otl scan
OTL logfile created on: 7/9/2010 6:26:34 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041E | Country: Thailand | Language: THA | Date Format: d/M/yyyy
991.00 Mb Total Physical Memory | 535.00 Mb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.70 Gb Total Space | 7.59 Gb Free Space | 38.52% Space Free | Partition Type: NTFS
Drive D: | 17.57 Gb Total Space | 13.98 Gb Free Space | 79.61% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: FAMILY
Current User Name: Admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\java\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Admin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (STacSV) -- c:\d\s\zi\STacSV.exe File not found
SRV - (JavaQuickStarterService) -- D:\java\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MsMpSvc) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (aspnet_state) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
========== Driver Services (SafeList) ==========
DRV - (IntelIde) -- C:\WINDOWS\System32\Drivers\IntelIde.sys File not found
DRV - (EagleNT) -- C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (catchme) -- C:\Combo-Fix\catchme.sys File not found
DRV - (SiSkp) -- C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SiS315) -- C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (MpFilter) -- C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (SISNIC) -- C:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (RTHDMIAzAudService) -- C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)
DRV - (vmmouse) -- C:\WINDOWS\system32\drivers\vmmouse.sys (VMware, Inc.)
DRV - (L8042Kbd) -- C:\WINDOWS\system32\drivers\L8042Kbd.sys (Logitech Inc.)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (SISNICXP) -- C:\WINDOWS\system32\drivers\sisnicxp.sys (SiS Corporation)
DRV - (SiS7012) Service for AC'97 Sample Driver (WDM) -- C:\WINDOWS\system32\drivers\sis7012.sys (Silicon Integrated Systems Corporation)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) -- C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://th.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = th,en-US;q=0.5
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7E 92 BE 0D 6C 4E CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: D:\java\lib\deploy\jqs\ff [2010/09/04 13:46:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
O1 HOSTS File: ([2010/09/06 21:51:00 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\java\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\java\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Admin\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: ส่&งออกไปยัง Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283100731125 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/18 23:03:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/09/07 18:24:23 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Admin\Desktop\OTL.exe
[2010/09/06 22:52:25 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/06 22:52:24 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/06 22:52:23 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/06 22:50:49 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/09/06 22:50:23 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Admin\Desktop\mbam-setup-1.46.exe
[2010/09/06 22:49:56 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\Admin\Desktop\ATF-Cleaner.exe
[2010/09/06 21:39:48 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/09/06 21:39:48 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/09/06 21:39:48 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/09/06 21:39:48 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/09/06 21:39:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/09/06 18:16:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2010/09/06 16:00:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2010/09/06 15:37:42 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2010/09/06 14:27:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin\Recent
[2010/09/06 09:40:42 | 000,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2010/09/05 22:37:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\Installer1068
[2010/09/05 22:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\Installer3448
[2010/09/05 21:59:31 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/09/05 21:45:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\WinPatrol
[2010/09/05 21:45:09 | 000,000,000 | ---D | C] -- C:\Program Files\BillP Studios
[2010/09/05 21:36:23 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
[2010/09/05 21:09:17 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Admin\IECompatCache
[2010/09/05 20:53:33 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/09/05 16:38:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie7updates
[2010/09/05 16:01:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010/09/05 15:00:21 | 000,759,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\VGX.dll
[2010/09/05 14:56:48 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jscript.dll
[2010/09/05 14:55:50 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010/09/05 14:51:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/09/05 13:05:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\Malwarebytes
[2010/09/05 13:05:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/05 00:09:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\XSxS
[2010/09/05 00:09:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\Xenocode
[2010/09/04 13:47:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2010/09/04 13:47:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/04 13:47:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/09/04 13:47:16 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/09/04 13:47:16 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/09/04 13:47:16 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/09/04 13:47:16 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/09/04 13:47:16 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/09/04 13:45:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\Sun
[2010/09/04 13:29:35 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2010/09/04 13:29:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2010/09/04 13:29:32 | 000,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2010/09/04 13:29:32 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010/09/04 12:12:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/09/04 12:00:36 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/09/04 10:08:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\PCHealth
[2010/09/03 11:19:42 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010/09/03 10:59:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/08/31 11:12:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/08/31 09:51:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2010/08/30 17:45:37 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cpe17_taskmgr.exe
[2010/08/30 17:27:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2010/08/30 15:31:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\msmq
[2010/08/30 15:08:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\ApplicationHistory
[2010/08/30 14:39:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/08/30 14:06:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\Windows Search
[2010/08/30 11:03:45 | 000,000,000 | ---D | C] -- D:\My documents\documents from (name)
[2010/08/30 03:17:01 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/08/30 03:14:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2010/08/30 03:14:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2010/08/30 03:14:16 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2010/08/30 03:12:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/08/30 03:03:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\Identities
[2010/08/30 03:02:16 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2010/08/30 03:01:24 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\offfilt.dll
[2010/08/30 03:01:24 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nlhtml.dll
[2010/08/30 03:01:24 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mimefilt.dll
[2010/08/30 02:59:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2010/08/30 02:47:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SiS
[2010/08/30 02:46:53 | 000,000,000 | ---D | C] -- C:\Program Files\SiS7012
[2010/08/30 02:46:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2010/08/30 01:24:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/08/30 01:23:06 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/08/30 01:06:20 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2010/08/30 01:06:14 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2010/08/30 01:06:10 | 001,986,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2010/08/30 01:06:09 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/30 01:03:56 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\t2embed.dll
[2010/08/30 01:03:56 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fontsub.dll
[2010/08/30 00:56:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2010/08/30 00:56:16 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2010/08/30 00:55:44 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2010/08/30 00:54:55 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2010/08/30 00:54:55 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/08/30 00:54:55 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/08/30 00:54:55 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/08/30 00:54:55 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2010/08/30 00:54:55 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/08/30 00:54:52 | 000,354,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2010/08/30 00:53:00 | 000,455,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2010/08/30 00:52:44 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/08/30 00:51:22 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/08/30 00:48:35 | 002,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2010/08/30 00:48:35 | 002,146,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2010/08/30 00:48:34 | 002,024,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2010/08/30 00:48:32 | 002,066,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2010/08/30 00:29:08 | 003,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/08/30 00:11:54 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tlntsess.exe
[2010/08/30 00:11:53 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\telnet.exe
[2010/08/29 23:59:30 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netapi32.dll
[2010/08/29 23:57:57 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadce.dll
[2010/08/29 23:57:16 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\es.dll
[2010/08/29 23:55:33 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2010/08/29 23:55:25 | 000,203,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rmcast.sys
[2010/08/29 23:54:25 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010/08/29 23:54:25 | 000,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2010/08/29 23:52:41 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2010/08/29 22:51:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/08/29 22:25:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\Yahoo!
[2010/08/18 16:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Local Settings\Application Data\HP
[2010/08/18 16:04:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WEBREG
[2010/08/18 16:04:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\HP
[2010/08/18 15:49:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cache
[2010/08/18 15:49:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\HpUpdate
[2010/08/18 15:43:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP
[2010/08/18 15:43:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard
[2010/08/18 15:41:15 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/08/18 15:36:38 | 000,123,904 | ---- | C] (Hewlett-Packard Company) -- C:\WINDOWS\System32\hpf3l70v.dll
[2010/08/18 15:36:37 | 000,452,408 | R--- | C] (Hewlett-Packard) -- C:\WINDOWS\System32\hpzids01.dll
[2010/08/18 15:35:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/07 18:29:06 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/07 18:24:23 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/07 18:23:28 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/07 18:23:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/07 18:18:02 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin\Desktop\OTL.exe
[2010/09/07 17:48:46 | 005,505,024 | -H-- | M] () -- C:\Documents and Settings\Admin\NTUSER.DAT
[2010/09/07 17:48:46 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Admin\ntuser.ini
[2010/09/07 17:39:49 | 005,248,776 | -H-- | M] () -- C:\Documents and Settings\Admin\Local Settings\Application Data\IconCache.db
[2010/09/06 22:52:27 | 000,000,701 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/06 21:51:47 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/09/06 21:51:00 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/09/06 21:37:58 | 003,837,097 | R--- | M] () -- C:\Documents and Settings\Admin\Desktop\Combo-Fix.exe
[2010/09/06 18:07:43 | 000,000,617 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/06 18:06:23 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/09/06 18:06:23 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/09/06 16:34:05 | 000,000,410 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\My Music.lnk
[2010/09/06 16:33:52 | 000,000,350 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\My Downloads.lnk
[2010/09/06 16:33:44 | 000,000,420 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\My shared folder.lnk
[2010/09/06 15:37:44 | 000,000,677 | ---- | M] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2010/09/06 15:37:44 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk
[2010/09/06 15:00:47 | 000,012,800 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/06 13:45:13 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\Disk Cleanup.job
[2010/09/06 13:42:45 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\defrag.job
[2010/09/06 12:00:22 | 000,059,464 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/06 11:59:23 | 001,539,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/06 10:13:03 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/09/06 09:54:09 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2010/09/06 09:40:22 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/09/05 21:04:16 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/05 16:11:46 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\Trillian - IM, Astra, Windows Live, Facebook, Twitter, Yahoo, MySpace, AIM, Email, and more!.url
[2010/09/05 16:07:00 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/09/04 15:10:42 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Admin\Desktop\mbam-setup-1.46.exe
[2010/09/04 14:28:23 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\n81nuh2d.exe
[2010/09/04 13:46:50 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/09/04 13:46:50 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/09/04 13:46:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/09/04 13:46:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/09/04 13:46:50 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/09/04 13:32:45 | 000,600,374 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/04 13:32:45 | 000,501,382 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/09/04 13:32:45 | 000,087,288 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/09/04 13:16:35 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Admin\Desktop\ATF-Cleaner.exe
[2010/09/04 12:07:29 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
[2010/09/03 11:11:22 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\dds.com
[2010/09/03 10:58:24 | 000,000,772 | ---- | M] () -- C:\Documents and Settings\Admin\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/08/31 10:39:04 | 000,000,420 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\documents from (name).lnk
[2010/08/30 10:15:16 | 000,000,372 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\My Videos.lnk
[2010/08/30 10:14:33 | 000,000,369 | ---- | M] () -- C:\Documents and Settings\Admin\Desktop\My Pictures.lnk
[2010/08/29 23:14:34 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/08/27 00:54:38 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/08/18 15:57:57 | 000,000,010 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2010/08/10 17:14:49 | 000,001,100 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/06 22:52:27 | 000,000,701 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/06 22:04:31 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\n81nuh2d.exe
[2010/09/06 22:04:18 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\dds.com
[2010/09/06 21:39:48 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/09/06 21:39:48 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/09/06 21:39:48 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/09/06 21:39:48 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/09/06 21:39:48 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/09/06 21:37:56 | 003,837,097 | R--- | C] () -- C:\Documents and Settings\Admin\Desktop\Combo-Fix.exe
[2010/09/06 18:06:23 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/09/06 18:06:22 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/09/06 15:37:44 | 000,000,677 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2010/09/06 15:37:44 | 000,000,659 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk
[2010/09/06 13:35:42 | 000,000,256 | ---- | C] () -- C:\WINDOWS\tasks\defrag.job
[2010/09/06 13:27:18 | 000,000,260 | ---- | C] () -- C:\WINDOWS\tasks\Disk Cleanup.job
[2010/09/06 09:53:38 | 000,000,772 | ---- | C] () -- C:\Documents and Settings\Admin\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/09/05 23:28:29 | 000,000,420 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\My shared folder.lnk
[2010/09/05 16:34:41 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010/09/05 16:24:47 | 000,000,820 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/05 16:11:46 | 000,000,214 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\Trillian - IM, Astra, Windows Live, Facebook, Twitter, Yahoo, MySpace, AIM, Email, and more!.url
[2010/09/05 16:07:00 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/09/05 14:56:41 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/04 12:00:43 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/09/04 12:00:38 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/08/31 10:59:24 | 000,343,224 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/31 10:39:04 | 000,000,420 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\documents from (name).lnk
[2010/08/31 10:24:50 | 000,297,350 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/08/30 11:09:01 | 000,000,350 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\My Downloads.lnk
[2010/08/30 10:15:16 | 000,000,372 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\My Videos.lnk
[2010/08/30 10:14:33 | 000,000,369 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\My Pictures.lnk
[2010/08/30 10:13:57 | 000,000,410 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\My Music.lnk
[2010/08/18 15:37:07 | 000,006,740 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/08/10 20:44:08 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/12 13:39:37 | 000,012,800 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/10 11:34:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Pool.INI
[2010/06/09 20:41:33 | 000,000,094 | -H-- | C] () -- C:\WINDOWS\System32\spv1_WCssg.ini
[2010/06/09 17:19:42 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/09/21 02:32:32 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/09/21 01:22:28 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Thsdict.ini
[2009/09/21 01:22:17 | 003,080,237 | ---- | C] () -- C:\WINDOWS\System32\MSOWC.DLL
[2009/09/21 00:51:41 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/08/24 01:03:37 | 000,000,160 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
========== LOP Check ==========
[2009/09/20 23:59:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\ACD Systems
[2010/06/10 13:46:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\DMCache
[2009/09/21 01:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\ESET
[2010/07/04 12:31:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\funkitron
[2010/06/09 17:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\IDM
[2009/09/21 02:07:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\TeraCopy
[2010/08/30 14:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\Windows Search
[2010/09/05 21:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\WinPatrol
[2009/09/20 23:58:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2010/08/29 23:14:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/09/21 01:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/06/25 16:23:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2010/06/10 01:25:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/06/27 19:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Media
[2010/09/04 23:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/06 13:42:45 | 000,000,256 | ---- | M] () -- C:\WINDOWS\Tasks\defrag.job
[2010/09/06 13:45:13 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\Disk Cleanup.job
[2010/09/07 18:29:06 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/04/14 19:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/04/14 19:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 19:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 19:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 19:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 19:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/14 19:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 19:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008/04/14 19:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 19:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/14 19:00:00 | 001,267,200 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/09/19 05:29:57 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/09/19 05:29:57 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/09/19 05:29:57 | 000,921,600 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
========== Files - Unicode (All) ==========
[2010/08/11 15:42:47 | 000,000,162 | -H-- | M] ()(C:\Documents and Settings\Admin\Desktop\~$????????.docx) -- C:\Documents and Settings\Admin\Desktop\~$ชาติชาดก.docx
[2010/08/11 15:42:47 | 000,000,162 | -H-- | C] ()(C:\Documents and Settings\Admin\Desktop\~$????????.docx) -- C:\Documents and Settings\Admin\Desktop\~$ชาติชาดก.docx
[2010/07/14 22:58:49 | 000,000,162 | -H-- | M] ()(C:\Documents and Settings\Admin\Desktop\~$?????-??????????????????????.docx) -- C:\Documents and Settings\Admin\Desktop\~$ดเด่น-จุดด้อยของพระพุทธศาสนา.docx
[2010/07/14 22:58:49 | 000,000,162 | -H-- | C] ()(C:\Documents and Settings\Admin\Desktop\~$?????-??????????????????????.docx) -- C:\Documents and Settings\Admin\Desktop\~$ดเด่น-จุดด้อยของพระพุทธศาสนา.docx
========== Alternate Data Streams ==========
@Alternate Data Stream - 241 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

282699C
< End of report >