yea it ran
hi crunch, that one seemed to run fine. here are the logs...
OTL logfile created on: 27/10/2010 8:34:19 PM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\Brian & Kim\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.91 Gb Total Space | 43.21 Gb Free Space | 77.30% Space Free | Partition Type: NTFS
Drive D: | 19.14 Gb Total Space | 12.95 Gb Free Space | 67.69% Space Free | Partition Type: NTFS
Drive H: | 446.77 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive I: | 930.86 Gb Total Space | 888.53 Gb Free Space | 95.45% Space Free | Partition Type: NTFS
Computer Name: OFFICE | User Name: Brian & Kim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/10/27 20:31:24 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brian & Kim\Desktop\OTL.exe
PRC - [2010/02/26 08:58:40 | 000,110,592 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2009/06/16 08:58:08 | 000,020,480 | ---- | M] (Memeo) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
PRC - [2009/02/14 16:29:14 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/22 01:35:52 | 000,103,808 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
========== Modules (SafeList) ==========
MOD - [2010/10/27 20:31:24 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brian & Kim\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\ComboFix\PEV.cfx -- (PEVSystemStart)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010/10/23 16:46:24 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/04/01 13:33:19 | 000,267,432 | ---- | M] (Avira GmbH) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/02/26 08:58:40 | 000,110,592 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV - [2010/02/24 10:28:09 | 000,135,336 | ---- | M] (Avira GmbH) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009/06/16 08:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
SRV - [2009/02/14 16:29:14 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2008/01/22 01:35:52 | 000,103,808 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2007/06/29 20:16:56 | 000,800,040 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Nero 7\Nero BackItUp\NBService.exe -- (NBService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys -- (pccsmcfd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ivusb.sys -- (ivusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTSBLFX.DLL -- (CTSBLFX.DLL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTERFXFX.DLL -- (CTERFXFX.DLL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTAUDFX.DLL -- (CTAUDFX.DLL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\COMMONFX.DLL -- (COMMONFX.DLL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\BRIAN&~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/08/04 14:41:04 | 000,006,656 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\iPodDrv.sys -- (iPodDrv)
DRV - [2010/03/01 10:05:24 | 000,124,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/02/16 14:24:01 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/10/27 12:02:14 | 000,023,936 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem)
DRV - [2009/07/08 10:12:06 | 000,106,240 | R--- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hwmob01.sys -- (hwmobilehsn)
DRV - [2009/06/23 13:38:26 | 000,189,464 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\haP17v2k.sys -- (hap17v2k)
DRV - [2009/06/23 13:38:16 | 000,162,840 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\haP16v2k.sys -- (hap16v2k)
DRV - [2009/06/23 13:38:06 | 000,798,744 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha10kx2k.sys -- (ha10kx2k)
DRV - [2009/06/23 13:37:54 | 000,092,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)
DRV - [2009/06/23 13:37:32 | 000,157,208 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2009/06/23 13:37:22 | 000,014,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2009/06/23 13:37:10 | 000,127,512 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2009/06/23 13:36:36 | 000,347,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2009/06/23 13:36:24 | 000,528,408 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2009/06/23 13:36:14 | 000,511,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2009/06/23 13:35:04 | 000,100,888 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\CTERFXFX.SYS -- (CTERFXFX.SYS)
DRV - [2009/06/23 13:35:04 | 000,100,888 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTERFXFX.sys -- (CTERFXFX)
DRV - [2009/06/23 13:34:52 | 000,566,296 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CTSBLFX.SYS -- (CTSBLFX.SYS)
DRV - [2009/06/23 13:34:52 | 000,566,296 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTSBLFX.sys -- (CTSBLFX)
DRV - [2009/06/23 13:34:40 | 000,555,032 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CTAUDFX.SYS -- (CTAUDFX.SYS)
DRV - [2009/06/23 13:34:40 | 000,555,032 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTAUDFX.sys -- (CTAUDFX)
DRV - [2009/06/23 13:34:30 | 000,099,352 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\COMMONFX.SYS -- (COMMONFX.SYS)
DRV - [2009/06/23 13:34:30 | 000,099,352 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COMMONFX.sys -- (COMMONFX)
DRV - [2009/05/18 10:42:12 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/05/11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/05/11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/02/13 11:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2008/04/13 10:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/04/12 08:10:26 | 000,164,608 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CT20XUT.DLL -- (CT20XUT.DLL)
DRV - [2007/04/12 08:10:26 | 000,066,816 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTHWIUT.DLL -- (CTHWIUT.DLL)
DRV - [2007/04/12 08:10:24 | 001,317,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEXFIFX.DLL -- (CTEXFIFX.DLL)
DRV - [2007/04/12 08:10:22 | 000,323,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEDSPSY.DLL -- (CTEDSPSY.DLL)
DRV - [2007/04/12 08:10:22 | 000,128,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEDSPIO.DLL -- (CTEDSPIO.DLL)
DRV - [2007/04/12 08:10:20 | 000,280,320 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEDSPFX.DLL -- (CTEDSPFX.DLL)
DRV - [2007/04/12 08:10:18 | 000,168,192 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CTEAPSFX.DLL -- (CTEAPSFX.DLL)
DRV - [2006/02/21 21:46:26 | 001,505,792 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/10/15 12:50:20 | 000,015,295 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)
DRV - [2004/06/03 11:40:46 | 000,079,360 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvatabus.sys -- (nvatabus)
DRV - [2004/04/02 16:40:00 | 000,021,760 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2004/01/29 02:45:50 | 000,093,764 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENET.sys -- (NVENET)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems:
linkfilter@kaspersky.ru:9.0.0.736
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/21 16:36:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/21 16:36:39 | 000,000,000 | ---D | M]
[2010/10/16 23:18:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\Mozilla\Extensions
[2010/10/26 23:07:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\Mozilla\Firefox\Profiles\rba2lgg0.default\extensions
[2010/10/16 23:23:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Brian & Kim\Application Data\Mozilla\Firefox\Profiles\rba2lgg0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/26 23:07:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/03/13 11:20:25 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
O1 HOSTS File: ([2010/10/26 18:33:30 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 64.59.160.13 64.59.160.15 64.59.161.68
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/18 14:12:18 | 000,000,088 | R--- | M] () - H:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/10/27 20:31:22 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Brian & Kim\Desktop\OTL.exe
[2010/10/27 17:17:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/10/27 17:17:28 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/10/27 17:17:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/10/27 17:17:28 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/10/27 17:17:21 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010/10/26 22:18:11 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Brian & Kim\Recent
[2010/10/26 21:23:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\Desktop\logs
[2010/10/26 21:19:39 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/10/26 17:35:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/10/26 17:35:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/10/25 19:47:06 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Brian & Kim\Desktop\TFC.exe
[2010/10/25 01:57:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\peernet
[2010/10/23 22:04:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2010/10/23 22:03:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\Application Data\Avira
[2010/10/23 21:58:19 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/10/23 21:58:18 | 000,124,784 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/10/23 21:58:18 | 000,060,936 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/10/23 21:58:18 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/10/23 21:58:18 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/10/23 21:58:18 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2010/10/23 21:58:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2010/10/23 16:46:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Creative Labs Shared
[2010/10/23 00:58:17 | 000,106,240 | R--- | C] (QUALCOMM Incorporated) -- C:\WINDOWS\System32\drivers\hwmob01.sys
[2010/10/21 17:35:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\My Documents\Subscriptions
[2010/10/21 17:31:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\doubleTwist_Corporation
[2010/10/21 17:22:06 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/10/21 17:15:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\doubleTwist Corporation
[2010/10/21 17:14:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\doubleTwist
[2010/10/21 17:14:55 | 000,060,273 | ---- | C] (Open Source Software community project) -- C:\WINDOWS\System32\pthreadGC2.dll
[2010/10/21 17:14:55 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2010/10/21 17:14:16 | 000,000,000 | ---D | C] -- C:\Program Files\doubleTwist 2.0
[2010/10/21 17:13:01 | 000,000,000 | ---D | C] -- C:\PC Suite
[2010/10/17 17:26:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2010/10/16 23:18:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\Application Data\Mozilla
[2010/10/16 22:02:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Samsung_USB_Drivers
[2010/10/16 22:02:36 | 000,233,472 | ---- | C] (Teruten) -- C:\WINDOWS\System32\FsUsbExService.Exe
[2010/10/16 22:02:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\My Documents\My NPS Files
[2010/10/16 18:55:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/10/16 18:55:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brian & Kim\Application Data\PC Suite
[2010/10/16 18:53:02 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2010/10/16 18:52:47 | 000,090,624 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcls.dll
[2010/10/16 18:51:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Installations
[2010/10/12 22:20:31 | 000,023,936 | ---- | C] (Motorola) -- C:\WINDOWS\System32\drivers\motmodem.sys
[2010/10/12 22:07:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motorola Shared
[2010/10/12 22:07:14 | 000,000,000 | ---D | C] -- C:\Program Files\Motorola
[2010/10/12 22:06:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/10/03 17:28:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/06/23 11:49:14 | 000,010,752 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
========== Files - Modified Within 30 Days ==========
[2010/10/27 20:35:57 | 000,762,880 | ---- | M] () -- C:\WINDOWS\System32\drivers\ucwfs.sys
[2010/10/27 20:31:24 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brian & Kim\Desktop\OTL.exe
[2010/10/27 19:33:21 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/10/27 19:32:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/27 17:14:21 | 000,030,120 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/27 17:14:21 | 000,030,120 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/27 17:14:21 | 000,027,408 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/27 17:14:21 | 000,027,408 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/27 17:14:21 | 000,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/27 17:01:25 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010/10/26 18:33:30 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/26 17:26:44 | 003,886,890 | R--- | M] () -- C:\Documents and Settings\Brian & Kim\Desktop\ComboFix.exe
[2010/10/26 15:36:39 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Xriqecofe.dat
[2010/10/26 00:00:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Dmoqupavidifexe.bin
[2010/10/25 22:16:10 | 000,079,872 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010/10/25 20:37:04 | 000,545,280 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Desktop\dds.scr
[2010/10/25 20:14:31 | 000,294,912 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Desktop\9im9j18e.exe
[2010/10/25 19:47:06 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brian & Kim\Desktop\TFC.exe
[2010/10/25 01:34:47 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Application Data\install
[2010/10/24 23:38:52 | 003,162,278 | ---- | M] () -- C:\WINDOWS\{00000001-00000000-00000009-00001102-00000004-00511102}.CDF
[2010/10/24 23:22:26 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/24 17:33:11 | 000,017,745 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\My Documents\A wild night.docx
[2010/10/23 21:58:34 | 000,001,741 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/10/23 16:45:34 | 000,444,952 | ---- | M] (Creative Labs) -- C:\WINDOWS\System32\wrap_oal.dll
[2010/10/23 01:24:26 | 000,000,160 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\default.pls
[2010/10/23 01:24:21 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/10/21 22:32:51 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/21 17:31:25 | 000,000,127 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/10/21 17:14:57 | 000,001,780 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Application Data\Microsoft\Internet Explorer\Quick Launch\doubleTwist.lnk
[2010/10/21 17:14:57 | 000,001,762 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\doubleTwist.lnk
[2010/10/21 17:13:14 | 000,000,556 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PC Suite.lnk
[2010/10/21 16:38:55 | 000,000,426 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[2010/10/19 15:31:35 | 000,435,568 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/19 15:31:35 | 000,068,272 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/10/18 18:56:35 | 000,012,708 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\My Documents\French project paragraphs.docx
[2010/10/17 22:51:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\housecall.guid.cache
[2010/10/16 23:18:12 | 000,001,654 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/16 23:18:12 | 000,001,636 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/16 22:02:18 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Brian & Kim\Application Data\$_hpcst$.hpc
[2010/10/15 16:51:40 | 000,000,074 | ---- | M] () -- C:\WINDOWS\ImportClient.INI
[2010/10/12 22:25:04 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motmodem_01007.Wdf
[2010/10/12 22:25:03 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
========== Files Created - No Company Name ==========
[2010/10/27 17:17:28 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/10/27 17:17:28 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/10/27 17:17:28 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/10/27 17:17:28 | 000,079,872 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/10/27 17:17:28 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/10/26 17:26:43 | 003,886,890 | R--- | C] () -- C:\Documents and Settings\Brian & Kim\Desktop\ComboFix.exe
[2010/10/25 20:37:04 | 000,545,280 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Desktop\dds.scr
[2010/10/25 20:14:30 | 000,294,912 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Desktop\9im9j18e.exe
[2010/10/25 01:34:47 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Application Data\install
[2010/10/24 23:24:58 | 000,762,880 | ---- | C] () -- C:\WINDOWS\System32\drivers\ucwfs.sys
[2010/10/24 17:13:18 | 000,017,745 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\My Documents\A wild night.docx
[2010/10/23 21:58:34 | 000,001,741 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/10/23 16:47:58 | 000,027,408 | ---- | C] () -- C:\WINDOWS\System32\BMXCtrlState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/23 16:47:58 | 000,027,408 | ---- | C] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/23 16:47:58 | 000,011,564 | ---- | C] () -- C:\WINDOWS\System32\DVCState-{00000001-00000000-00000009-00001102-00000004-00511102}.rfx
[2010/10/23 16:45:47 | 003,162,278 | ---- | C] () -- C:\WINDOWS\{00000001-00000000-00000009-00001102-00000004-00511102}.CDF
[2010/10/21 21:53:20 | 000,245,328 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/10/21 17:31:25 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/10/21 17:14:57 | 000,001,780 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Application Data\Microsoft\Internet Explorer\Quick Launch\doubleTwist.lnk
[2010/10/21 17:14:57 | 000,001,762 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\doubleTwist.lnk
[2010/10/21 17:14:56 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/10/21 17:13:14 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PC Suite.lnk
[2010/10/18 18:50:47 | 000,012,708 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\My Documents\French project paragraphs.docx
[2010/10/17 22:51:12 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\housecall.guid.cache
[2010/10/16 23:18:12 | 000,001,654 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/16 23:18:12 | 000,001,636 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/16 22:02:36 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/10/16 22:02:36 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/10/16 22:02:18 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Application Data\$_hpcst$.hpc
[2010/10/12 22:25:04 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motmodem_01007.Wdf
[2010/10/12 22:25:03 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/05/01 18:14:39 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/05/01 18:11:23 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2010/05/01 18:09:19 | 000,031,567 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/03/14 13:27:12 | 000,000,074 | ---- | C] () -- C:\WINDOWS\ImportClient.INI
[2010/03/14 13:10:37 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\PretzelSpellCheck.dll
[2010/03/14 13:10:36 | 000,745,472 | ---- | C] () -- C:\WINDOWS\System32\PMAppBuilder.dll
[2010/03/14 13:10:36 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\PMovieServer.dll
[2010/03/13 16:16:14 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/03/13 13:09:27 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\Brian & Kim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/13 12:36:18 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2010/03/12 11:34:28 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/23 12:29:50 | 000,049,719 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2009/06/23 12:29:48 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2009/06/23 11:51:00 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/08/13 20:45:02 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll
[2007/04/12 09:10:28 | 000,105,728 | ---- | C] () -- C:\WINDOWS\System32\APOMgrH.dll
[2006/10/02 17:25:18 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\kill.ini
========== LOP Check ==========
[2010/10/21 17:17:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/03/13 12:44:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/03/13 12:53:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2010/09/13 16:23:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010/03/13 12:53:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenu
[2010/10/16 18:51:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2010/10/16 18:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/10/17 17:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2010/05/02 11:35:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/10/25 02:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/12 20:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Western Digital
[2010/03/18 16:37:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\Hoyle FaceCreator
[2010/10/26 16:14:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\Hoyle Puzzle and Board Games
[2010/10/16 18:55:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\PC Suite
[2010/10/16 21:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\uTorrent
[2010/03/17 16:45:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\Western Digital
[2010/03/17 16:45:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brian & Kim\Application Data\Western DigitalTemp
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 02:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/03/13 02:06:24 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/03/13 02:06:24 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 02:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/03/13 02:06:24 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/03/13 02:06:24 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\Qoobox\32788R22FWJFW\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATABUS.SYS >
[2004/06/03 11:40:46 | 000,079,360 | ---- | M] (NVIDIA Corporation) MD5=46DEED4C6C5FA765F9A2C723BE60348D -- C:\Qoobox\32788R22FWJFW\nvatabus.sys
[2004/06/03 11:40:46 | 000,079,360 | ---- | M] (NVIDIA Corporation) MD5=46DEED4C6C5FA765F9A2C723BE60348D -- C:\WINDOWS\system32\drivers\nvatabus.sys
< MD5 for: SCECLI.DLL >
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 05:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 05:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
< %systemroot%\System32\config\*.sav >
[2010/03/12 11:32:29 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010/03/12 11:32:29 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010/03/12 11:32:29 | 000,425,984 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

FC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >