========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files\Internet\Mozilla Firefox 3\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U23 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Internet\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files\Internet\Mozilla Firefox 3\plugins\npBitCometAgent.dll
CHR - plugin: 3D Life Player (Enabled) = C:\Program Files\Internet\Mozilla Firefox\plugins\npvirtools.dll
CHR - plugin: thriXXX WebLaunch (Enabled) = C:\Program Files\Internet\Mozilla Firefox\plugins\npWebLaunch.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files\Internet\Mozilla Firefox\plugins\npzylomgamesplayer.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Super Mario Bros. Crossover = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eeecbbkpegiknjlkklkajceokkdgipbm\2.1_0\
CHR - Extension: Lord of Ultima = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jdheeblenjmceeppomdgokgilmkonced\1.0.11_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\
CHR - Extension: Poppit = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Google Chrome to Phone Extension = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
O1 HOSTS File: ([2012/02/16 11:48:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\Internet\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - Reg Error: Value error. File not found
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O3 - HKLM\..\Toolbar: (NetXfer) - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Internet\NetXfer\NXToolBar.dll (Xi)
O3 - HKLM\..\Toolbar: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007\..\Toolbar\WebBrowser: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O4 - HKLM..\Run: [!1_pgaccount] C:\Program Files\ProcessGuard\pgaccount.exe (DiamondCS)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe (Privacyware/PWI, Inc.)
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [StartupDelayer] C:\Program Files\Startup Delayer\Startup Launcher GUI.exe (r2 studios)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [!1_ProcessGuard_Startup] C:\Program Files\ProcessGuard\procguard.exe (DiamondCS)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [DriverMax] C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [DriverMax_RESTART] C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe (Methlabs)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [SplitCam] C:\Program Files\SplitCam\SplitCam.exe (SplitCam Co.)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe (SFX TEAM)
O4 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O4 - HKU\S-1-5-18..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\PinMcLnk.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3220704123-1705262036-168104783-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\Internet\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\Internet\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Download all by NetXfer - C:\Program Files\Internet\NetXfer\NXAddList.html ()
O8 - Extra context menu item: Download by NetXfer - C:\Program Files\Internet\NetXfer\NXAddLink.html ()
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\HP_Administrator\Application Data\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\HP_Administrator\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O9 - Extra Button: Bubble This URL - {A3A0268C-3146-431d-84EE-2789B750ABD2} - C:\Program Files\Bubbles\BubblesHBO.dll (3D3R)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\Internet\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1287561639000 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0}
http://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll (diskhealth Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1594FE92-FEC5-43E7-902C-E92A362EBDCF}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9B743EA3-719A-4C2C-A274-07437BDFF65F}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/19 17:40:56 | 000,000,100 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/27 08:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2011/08/06 01:11:04 | 000,000,000 | ---D | M] - J:\Autohotkey -- [ NTFS ]
O32 - AutoRun File - [2006/05/26 12:25:18 | 000,712,704 | ---- | M] () - K:\AutoRAR.exe -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: MRESP50a64 - File not found
NetSvcs: wps - File not found
NetSvcs: MSFWDrv - File not found
NetSvcs: point32 - File not found
NetSvcs: MTC0001_ESB - File not found
NetSvcs: se59mgmt - File not found
NetSvcs: queuemgr - File not found
NetSvcs: cmdmon - File not found
NetSvcs: Nsynas32 - File not found
NetSvcs: mirrorv3 - File not found
NetSvcs: GTPTSER - File not found
NetSvcs: x10nets - File not found
NetSvcs: houdinilicenseserver - File not found
NetSvcs: sfhlp02 - File not found
NetSvcs: mgabgexe - File not found
NetSvcs: int15 - File not found
NetSvcs: wmconnectcds - File not found
NetSvcs: issimon - File not found
NetSvcs: NWFILTER - File not found
NetSvcs: s116nd5 - File not found
NetSvcs: lusbaudio - File not found
NetSvcs: clmtomcatstartersvc - File not found
NetSvcs: foldersize - File not found
NetSvcs: ikfilesec - File not found
NetSvcs: centennialclientagent - File not found
NetSvcs: SaiH040B - C:\WINDOWS\system32\w810bus.dll (Oak Technology Inc.)
NetSvcs: imap4d32 - File not found
NetSvcs: nmindexingservice - File not found
NetSvcs: pclepci - File not found
NetSvcs: CAM1210 - File not found
NetSvcs: portmapper - File not found
NetSvcs: lxbx_device - File not found
NetSvcs: dwusbdnt - File not found
NetSvcs: mcusrmgr - File not found
NetSvcs: SQTECH9080 - File not found
NetSvcs: s117mdm - File not found
NetSvcs: iPassPeriodicUpdateApp - File not found
NetSvcs: SMCB000 - File not found
NetSvcs: sthda - File not found
NetSvcs: st330service - File not found
NetSvcs: icraplus - File not found
NetSvcs: com0com - File not found
NetSvcs: lxbt_device - File not found
NetSvcs: cpqnicmgmt - File not found
NetSvcs: SaiNtHid - File not found
NetSvcs: toscosrv - File not found
NetSvcs: NuidFltr - File not found
NetSvcs: k56 - File not found
NetSvcs: infrastructure - File not found
NetSvcs: vwlogger - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.D263 - C:\WINDOWS\System32\xl_x263dec.dll (Xirlink, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\WINDOWS\System32\i420vfw.dll (
www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (
www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/16 13:49:02 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2012/02/16 12:01:36 | 000,012,568 | ---- | C] (Sysinternals -
www.sysinternals.com) -- C:\WINDOWS\System32\drivers\PROCEXP113.SYS
[2012/02/15 22:43:02 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/02/12 00:26:25 | 000,000,000 | --SD | C] -- C:\WINDOWS\Cookies
[2012/02/11 23:17:52 | 004,402,217 | R--- | C] (Swearware) -- C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
[2012/02/11 20:58:22 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/02/11 20:52:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/11 20:52:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/11 20:52:59 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/11 20:52:59 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/11 20:52:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/02/11 20:52:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/09 06:22:28 | 000,000,000 | ---D | C] -- C:\found.001
[2012/02/04 16:25:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2012/02/04 16:25:02 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
[2012/02/04 15:17:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ThreatFire
[2012/02/04 15:16:59 | 000,069,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfSysMon.sys
[2012/02/04 15:16:59 | 000,051,984 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfFsMon.sys
[2012/02/04 15:16:59 | 000,033,552 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfNetMon.sys
[2012/02/04 15:16:56 | 000,000,000 | ---D | C] -- C:\Program Files\ThreatFire
[2012/02/04 15:16:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2012/02/03 17:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Threats
[2012/02/02 12:40:07 | 000,000,000 | ---D | C] -- C:\Program Files\ThreatExpert Memory Scanner
[2012/02/02 12:40:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ThreatExpert Memory Scanner
[2012/01/29 15:26:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Argente - Uninstall Manager
[2012/01/29 15:26:24 | 000,000,000 | ---D | C] -- C:\Program Files\Argente - Uninstall Manager
[2012/01/26 03:33:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Yahoo! Messenger
[2012/01/24 17:38:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Administrator\Application Data\DAEMON Tools Lite
[2012/01/24 17:22:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/12/05 22:02:08 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
[2010/12/05 22:02:08 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
[2010/08/06 04:16:53 | 001,618,432 | ---- | C] (factormystic.net) -- C:\Program Files\Default Programs Editor.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/16 14:52:00 | 000,000,906 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/16 14:52:00 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/16 13:49:05 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2012/02/16 12:02:32 | 000,001,226 | ---- | M] () -- C:\WINDOWS\SplitCam.INI
[2012/02/16 12:01:36 | 000,012,568 | ---- | M] (Sysinternals -
www.sysinternals.com) -- C:\WINDOWS\System32\drivers\PROCEXP113.SYS
[2012/02/16 11:49:46 | 000,000,185 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2012/02/16 11:48:10 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/16 11:46:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/16 11:46:01 | 3487,744,000 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/16 11:45:56 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2012/02/16 11:45:47 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2012/02/15 22:41:29 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/02/15 22:29:31 | 000,278,096 | ---- | M] () -- C:\WINDOWS\System32\pghash.dat
[2012/02/15 20:29:57 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/15 02:18:00 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/14 13:54:07 | 000,000,000 | -HS- | M] () -- C:\WINDOWS\System32\dds_trash_log.cmd
[2012/02/13 19:21:12 | 000,336,993 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Desktop\FSS.exe
[2012/02/12 15:46:55 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/11 23:38:33 | 000,504,792 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/02/11 23:38:32 | 000,088,586 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/02/11 20:58:30 | 000,000,364 | RHS- | M] () -- C:\boot.ini
[2012/02/11 20:45:27 | 004,402,217 | R--- | M] (Swearware) -- C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
[2012/02/11 19:52:11 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat
[2012/02/06 22:24:35 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/02/06 22:24:35 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/02/06 22:17:57 | 000,000,176 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\defogger_reenable
[2012/02/06 22:10:05 | 000,000,701 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2012/02/06 22:07:09 | 088,369,140 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/05 00:04:01 | 000,335,823 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/02/04 15:21:40 | 000,272,096 | ---- | M] () -- C:\WINDOWS\System32\pguard.dat
[2012/02/04 15:17:01 | 000,000,650 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\ThreatFire.lnk
[2012/01/26 22:13:01 | 000,252,080 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012/01/26 22:13:01 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012/01/24 17:43:30 | 000,242,240 | ---- | M] () -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2012/01/24 03:08:32 | 000,000,039 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Desktop\Shutdown Stopper.ini
[2012/01/21 01:38:42 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverMax.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/15 23:34:09 | 3487,744,000 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/13 20:31:37 | 000,000,000 | -HS- | C] () -- C:\WINDOWS\System32\dds_trash_log.cmd
[2012/02/13 20:23:35 | 000,242,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2012/02/13 19:45:10 | 000,336,993 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Desktop\FSS.exe
[2012/02/11 20:52:59 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/11 20:52:59 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/11 20:52:59 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/11 20:52:59 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/11 20:52:59 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/11 19:52:11 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat
[2012/02/06 22:17:38 | 000,000,176 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\defogger_reenable
[2012/02/04 15:17:01 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\ThreatFire.lnk
[2012/01/25 18:19:23 | 000,001,226 | ---- | C] () -- C:\WINDOWS\SplitCam.INI
[2012/01/24 03:08:30 | 000,000,039 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Desktop\Shutdown Stopper.ini
[2011/12/27 03:07:29 | 000,000,986 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\3wypc81pasp27g3e0aetpba643751l426a77ix
[2011/12/27 03:07:29 | 000,000,986 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\3wypc81pasp27g3e0aetpba643751l426a77ix
[2011/12/25 21:21:44 | 000,002,234 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\wpiyhave0j0l
[2011/12/25 21:21:44 | 000,002,234 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\wpiyhave0j0l
[2011/12/21 13:41:21 | 000,278,096 | ---- | C] () -- C:\WINDOWS\System32\pghash.dat
[2011/12/21 13:41:20 | 000,272,096 | ---- | C] () -- C:\WINDOWS\System32\pguard.dat
[2011/12/20 16:10:27 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\procguard.dll
[2011/12/18 19:10:03 | 000,000,146 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011/12/16 15:09:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\HJ82c.exe.b
[2011/12/16 15:06:53 | 000,000,112 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Xmnj5x8.dat
[2011/12/16 14:53:32 | 000,013,984 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\556743u6e382q717x083h0cov2n3
[2011/12/16 14:53:32 | 000,013,984 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\556743u6e382q717x083h0cov2n3
[2011/10/14 01:04:26 | 000,007,633 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\.freeciv-client-rc-2.3
[2011/08/20 00:16:09 | 000,267,614 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/08/16 05:16:24 | 000,337,722 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3220704123-1705262036-168104783-1007-0.dat
[2011/07/26 17:26:48 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe
[2011/07/26 17:26:46 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2011/07/26 17:26:46 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/07/26 17:26:46 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/07/26 17:26:46 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2011/07/03 15:47:49 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/07/03 15:47:49 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/06/30 16:22:07 | 000,016,432 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2011/04/20 17:19:39 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Ddiwezipahal.dat
[2011/04/20 17:19:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Ksuzebic.bin
[2010/12/16 06:06:58 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\setup_ldm.iss
[2010/12/05 20:12:55 | 000,042,535 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2010/12/05 19:13:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\SuperSafer.cfg
[2010/12/05 19:13:08 | 002,771,968 | ---- | C] () -- C:\WINDOWS\System32\wxmsw28u_core_vc_custom.dll
[2010/12/05 19:13:08 | 001,163,776 | ---- | C] () -- C:\WINDOWS\System32\wxbase28u_vc_custom.dll
[2010/12/05 19:13:08 | 000,681,472 | ---- | C] () -- C:\WINDOWS\System32\wxmsw28u_adv_vc_custom.dll
[2010/12/05 19:13:08 | 000,492,032 | ---- | C] () -- C:\WINDOWS\System32\wxmsw28u_xrc_vc_custom.dll
[2010/12/05 19:13:08 | 000,470,528 | ---- | C] () -- C:\WINDOWS\System32\wxmsw28u_html_vc_custom.dll
[2010/12/05 19:13:08 | 000,119,808 | ---- | C] () -- C:\WINDOWS\System32\wxbase28u_net_vc_custom.dll
[2010/12/05 19:13:08 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\wxbase28u_xml_vc_custom.dll
[2010/12/05 19:13:08 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\verify.dll
[2010/12/05 19:13:08 | 000,014,336 | ---- | C] () -- C:\WINDOWS\System32\config.dll
[2010/12/03 13:58:47 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2010/12/03 13:58:47 | 000,011,296 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2010/12/03 13:58:44 | 000,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/12/03 13:58:44 | 000,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/12/03 13:56:42 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/12/03 13:44:08 | 000,049,152 | R--- | C] () -- C:\WINDOWS\DAOD.exe
[2010/12/03 13:44:05 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/12/03 13:44:02 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2010/12/03 13:43:52 | 000,033,790 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010/12/03 13:43:50 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/12/03 13:12:20 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/12/03 13:12:18 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/12/03 13:12:18 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/12/03 12:53:54 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/11/10 10:44:49 | 000,266,056 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/10/20 03:40:01 | 000,102,038 | ---- | C] () -- C:\WINDOWS\System32\HCW848UN.EXE
[2010/10/20 03:13:29 | 000,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2010/09/15 03:34:39 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/08/28 02:18:30 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/08/28 02:18:30 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/08/28 02:18:28 | 000,080,896 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/07/26 18:22:18 | 000,000,034 | -H-- | C] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2010/06/18 14:42:43 | 000,000,043 | ---- | C] () -- C:\WINDOWS\FFS20ChtReg.ini
[2010/05/23 15:13:31 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/04/21 00:16:46 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/01/30 01:20:02 | 000,000,430 | ---- | C] () -- C:\WINDOWS\Memory.ini
[2010/01/30 01:17:31 | 000,000,361 | ---- | C] () -- C:\WINDOWS\MasMind.INI
[2009/12/29 08:01:05 | 000,004,620 | ---- | C] () -- C:\WINDOWS\XChange.dat
[2009/12/25 18:22:41 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/12/06 01:46:45 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/11/07 16:23:36 | 000,000,279 | ---- | C] () -- C:\WINDOWS\YAHTZEE.INI
[2009/11/07 16:22:56 | 000,000,049 | ---- | C] () -- C:\WINDOWS\TTT.INI
[2009/11/07 16:22:06 | 000,000,050 | ---- | C] () -- C:\WINDOWS\pmachine.ini
[2009/10/07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/31 05:59:39 | 000,000,093 | ---- | C] () -- C:\WINDOWS\othello.ini
[2009/08/31 05:56:54 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Blip.ini
[2009/07/31 22:57:06 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009/07/31 21:43:51 | 001,377,162 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\speech.wav
[2009/07/02 03:37:07 | 000,003,464 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\springsettings.cfg
[2009/07/01 15:04:57 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/04/20 23:32:39 | 000,001,160 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\MPQEditor.ini
[2009/04/09 04:35:45 | 000,000,152 | ---- | C] () -- C:\WINDOWS\CS_MD_T.ini
[2009/03/25 02:10:00 | 000,810,496 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/03/25 02:10:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/03/24 05:41:58 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2009/03/20 06:47:41 | 000,004,226 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\Cosmos Prefs
[2009/03/17 23:07:43 | 000,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2009/03/07 08:54:47 | 000,019,840 | ---- | C] () -- C:\WINDOWS\W2BNEUnin.dat
[2009/03/04 20:01:04 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2009/01/20 12:43:35 | 000,005,292 | ---- | C] () -- C:\WINDOWS\DiabUnin.dat
[2008/12/03 11:57:29 | 000,905,290 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2008/12/03 11:57:28 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\AvidXPSerial.sys
[2008/10/29 03:16:02 | 000,088,456 | ---- | C] () -- C:\WINDOWS\Network Measurement Agent Uninstaller.exe
[2008/10/12 23:56:05 | 000,000,335 | ---- | C] () -- C:\WINDOWS\mozregistry.dat
[2008/10/11 18:53:40 | 000,000,047 | ---- | C] () -- C:\WINDOWS\WinBIN2ISO.INI
[2008/09/07 19:52:55 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\WavCodec.wff
[2008/08/19 21:46:41 | 000,000,216 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini
[2008/05/21 05:30:54 | 000,000,062 | ---- | C] () -- C:\WINDOWS\TSW12.INI
[2008/05/12 17:46:11 | 000,000,516 | ---- | C] () -- C:\WINDOWS\ROPatch.ini
[2008/04/21 03:26:52 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\sprview.dll
[2008/03/05 18:38:08 | 001,457,024 | ---- | C] () -- C:\WINDOWS\System32\SSCProt.dll
[2008/02/07 06:56:54 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/11/26 21:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2007/09/26 13:16:55 | 000,308,928 | ---- | C] () -- C:\WINDOWS\System32\ivflt08.dll
[2007/09/26 13:16:55 | 000,211,456 | ---- | C] () -- C:\WINDOWS\System32\ivbas08.dll
[2007/09/19 23:50:09 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2007/08/19 15:11:59 | 000,000,311 | ---- | C] () -- C:\WINDOWS\SoftWriting.ini
[2007/07/25 23:15:41 | 000,000,626 | ---- | C] () -- C:\WINDOWS\roughdraft.INI
[2007/06/28 19:01:48 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/03/31 23:40:54 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Mp3Decode.INI
[2007/03/21 21:21:10 | 000,703,258 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2007/03/21 21:21:10 | 000,003,381 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2007/03/03 21:13:48 | 000,000,376 | ---- | C] () -- C:\WINDOWS\settings.ini
[2007/02/18 05:33:34 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2007/02/05 11:11:36 | 000,007,725 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Application Data\.googlewebacchosts
[2007/01/18 02:46:39 | 000,000,635 | ---- | C] () -- C:\WINDOWS\Sta2.INI
[2006/11/13 00:09:16 | 000,000,007 | -H-- | C] () -- C:\WINDOWS\TFSFILE5.DAT
[2006/11/06 03:44:43 | 000,004,929 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/06 01:11:30 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2006/11/06 00:56:25 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/05 22:09:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/05 21:04:56 | 000,000,139 | ---- | C] () -- C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2006/08/19 18:08:53 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/19 17:44:32 | 000,014,317 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2006/08/19 17:44:26 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2006/08/19 17:41:13 | 000,000,174 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2006/08/19 17:29:45 | 000,004,567 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/08/19 17:29:06 | 000,045,929 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/08/19 17:29:06 | 000,000,698 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/08/19 17:24:22 | 000,095,822 | ---- | C] () -- C:\WINDOWS\hpqins69.dat
[2006/08/19 17:23:25 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/08/19 17:21:15 | 000,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll.hcw
[2006/08/19 17:20:00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/08/19 17:20:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/08/19 17:18:35 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/08/19 16:57:40 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2006/08/19 16:57:40 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2006/08/19 16:57:21 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2006/08/04 19:24:28 | 000,010,747 | ---- | C] () -- C:\WINDOWS\System32\UDBDef.exe
[2006/06/27 22:15:56 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2006/06/16 06:58:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/11/07 17:32:46 | 003,088,384 | ---- | C] () -- C:\WINDOWS\System32\erdmpg-4.dll
[2005/11/04 21:57:14 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\Manipulate.dll
[2005/08/30 16:17:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/08/30 16:07:46 | 000,504,792 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/08/30 16:07:46 | 000,088,586 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/08/30 16:05:30 | 000,230,392 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/30 16:01:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/30 15:58:02 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/08/05 16:01:54 | 000,239,104 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 18:19:16 | 000,050,176 | ---- | C] () -- C:\WINDOWS\armcex.dll
[2004/08/09 23:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/09 16:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/09 16:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/09 16:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/09 16:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/09 16:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/09 16:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/09 16:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/07/26 02:51:38 | 000,000,560 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/08/07 14:01:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2003/07/25 00:23:32 | 001,000,583 | ---- | C] () -- C:\WINDOWS\System32\gnet-1.1.dll
[2002/12/12 22:24:04 | 000,653,824 | ---- | C] () -- C:\WINDOWS\System32\libxml2.dll
[2001/08/23 03:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:11:02 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys