(OTL results, pt. 2):
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.ctmp3 - C:\WINDOWS\system32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: VIDC.IV41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/25 19:15:51 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ann\Desktop\OTL.exe
[2012/05/24 21:32:06 | 000,000,000 | --SD | C] -- C:\yourname
[2012/05/22 12:22:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ann\Desktop\Debugging Files
[2012/05/20 02:52:11 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ann\Recent
[2012/05/20 01:24:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[2012/05/19 22:22:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2012/05/19 20:44:31 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/05/19 20:40:48 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/05/19 20:40:48 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/05/19 20:40:48 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/05/19 20:40:48 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/05/19 20:40:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/05/19 00:31:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ann\My Documents\Downloads
[2012/05/18 13:02:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/05/18 13:02:44 | 000,337,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/05/18 13:02:44 | 000,020,696 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/05/18 13:02:38 | 000,035,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/05/18 13:02:37 | 000,053,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/05/18 13:02:36 | 000,612,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/05/18 13:02:35 | 000,095,704 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/05/18 13:02:35 | 000,089,048 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/05/18 13:02:34 | 000,024,920 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/05/18 13:01:23 | 000,041,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/05/18 13:01:20 | 000,201,352 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/05/18 12:57:52 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/05/18 12:57:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/05/18 12:29:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Registry First Aid
[2012/05/16 23:04:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/05/03 16:03:01 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ann\My Documents\My Videos
[2012/05/02 10:51:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/05/02 10:49:11 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/05/02 10:49:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/05/02 10:38:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012/05/02 10:32:02 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012/05/01 23:49:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVD43
[2012/05/01 23:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\dvd43
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/25 19:15:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ann\Desktop\OTL.exe
[2012/05/25 18:11:42 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/25 18:08:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/25 18:08:04 | 267,460,608 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/25 18:07:53 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2012/05/25 18:07:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2012/05/24 01:21:57 | 000,000,328 | RHS- | M] () -- C:\boot.ini
[2012/05/23 22:05:14 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/05/23 10:57:11 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\Ann\Desktop\Microsoft Word.lnk
[2012/05/23 07:09:10 | 000,062,976 | ---- | M] () -- C:\Documents and Settings\Ann\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/22 13:00:43 | 000,039,732 | ---- | M] () -- C:\Documents and Settings\Ann\Application Data\wklnhst.dat
[2012/05/20 02:39:39 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/05/20 02:17:28 | 000,000,844 | ---- | M] () -- C:\WINDOWS\System32\.crusader
[2012/05/18 13:02:46 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/05/18 13:02:36 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/05/16 22:32:10 | 000,000,212 | ---- | M] () -- C:\Boot.bak
[2012/05/16 22:29:17 | 000,768,488 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/14 11:42:48 | 000,725,408 | ---- | M] () -- C:\Documents and Settings\Ann\My Documents\cc_20120514_114231.reg
[2012/05/02 10:51:55 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/04/30 10:23:06 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/20 23:46:33 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\Ann\Start Menu\Programs\MalwareBytes Anti-Malware.lnk
[2012/05/20 02:17:28 | 000,000,844 | ---- | C] () -- C:\WINDOWS\System32\.crusader
[2012/05/19 23:26:53 | 267,460,608 | -HS- | C] () -- C:\hiberfil.sys
[2012/05/19 20:44:38 | 000,000,212 | ---- | C] () -- C:\Boot.bak
[2012/05/19 20:44:33 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/05/19 20:40:48 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/05/19 20:40:48 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/05/19 20:40:48 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/05/19 20:40:48 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/05/19 20:40:48 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/05/19 01:47:36 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/05/18 13:02:46 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/05/14 11:42:39 | 000,725,408 | ---- | C] () -- C:\Documents and Settings\Ann\My Documents\cc_20120514_114231.reg
[2012/05/02 10:51:55 | 000,001,542 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/04/03 12:13:48 | 000,000,088 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\avbase.dat
[2012/02/14 23:15:20 | 000,000,034 | -H-- | C] () -- C:\WINDOWS\System32\DVDRipper_sysquict.dat
[2012/02/13 11:54:55 | 000,000,017 | -H-- | C] () -- C:\Documents and Settings\Ann\Application Data\mpdt294
[2012/02/13 11:54:45 | 000,000,383 | ---- | C] () -- C:\WINDOWS\mapedit2.ini
[2011/09/19 13:58:35 | 000,198,521 | ---- | C] () -- C:\Documents and Settings\Ann\Local Settings\Application Data\census.cache
[2011/09/19 13:58:07 | 000,184,157 | ---- | C] () -- C:\Documents and Settings\Ann\Local Settings\Application Data\ars.cache
[2011/02/23 00:32:50 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Ann\Local Settings\Application Data\housecall.guid.cache
[2011/01/17 15:38:01 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2011/01/17 15:38:01 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2011/01/17 15:37:50 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Ann\Application Data\$_hpcst$.hpc
[2011/01/14 12:44:04 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\exit32.dll
[2011/01/14 12:44:03 | 000,002,962 | ---- | C] () -- C:\WINDOWS\nedprint.ini
========== LOP Check ==========
[2012/05/18 13:00:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2009/10/05 22:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/01/26 23:32:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Final Draft
[2007/05/30 02:37:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FRISK Software
[2012/05/20 02:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[2006/06/13 11:58:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MVTLogs
[2007/12/12 22:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/10/05 22:59:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2008/09/23 22:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Quick Heal
[2011/01/17 15:38:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2012/04/21 07:25:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2008/01/18 00:52:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2007/01/17 13:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/02/22 23:44:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/05 22:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/10/05 22:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vhosts
[2007/06/22 10:27:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2012/05/02 10:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2007/01/26 13:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\acccore
[2012/05/13 21:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\BitTorrent
[2009/11/01 18:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\BitZipper
[2012/02/13 11:54:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\BoutellDotCom
[2011/11/21 01:40:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Canon
[2012/05/08 22:55:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\CoreFTP
[2012/05/12 08:05:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Dropbox
[2012/02/15 01:21:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\dvdae
[2010/06/15 23:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Facebook
[2009/11/20 00:39:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\FileZilla
[2010/01/26 23:33:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Final Draft
[2012/05/04 03:01:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\HandBrake
[2012/02/09 23:49:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\iMapBuilder
[2010/02/05 19:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Leadertech
[2010/09/03 16:33:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\LimeWire
[2005/05/26 20:36:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\MailFrontier
[2007/12/12 22:13:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\NCH Swift Sound
[2009/10/05 23:05:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Nikon
[2011/01/17 15:52:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Samsung
[2008/11/13 02:23:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Snapfish
[2010/12/25 01:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Stella
[2007/12/31 16:37:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Template
[2007/10/15 15:24:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\vol_toolbar
[2006/12/30 18:34:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\EarthLink Toolbar
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/03/05 09:24:46 | 000,000,353 | ---- | M] () -- C:\aaw7boot.log
[2008/09/25 09:04:13 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2012/05/16 22:32:10 | 000,000,212 | ---- | M] () -- C:\Boot.bak
[2012/05/24 01:21:57 | 000,000,328 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2005/04/05 19:26:40 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2012/05/25 18:08:04 | 267,460,608 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/04 08:34:57 | 000,000,523 | ---- | M] () -- C:\hpfr3420.xml
[2009/10/04 08:34:57 | 000,138,181 | ---- | M] () -- C:\hpfr3425.log
[2009/05/29 11:38:49 | 000,000,800 | -H-- | M] () -- C:\hpothb07.dat
[2009/05/27 13:54:46 | 000,032,592 | -H-- | M] () -- C:\hpothb07.tif
[2005/04/05 19:26:40 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/07/21 11:57:53 | 000,002,559 | -H-- | M] () -- C:\IPH.PH
[2005/04/05 19:26:40 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2005/04/10 14:33:36 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/18 21:40:17 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/05/25 18:07:49 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys
[2009/04/07 00:12:33 | 000,000,678 | ---- | M] () -- C:\qhdebug.log
[2012/05/23 23:24:22 | 000,000,359 | ---- | M] () -- C:\rkill.log
[2012/05/19 00:46:53 | 000,095,626 | ---- | M] () -- C:\TDSSKiller.2.7.35.0_19.05.2012_00.41.46_log.txt
[2012/05/20 01:01:27 | 000,097,508 | ---- | M] () -- C:\TDSSKiller.2.7.35.0_20.05.2012_00.58.50_log.txt
[2012/05/20 01:07:35 | 000,087,942 | ---- | M] () -- C:\TDSSKiller.2.7.35.0_20.05.2012_01.06.03_log.txt
[2012/05/22 13:25:08 | 000,086,478 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_22.05.2012_13.21.34_log.txt
[2009/03/21 10:06:58 | 000,001,152 | -HS- | M] () -- C:\xdnt32fn.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/04/05 19:26:15 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/06 19:15:19 | 000,041,184 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2007/06/06 18:23:32 | 001,047,341 | ---- | M] (andUP GmbH && Co.KG) -- C:\WINDOWS\The HAL 9000 Screensaver.scr
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/05/29 11:37:13 | 000,000,588 | -H-- | M] () -- C:\Program Files\hpothb07.dat
[2009/05/27 13:49:42 | 000,000,999 | -H-- | M] () -- C:\Program Files\hpothb07.tif
[2008/02/12 18:14:43 | 000,000,000 | ---- | M] () -- C:\Program Files\SOUNDPAD.BMP
[2001/10/31 13:07:50 | 000,249,856 | ---- | M] (Menace Software) -- C:\Program Files\SOUNDPAD.EXE
[1996/01/17 20:35:12 | 000,027,315 | ---- | M] () -- C:\Program Files\SOUNDPAD.HLP
[1996/02/03 20:10:08 | 000,000,428 | ---- | M] () -- C:\Program Files\SOUNDPAD.INI
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/04/05 12:04:26 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005/04/05 12:04:26 | 000,602,112 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2005/04/05 12:04:26 | 000,393,216 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/18 21:48:10 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/04/10 16:45:08 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Ann\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/04/05 20:12:27 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Ann\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/05/25 19:15:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ann\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2002/09/03 12:46:18 | 000,000,065 | RH-- | M] () -- C:\WINDOWS\tasks\desktop.ini
[2012/05/25 18:08:14 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2008/02/14 12:41:06 | 000,584,944 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Ann\My Documents\WindowsXP-KB900485-v2-x86-ENU.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2005/04/10 16:45:08 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Ann\Favorites\Desktop.ini
[2007/12/12 22:13:18 | 000,000,440 | ---- | M] () -- C:\Documents and Settings\Ann\Favorites\NCH Audio and Telephony Software Page.lnk
[2007/10/15 15:17:48 | 000,001,710 | ---- | M] () -- C:\Documents and Settings\Ann\Favorites\Verizon Central.lnk
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2009/05/29 09:30:15 | 000,000,253 | -H-- | M] () -- C:\Documents and Settings\All Users\hpothb07.tif
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2012/01/15 15:27:39 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Ann\Cookies\desktop.ini
[2012/05/25 18:10:23 | 000,032,768 | -HS- | M] () -- C:\Documents and Settings\Ann\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008/04/13 20:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2002/09/03 12:39:47 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
[2002/08/20 15:32:18 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2002/08/20 15:32:22 | 000,000,807 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
[2008/05/02 10:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2008/04/13 13:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/04/13 20:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2002/08/20 18:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgsin.exe
[2002/09/03 12:49:05 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2002/09/03 12:49:07 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2002/09/03 12:51:10 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2002/08/20 15:32:20 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2004/07/17 14:41:04 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
[2002/07/17 17:22:34 | 000,003,535 | ---- | M] () -- C:\WINDOWS\system\Wowpost.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-05-16 15:16:48
========== Files - Unicode (All) ==========
[2009/10/13 15:44:24 | 000,024,064 | ---- | M] ()(C:\Documents and Settings\Ann\My Documents\????????? ??p??.doc) -- C:\Documents and Settings\Ann\My Documents\Εἰρηνικὁς Κἣπος.doc
[2009/08/27 10:05:36 | 000,458,240 | ---- | M] ()(C:\Documents and Settings\Ann\My Documents\e?????.doc) -- C:\Documents and Settings\Ann\My Documents\εἰρήνη.doc
[2009/08/27 10:05:35 | 000,458,240 | ---- | C] ()(C:\Documents and Settings\Ann\My Documents\e?????.doc) -- C:\Documents and Settings\Ann\My Documents\εἰρήνη.doc
[2009/08/25 11:01:41 | 000,024,064 | ---- | C] ()(C:\Documents and Settings\Ann\My Documents\????????? ??p??.doc) -- C:\Documents and Settings\Ann\My Documents\Εἰρηνικὁς Κἣπος.doc
[2007/02/16 13:48:38 | 000,000,000 | ---D | M](C:\WINDOWS\?icrosoft) -- C:\WINDOWS\Μicrosoft
[2007/02/16 13:48:38 | 000,000,000 | ---D | C](C:\WINDOWS\?icrosoft) -- C:\WINDOWS\Μicrosoft
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:30FD0CBD
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

FC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >