03 | 000,165,584 | -H-- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 10:47:46 | 000,023,376 | -H-- | M] (AVAST Software) [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 10:47:19 | 000,100,176 | -H-- | M] (AVAST Software) [File_System | Auto] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 10:47:07 | 000,017,744 | -H-- | M] (AVAST Software) [File_System | Auto] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 10:46:51 | 000,028,880 | -H-- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/09/16 06:22:48 | 000,214,664 | -H-- | M] (McAfee, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/09/16 06:22:48 | 000,079,816 | -H-- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2009/09/16 06:22:48 | 000,040,552 | -H-- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/09/16 06:22:48 | 000,035,272 | -H-- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/09/16 06:22:14 | 000,034,248 | -H-- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/08/17 12:08:37 | 000,054,784 | ---- | M] () [Kernel | System] -- C:\WINDOWS\system32\drivers\UACexvaprniqe.sys -- (UACd.sys)
DRV - [2009/07/16 08:32:26 | 000,120,136 | -H-- | M] (McAfee, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)
DRV - [2007/02/06 05:00:00 | 000,383,800 | -H-- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2007/01/15 01:42:58 | 000,008,413 | -H-- | M] (RealNetworks, Inc.) [Kernel | Auto] -- C:\WINDOWS\System32\drivers\mcstrm.sys -- (MCSTRM)
DRV - [2006/08/08 05:46:59 | 000,010,344 | -H-- | M] (Symantec Corporation) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
DRV - [2006/06/14 14:04:12 | 004,299,264 | -H-- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/04/05 00:58:44 | 001,536,000 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/02/27 08:46:20 | 000,081,408 | -H-- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005/12/12 20:27:00 | 000,019,072 | -H-- | M] (Hewlett-Packard Company) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
DRV - [2005/12/06 14:20:50 | 000,241,664 | -H-- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2005/12/06 14:20:40 | 000,936,448 | -H-- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSX_DP.sys -- (HSX_DP)
DRV - [2004/08/03 17:31:34 | 000,020,992 | -H-- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
IE - HKU\.DEFAULT\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
IE - HKU\Administrator_ON_C\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Compaq_Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
IE - HKU\Compaq_Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\Compaq_Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\Compaq_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Compaq_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKU\Compaq_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/04/29 14:17:21 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Components: C:\Program Files\Netscape\Netscape Browser\Components [2011/04/22 11:42:44 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Plugins: C:\Program Files\Netscape\Netscape Browser\Plugins [2010/04/29 11:42:26 | 000,000,000 | -H-D | M]
O1 HOSTS File: ([2004/08/10 07:00:00 | 000,000,734 | -H-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\Compaq_Administrator_ON_C\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\Compaq_Administrator_ON_C\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AlwaysReady Power Message APP] C:\WINDOWS\arpwrmsg.exe (Microsoft)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ftutil2] C:\WINDOWS\System32\ftutil2.dll (Promise Technology, Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [minix32] File not found
O4 - HKU\Compaq_Administrator_ON_C..\Run: [Getdo] C:\Documents and Settings\Compaq_Administrator\Application Data\Adobe\Update\flacor.dat ()
O4 - HKU\Compaq_Administrator_ON_C..\Run: [Helper] C:\Documents and Settings\Compaq_Administrator\Application Data\Helper\bin\liveu.exe ()
O4 - HKU\Compaq_Administrator_ON_C..\Run: [kqAIrvwyxLeS] C:\Documents and Settings\All Users\Application Data\kqAIrvwyxLeS.exe (eSafe)
O4 - HKU\Compaq_Administrator_ON_C..\Run: [Monopod] File not found
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\PinMcLnk.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Compaq_Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Compaq_Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - File not found
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://www1.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134}
http://lads.myspace.com/upload/MySpaceUploader.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/31 00:02:02 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: ipcoll32 - (C:\WINDOWS\system32\mspaclip.dll) - C:\WINDOWS\system32\mspaclip.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/08 11:16:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Compaq_Administrator\Recent
[2011/06/08 11:03:33 | 127,222,215 | -H-- | C] (Igor Pavlov) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTLPENet.exe
[2011/06/07 18:24:30 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Application Data\Macromedia
[2011/06/07 18:20:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\malwarebytes
[2011/06/07 18:20:16 | 000,000,000 | -H-D | C] -- C:\Program Files\Malwarebytes
[2011/06/07 18:14:35 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2011/06/06 16:59:18 | 000,000,000 | -H-D | C] -- C:\Program Files\Mal
[2011/06/06 16:57:28 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Compaq_Administrator\Application Data\ElevatedDiagnostics
[2011/06/06 16:56:23 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2011/06/06 16:54:29 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\windowspowershell
[2011/06/06 10:52:14 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\PrivacIE
[2011/06/06 10:49:04 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\IETldCache
[2011/06/05 10:24:05 | 000,039,984 | -H-- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/05 10:24:04 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/06/05 10:24:00 | 000,022,712 | -H-- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/06/05 10:22:46 | 009,435,312 | -H-- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Compaq_Administrator\Desktop\chad.com.exe
[2011/06/05 10:16:59 | 000,000,000 | -H-D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/05 10:13:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Compaq_Administrator\Desktop\gmer
[2011/06/05 10:12:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Desktop
[2011/06/05 09:38:08 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Administrative Tools
[2011/06/05 09:37:19 | 000,607,222 | RH-- | C] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr
[2011/06/05 09:28:46 | 001,431,344 | -H-- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Compaq_Administrator\Desktop\away.com.exe
[2011/06/04 11:35:40 | 001,431,344 | -H-- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Compaq_Administrator\Desktop\vaway.com.exe
[2011/06/02 17:12:01 | 000,465,408 | -H-- | C] (eSafe) -- C:\Documents and Settings\All Users\Application Data\kqAIrvwyxLeS.exe
[2011/06/02 12:02:44 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Windows XP Recovery
[2011/05/11 12:26:45 | 006,600,192 | -H-- | C] (Mirage Systems) -- C:\WINDOWS\System32\licprotector310.exe
[2011/05/11 12:26:45 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Free File Opener
[2011/05/11 12:26:41 | 000,000,000 | -H-D | C] -- C:\Program Files\Free File Opener
[2011/05/11 12:26:41 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Free File Opener
[2006/02/19 13:28:56 | 000,012,288 | -H-- | C] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/08 11:17:15 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/08 11:03:33 | 127,222,215 | -H-- | M] (Igor Pavlov) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTLPENet.exe
[2011/06/08 11:00:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2011/06/08 11:00:00 | 000,000,270 | -H-- | M] () -- C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2011/06/08 10:55:29 | 000,001,158 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/08 10:52:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\malwarebytes
[2011/06/08 10:52:16 | 1006,030,848 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/07 19:52:07 | 000,000,186 | -H-- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2011/06/07 19:46:22 | 001,007,120 | -H-- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\iExplore.exe
[2011/06/07 18:20:21 | 000,000,694 | -H-- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/06 16:51:02 | 009,435,312 | -H-- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Compaq_Administrator\Desktop\chad.com.exe
[2011/06/06 12:02:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2011/06/05 10:12:50 | 000,293,977 | -H-- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\gmer.zip
[2011/06/05 09:37:23 | 000,607,222 | RH-- | M] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr
[2011/06/05 09:34:32 | 000,050,477 | -H-- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Defogger.exe
[2011/06/05 09:28:46 | 001,431,344 | -H-- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Compaq_Administrator\Desktop\away.com.exe
[2011/06/04 11:35:40 | 001,431,344 | -H-- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Compaq_Administrator\Desktop\vaway.com.exe
[2011/06/03 20:26:48 | 000,442,466 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/03 20:26:47 | 000,071,732 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/06/03 20:25:34 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/06/03 20:25:21 | 000,004,236 | -H-- | M] () -- C:\WINDOWS\imsins.BAK
[2011/06/03 20:24:33 | 000,000,823 | -H-- | M] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/02 17:12:33 | 000,116,224 | -H-- | M] () -- C:\WINDOWS\System32\drivers\11216E.sys
[2011/06/02 17:11:58 | 000,465,408 | -H-- | M] (eSafe) -- C:\Documents and Settings\All Users\Application Data\kqAIrvwyxLeS.exe
[2011/06/02 12:11:46 | 000,020,093 | -H-- | M] () -- C:\WINDOWS\System32\Config.MPF
[2011/06/02 12:09:21 | 000,000,152 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~26468132r
[2011/06/02 12:09:21 | 000,000,136 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~26468132
[2011/06/02 12:07:27 | 000,410,112 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\26468132.exe
[2011/06/02 12:02:48 | 000,000,807 | -H-- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Windows XP Recovery.lnk
[2011/06/02 12:02:29 | 000,000,344 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\26468132
[2011/06/02 12:02:22 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/06/02 12:02:22 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Digital Media Enhancements
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Winamp
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Try Microsoft Office for 60 days
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\TaxCut 2006
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Sonic
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Snapfish for your photos
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Rhapsody
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Quicken 2006
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC Help & Tools
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Online Services
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Netscape
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\My HP Games
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\HP
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Hot Deals
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Free File Opener
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVD Shrink
[2011/06/02 12:02:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/05/29 05:11:30 | 000,039,984 | -H-- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 05:11:20 | 000,022,712 | -H-- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/08 10:50:08 | 1006,030,848 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/07 18:20:21 | 000,000,694 | -H-- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/05 10:12:49 | 000,293,977 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\gmer.zip
[2011/06/05 09:34:32 | 000,050,477 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Defogger.exe
[2011/06/04 11:27:20 | 001,007,120 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\iExplore.exe
[2011/06/03 20:24:33 | 000,000,823 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/02 17:12:33 | 000,116,224 | -H-- | C] () -- C:\WINDOWS\System32\drivers\11216E.sys
[2011/06/02 12:09:21 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~26468132r
[2011/06/02 12:09:21 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~26468132
[2011/06/02 12:02:48 | 000,000,807 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Windows XP Recovery.lnk
[2011/06/02 12:02:29 | 000,000,344 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\26468132
[2011/06/02 12:02:23 | 000,410,112 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\26468132.exe
[2011/04/21 11:23:52 | 000,000,664 | -H-- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/10 16:34:10 | 000,047,104 | -H-- | C] () -- C:\WINDOWS\System32\mspaclip.dll
[2010/05/01 06:32:44 | 000,000,036 | -H-- | C] () -- C:\WINDOWS\rasqervy.dll
[2010/05/01 06:32:42 | 000,000,008 | -H-- | C] () -- C:\WINDOWS\sdfinacs.dll
[2010/05/01 06:32:41 | 000,000,004 | -H-- | C] () -- C:\WINDOWS\sdfixwcs.dll
[2010/05/01 05:07:33 | 000,000,168 | -H-- | C] () -- C:\WINDOWS\wuasirvy.dll
[2010/03/22 11:21:01 | 000,082,482 | -H-- | C] () -- C:\WINDOWS\msacm32.drv
[2009/08/18 16:21:48 | 000,016,969 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\ajukaqyni.bin
[2009/08/18 16:21:48 | 000,016,401 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\fozihow.lib
[2009/08/18 16:21:48 | 000,013,986 | -H-- | C] () -- C:\WINDOWS\gifitinab.sys
[2009/08/18 16:21:48 | 000,012,933 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\yzuju.bin
[2009/08/18 16:21:48 | 000,012,918 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\ukutirez.dat
[2009/08/18 16:21:48 | 000,012,335 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\fule.reg
[2009/08/18 16:21:48 | 000,011,780 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\zugezaxyz.db
[2009/08/18 16:21:48 | 000,011,473 | -H-- | C] () -- C:\WINDOWS\abane.exe
[2009/08/18 16:20:01 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\UACqyisuyipjd.dll
[2009/08/17 12:32:12 | 000,000,091 | -H-- | C] () -- C:\WINDOWS\System32\kbiwkmbltfmuij.dat
[2009/08/17 12:08:47 | 000,011,336 | ---- | C] () -- C:\WINDOWS\System32\uacinit.dll
[2009/08/17 12:08:47 | 000,000,269 | ---- | C] () -- C:\WINDOWS\System32\UACvrbfaswulk.dat
[2009/08/17 12:08:44 | 000,074,240 | ---- | C] () -- C:\WINDOWS\System32\UACrjkomqxewc.dll
[2009/08/17 12:08:37 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\UACexvaprniqe.sys
[2009/08/17 12:08:13 | 000,009,150 | -H-- | C] () -- C:\WINDOWS\System32\kbiwkmtxwvbtvx.dat
[2009/07/26 18:15:36 | 000,000,085 | -H-- | C] () -- C:\WINDOWS\System32\vsfoceamfragrh.dat
[2009/01/07 13:09:36 | 000,124,348 | -H-- | C] () -- C:\WINDOWS\HPHins12.dat
[2009/01/07 13:09:36 | 000,014,916 | -H-- | C] () -- C:\WINDOWS\hphmdl12.dat
[2008/10/18 19:32:46 | 000,019,681 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\duwe.lib
[2008/10/18 19:32:46 | 000,018,214 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\azyqukyren.inf
[2008/10/18 19:32:46 | 000,017,948 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\tutazaryf._sy
[2008/10/18 19:32:46 | 000,016,907 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\yvab.dat
[2008/10/18 19:32:46 | 000,014,703 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\akoq.dll
[2008/10/18 19:32:46 | 000,014,269 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\amuwipoj.sys
[2008/10/18 19:32:46 | 000,014,025 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\azerygy.ban
[2008/10/18 19:32:46 | 000,012,895 | -H-- | C] () -- C:\WINDOWS\amelycehe.com
[2008/10/18 19:32:46 | 000,012,320 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\ikuqunywiq.scr
[2008/10/18 19:32:46 | 000,012,189 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\aguka.ban
[2008/10/18 19:32:46 | 000,012,096 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\loxoco.inf
[2008/10/18 19:32:46 | 000,010,406 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\roduviri.bin
[2008/10/18 19:32:46 | 000,010,169 | -H-- | C] () -- C:\Program Files\Common Files\ozusi.dl
[2008/10/18 19:27:38 | 000,000,118 | -H-- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/10/18 19:13:36 | 000,003,896 | -H-- | C] () -- C:\WINDOWS\System32\TDSSlxwp.dll
[2008/10/18 19:13:32 | 000,000,164 | -H-- | C] () -- C:\WINDOWS\System32\TDSSorvd.dat
[2008/03/27 03:09:04 | 000,000,010 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\usb001
[2008/01/27 17:12:40 | 000,077,824 | RH-- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2007/12/30 08:10:44 | 000,012,800 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/06 03:44:03 | 000,000,854 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2007/05/15 22:53:58 | 000,002,287 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/02/28 04:48:23 | 000,001,755 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/21 21:07:07 | 000,000,107 | -H-- | C] () -- C:\WINDOWS\wpd99.drv
[2007/02/21 21:06:54 | 000,118,784 | -H-- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2007/02/21 21:06:54 | 000,051,716 | -H-- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2007/02/08 03:06:54 | 000,000,044 | -H-- | C] () -- C:\WINDOWS\liveup.ini
[2007/01/17 02:19:53 | 000,000,335 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2007/01/17 02:19:15 | 000,000,029 | -H-- | C] () -- C:\WINDOWS\atid.ini
[2007/01/14 23:41:04 | 000,000,143 | -H-- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\fusioncache.dat
[2006/08/08 06:03:01 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/08 05:34:55 | 000,028,848 | -H-- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2006/08/08 05:27:54 | 000,118,842 | RH-- | C] () -- C:\WINDOWS\HPCPCUninstaller-6.3.2.116-5577497.exe
[2006/08/08 05:27:14 | 000,667,896 | -H-- | C] () -- C:\WINDOWS\unins000.exe
[2006/08/08 05:27:14 | 000,001,235 | -H-- | C] () -- C:\WINDOWS\unins000.dat
[2006/08/08 05:27:05 | 000,012,988 | -H-- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2006/08/08 05:26:54 | 000,045,056 | -H-- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2006/08/08 05:23:36 | 000,000,174 | -H-- | C] () -- C:\WINDOWS\QUICKEN.INI
[2006/08/08 05:12:47 | 000,000,238 | -H-- | C] () -- C:\WINDOWS\WININIT.INI
[2006/08/08 05:11:23 | 000,045,929 | -H-- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/08/08 05:11:23 | 000,000,698 | -H-- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/08/08 05:06:15 | 000,095,822 | -H-- | C] () -- C:\WINDOWS\hpqins69.dat
[2006/08/08 05:05:15 | 000,001,793 | -H-- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/08/08 05:01:28 | 000,125,796 | -H-- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/08/08 04:59:50 | 000,000,791 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2006/08/08 04:39:53 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2006/08/08 04:36:38 | 000,323,584 | -H-- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2006/08/08 04:36:38 | 000,094,208 | -H-- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2006/08/08 04:36:17 | 000,016,896 | -H-- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2006/06/16 14:58:18 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/31 00:17:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/08/31 00:07:46 | 000,442,466 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/08/31 00:07:46 | 000,071,732 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/08/31 00:05:30 | 000,208,896 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/31 00:01:42 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/30 23:58:02 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/08/06 00:01:54 | 000,235,008 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 000,050,176 | -H-- | C] () -- C:\WINDOWS\armcex.dll
[2004/08/10 07:00:00 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 00:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 00:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 00:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 00:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 00:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 00:00:00 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/10 00:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/07/26 10:51:38 | 000,000,592 | -H-- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2002/09/04 00:48:27 | 000,001,024 | -H-- | C] () -- C:\WINDOWS\System32\atsdrve.dll
[2001/08/23 11:12:28 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 11:11:02 | 000,004,490 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
========== LOP Check ==========
[2011/06/06 16:57:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\ElevatedDiagnostics
[2008/03/13 22:43:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Leadertech
[2011/03/31 11:17:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\LimeWire
[2010/03/28 14:54:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Netscape
[2008/01/01 14:55:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Snapfish
[2007/12/06 03:44:05 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Template
[2009/08/18 14:46:57 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Uniblue
[2007/01/20 01:03:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Viewpoint
[2008/01/07 20:19:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\WildTangent
[2007/07/05 01:41:05 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\WinBatch
[2010/03/28 10:38:06 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2006/08/08 05:17:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2007/02/21 21:06:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\pdf995
[2010/01/30 07:31:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/01/07 20:19:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/04/29 11:45:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/14 21:00:00 | 000,000,380 | -H-- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2010/06/30 21:00:17 | 000,000,382 | -H-- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2011/06/08 11:00:00 | 000,000,270 | -H-- | M] () -- C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2011/06/08 11:00:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Compaq_Administrator\My Documents\me and micaela:SummaryInformation
< End of report >