otl logfile created on: 10/23/2010 11:34:27 am - run 1
otl by oldtimer - version 3.2.17.0 folder = c:\download
windows xp home edition service pack 3 (version = 5.1.2600) - type = ntworkstation
internet explorer (version = 8.0.6001.18702)
locale: 00000409 | country: United states | language: Enu | date format: M/d/yyyy
3.00 gb total physical memory | 2.00 gb available physical memory | 76.00% memory free
5.00 gb paging file | 4.00 gb available in paging file | 85.00% paging file free
paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%systemdrive% = c: | %systemroot% = c:\windows | %programfiles% = c:\program files
drive c: | 465.75 gb total space | 54.54 gb free space | 11.71% space free | partition type: Ntfs
drive d: | 5.52 gb total space | 0.00 gb free space | 0.00% space free | partition type: Udf
computer name: Office | user name: Robert | logged in as administrator.
Boot mode: Normal | scan mode: Current user
company name whitelist: Off | skip microsoft files: Off | no company name whitelist: On | file age = 30 days
========== processes (safelist) ==========
prc - c:\download\otl.exe (oldtimer tools)
prc - c:\program files\avg\avg9\avgtray.exe (avg technologies cz, s.r.o.)
prc - c:\program files\avg\avg9\avgnsx.exe (avg technologies cz, s.r.o.)
prc - c:\program files\common files\real\update_ob\realsched.exe (realnetworks, inc.)
prc - c:\program files\avg\avg9\avgrsx.exe (avg technologies cz, s.r.o.)
prc - c:\program files\avg\avg9\avgwdsvc.exe (avg technologies cz, s.r.o.)
prc - c:\program files\avg\avg9\avgcsrvx.exe (avg technologies cz, s.r.o.)
prc - c:\program files\avg\avg9\avgchsvx.exe (avg technologies cz, s.r.o.)
prc - c:\program files\avg\avg9\avgam.exe (avg technologies cz, s.r.o.)
prc - c:\program files\lavasoft\ad-aware\aawtray.exe (lavasoft)
prc - c:\program files\lavasoft\ad-aware\aawservice.exe (lavasoft)
prc - c:\program files\java\jre6\bin\jucheck.exe (sun microsystems, inc.)
prc - c:\windows\explorer.exe (microsoft corporation)
prc - c:\program files\analog devices\core\smax4pnp.exe (analog devices, inc.)
prc - c:\program files\analog devices\soundmax\smax4.exe (analog devices, inc.)
prc - c:\program files\disney\dreams screensaver\disney.wdpro.dreamsscreensaver.imagedownloader.exe (walt disney internet group)
prc - c:\program files\asus wifi-ap solo\rtwlan.exe (asustek computer inc.)
prc - c:\program files\sec\natural color pro\ncprotray.exe (samsung)
========== modules (safelist) ==========
mod - c:\download\otl.exe (oldtimer tools)
mod - c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (microsoft corporation)
mod - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\chrome\hook\rpchromebrowserrecordhelper.dll ()
mod - c:\windows\system32\msvbvm60.dll (microsoft corporation)
mod - c:\windows\system32\dinput.dll (microsoft corporation)
========== win32 services (safelist) ==========
srv - (appmgmt) -- c:\windows\system32\appmgmts.dll file not found
srv - (avg9wd) -- c:\program files\avg\avg9\avgwdsvc.exe (avg technologies cz, s.r.o.)
srv - (lavasoft ad-aware service) -- c:\program files\lavasoft\ad-aware\aawservice.exe (lavasoft)
srv - (daupdatersvc) -- c:\program files\dragon age\bin_ship\daupdatersvc.service.exe (bioware)
========== driver services (safelist) ==========
drv - (ncpro) -- c:\windows\system32\drivers\mtictwl.sys file not found
drv - (magictune) -- c:\windows\system32\drivers\mtictwl.sys file not found
drv - (btkrnl) -- c:\windows\system32\drivers\btkrnl.sys file not found
drv - (avgtdix) -- c:\windows\system32\drivers\avgtdix.sys (avg technologies cz, s.r.o.)
drv - (avgldx86) -- c:\windows\system32\drivers\avgldx86.sys (avg technologies cz, s.r.o.)
drv - (avgmfx86) -- c:\windows\system32\drivers\avgmfx86.sys (avg technologies cz, s.r.o.)
drv - (avgrkx86) -- c:\windows\system32\drivers\avgrkx86.sys (avg technologies cz, s.r.o.)
drv - (ati2mtag) -- c:\windows\system32\drivers\ati2mtag.sys (ati technologies inc.)
drv - (lbd) -- c:\windows\system32\drivers\lbd.sys (lavasoft ab)
drv - (asio) -- c:\windows\system32\drivers\asio.sys ()
drv - (mtsensor) -- c:\windows\system32\drivers\asacpi.sys ()
drv - (rtl8023xp) -- c:\windows\system32\drivers\rtnicxp.sys (realtek semiconductor corporation )
drv - (atihdmiservice) -- c:\windows\system32\drivers\atihdmi.sys (ati research inc.)
drv - (jraid) -- c:\windows\system32\drivers\jraid.sys (jmicron technology corp.)
drv - (usbpnpa) -- c:\windows\system32\drivers\cm108.sys (c-media electronics inc)
drv - (kmwdfilter) -- c:\windows\system32\drivers\kmwdfilter.sys (windows (r) codename longhorn ddk provider)
drv - (rtlwusb) -- c:\windows\system32\drivers\rtl8187.sys (realtek semiconductor corporation )
drv - (hdaudbus) -- c:\windows\system32\drivers\hdaudbus.sys (windows (r) server 2003 ddk provider)
drv - (usbaudio) usb audio driver (wdm) -- c:\windows\system32\drivers\usbaudio.sys (microsoft corporation)
drv - (adihdaudaddservice) -- c:\windows\system32\drivers\adihdaud.sys (analog devices, inc.)
drv - (hdaudaddservice) -- c:\windows\system32\drivers\atihdaud.sys (ati research inc.)
drv - (hamachi_oem) -- c:\windows\system32\drivers\gan_adapter.sys (applied networking inc.)
drv - (yukonwxp) -- c:\windows\system32\drivers\yk51x86.sys (marvell)
drv - (xnacc) -- c:\windows\system32\drivers\xnacc.sys (microsoft corporation)
drv - (sjypkt) -- c:\windows\system32\drivers\sjypkt.sys (windows (r) 2000 ddk provider)
drv - (senfiltservice) -- c:\windows\system32\drivers\senfilt.sys (sensaura)
drv - (ubohci) -- c:\windows\system32\drivers\ubohci.sys (unibrain s.a.)
drv - (ubumapi) -- c:\windows\system32\drivers\ubumapi.sys (unibrain s.a.)
drv - (ubsbm) -- c:\windows\system32\drivers\ubsbm.sys (unibrain s.a.)
drv - (brscnusb) -- c:\windows\system32\drivers\brscnusb.sys (brother industries ltd.)
drv - (usb-100) -- c:\windows\system32\drivers\rtl8150.sys (realtek )
========== standard registry (safelist) ==========
========== internet explorer ==========
ie - hklm\software\microsoft\internet explorer\search,default_search_url =
http://www.google.com/ie
ie - hklm\software\microsoft\internet explorer\search,searchassistant =
http://www.google.com/ie
ie - hkcu\software\microsoft\internet explorer\main,search page =
http://www.google.com
ie - hkcu\software\microsoft\internet explorer\main,searchmigrateddefaultname = google
ie - hkcu\software\microsoft\internet explorer\main,searchmigrateddefaulturl = http://www.google.com/search?q={searchterms}&sourceid=ie7&rls=com.microsoft:en-us&ie=utf8&oe=utf8
ie - hkcu\software\microsoft\internet explorer\main,start page =
http://www.facebook.com/home.php
ie - hkcu\software\microsoft\internet explorer\search,searchassistant =
http://www.google.com/ie
ie - hkcu\software\microsoft\windows\currentversion\internet settings: "proxyenable" = 0
ie - hkcu\software\microsoft\windows\currentversion\internet settings: "proxyoverride" = <local>
ie - hkcu\software\microsoft\windows\currentversion\internet settings: "proxyserver" = 192.104.67.250:8080
ff - hklm\software\mozilla\firefox\extensions\\{abde892b-13a8-4d1b-88e6-365a6e755758}: C:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext [2010/07/13 19:50:40 | 000,000,000 | ---d | m]
o1 hosts file: ([2008/04/14 08:00:00 | 000,000,734 | ---- | m]) - c:\windows\system32\drivers\etc\hosts
o1 - hosts: 127.0.0.1 localhost
o2 - bho: (realplayer download and record plugin for internet explorer) - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll (realplayer)
o2 - bho: (avg safe search) - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll (avg technologies cz, s.r.o.)
o2 - bho: (browser helper object) - {afd4ad01-58c1-47db-a404-fbe00a6c5486} - c:\program files\shared\lib.dll file not found
o3 - hklm\..\toolbar: (no name) - {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - no clsid value found.
O3 - hkcu\..\toolbar\webbrowser: (no name) - {4f11acbb-393f-4c86-a214-ff3d0d155cc3} - no clsid value found.
O3 - hkcu\..\toolbar\webbrowser: (no name) - {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - no clsid value found.
O3 - hkcu\..\toolbar\webbrowser: (no name) - {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - no clsid value found.
O4 - hklm..\run: [36x raid configurer] c:\windows\system32\xraidsetup.exe (jmicron technology corp.)
o4 - hklm..\run: [ad-watch] c:\program files\lavasoft\ad-aware\aawtray.exe (lavasoft)
o4 - hklm..\run: [avg9_tray] c:\program files\avg\avg9\avgtray.exe (avg technologies cz, s.r.o.)
o4 - hklm..\run: [cm108sound] file not found
o4 - hklm..\run: [cmusbsound] file not found
o4 - hklm..\run: [family tree builder update] c:\program files\myheritage\bin\ftbcheckupdates.exe (myheritage)
o4 - hklm..\run: [imagedownloader] c:\program files\disney\dreams screensaver\disney.wdpro.dreamsscreensaver.imagedownloader.exe (walt disney internet group)
o4 - hklm..\run: [jmb36x ide setup] c:\windows\raidtool\xinside.exe ()
o4 - hklm..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe (nero ag)
o4 - hklm..\run: [soundmax] c:\program files\analog devices\soundmax\smax4.exe (analog devices, inc.)
o4 - hklm..\run: [soundmaxpnp] c:\program files\analog devices\core\smax4pnp.exe (analog devices, inc.)
o4 - hklm..\run: [startccc] c:\program files\ati technologies\ati.ace\core-static\clistart.exe (advanced micro devices, inc.)
o4 - hklm..\run: [tkbellexe] c:\program files\common files\real\update_ob\realsched.exe (realnetworks, inc.)
o4 - hklm..\run: [turbine download manager tray icon] c:\program files\turbine\turbine download manager\turbinedownloadmanagericon.exe file not found
o4 - hkcu..\run: [igndlm.exe] c:\program files\download manager\dlm.exe (ign entertainment)
o4 - hkcu..\run: [steam] c:\program files\steam\steam.exe (valve corporation)
o4 - startup: C:\documents and settings\all users\start menu\programs\startup\asus wifi-ap solo.lnk = c:\program files\asus wifi-ap solo\rtwlan.exe (asustek computer inc.)
o4 - startup: C:\documents and settings\all users\start menu\programs\startup\ncprotray.lnk = c:\program files\sec\natural color pro\ncprotray.exe (samsung)
o4 - startup: C:\documents and settings\robert\start menu\programs\startup\curseclientstartup.ccip ()
o4 - startup: C:\documents and settings\robert\start menu\programs\startup\disney vacation connection.lnk = c:\program files\disney vacation connection\disney vacation connection.exe ()
o4 - startup: C:\documents and settings\robert\start menu\programs\startup\registration .lnk = c:\program files\ubisoft\dark messiah of might and magic\registrationreminder.exe file not found
o6 - hklm\software\microsoft\windows\currentversion\policies\explorer: Honorautorunsetting = 1
o7 - hkcu\software\microsoft\windows\currentversion\policies\explorer: Nodrivetypeautorun = 145
o9 - extra button: Pokerstars - {3ad14f0c-ed16-4e43-b6d8-661b03f6a1ef} - c:\program files\pokerstars\pokerstarsupdate.exe (pokerstars)
o15 - hkcu\..trusted domains: Live.com ([login] http in trusted sites)
o15 - hkcu\..trusted domains: Youtube.com ([www] http in trusted sites)
o16 - dpf: {0d41b8c5-2599-4893-8183-00195ec8d5f9}
http://support.asus.com/common/asustek_sys_ctrl.cab (asustek_sysctrl class)
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700}
http://download.microsoft.com/downl...-48d9-9b0e-1719d1177202/legitcheckcontrol.cab (windows genuine advantage validation tool)
o16 - dpf: {39b0684f-d7bf-4743-b050-fdc3f48f7e3b}
http://www.fileplanet.com/fpdlmgr/cabs/fpdc_2.3.10.115.cab (cdownloadctrl object)
o16 - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537}
http://gfx1.hotmail.com/mail/w3/resources/msnpupld.cab (msn photo upload tool)
o16 - dpf: {6218f7b5-0d3a-48ba-ae4c-49dcfa63d400}
http://www.myheritage.com/genoogle/components/activex/searchenginequery.dll (csequeryobject object)
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c}
http://update.microsoft.com/windowsupdate/v6/v5controls/en/x86/client/wuweb_site.cab?1240419885734 (wuwebcontrol class)
o16 - dpf: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3}
http://update.microsoft.com/microsoftupdate/v6/v5controls/en/x86/client/muweb_site.cab?1240419964187 (muwebcontrol class)
o16 - dpf: {8100d56a-5661-482c-bee8-afece305d968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/facebookphotouploader55.cab (facebook photo uploader 5 control)
o16 - dpf: {8ad9c840-044e-11d1-b3e9-00805f499d93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (java plug-in 1.6.0_15)
o16 - dpf: {8ffbe65d-2c9c-4669-84bd-5829dc0b603c}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (reg error: Key error.)
o16 - dpf: {cafeefac-0016-0000-0015-abcdeffedcba}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (java plug-in 1.6.0_15)
o16 - dpf: {cafeefac-ffff-ffff-ffff-abcdeffedcba}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (java plug-in 1.6.0_15)
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553550000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (reg error: Key error.)
o16 - dpf: {e2883e8f-472f-4fb0-9522-ac9bf37916a7}
http://platformdl.adobe.com/nos/getplusplus/1.6/gp.cab (reg error: Key error.)
o17 - hklm\system\ccs\services\tcpip\parameters: Dhcpnameserver = 192.168.2.1
o17 - hklm\system\ccs\services\tcpip\parameters: Nameserver = 93.188.162.249,93.188.160.59
o18 - protocol\handler\linkscanner {f274614c-63f8-47d5-a4d1-fbdde494f8d1} - c:\program files\avg\avg9\avgpp.dll (avg technologies cz, s.r.o.)
o18 - protocol\handler\skype4com {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\program files\common files\skype\skype4com.dll (skype technologies)
o20 - hklm winlogon: Shell - (explorer.exe) - c:\windows\explorer.exe (microsoft corporation)
o20 - winlogon\notify\atiextevent: Dllname - ati2evxx.dll - c:\windows\system32\ati2evxx.dll (ati technologies inc.)
o20 - winlogon\notify\avgrsstarter: Dllname - avgrsstx.dll - c:\windows\system32\avgrsstx.dll (avg technologies cz, s.r.o.)
o24 - desktop wallpaper: C:\documents and settings\robert\application data\microsoft\internet explorer\internet explorer wallpaper.bmp
o24 - desktop backupwallpaper: C:\documents and settings\robert\application data\microsoft\internet explorer\internet explorer wallpaper.bmp
o32 - hklm cdrom: Autorun - 1
o32 - autorun file - [2009/04/22 11:25:19 | 000,000,000 | ---- | m] () - c:\autoexec.bat -- [ ntfs ]
o32 - autorun file - [2008/09/08 17:13:25 | 000,000,058 | r--- | m] () - d:\autorun.inf -- [ udf ]
o33 - mountpoints2\##vikki#vikki\shell - "" = autorun
o33 - mountpoints2\##vikki#vikki\shell\autorun - "" = auto&play
o33 - mountpoints2\##vikki#vikki\shell\autorun\command - "" = z:\x3xh.exe -- file not found
o33 - mountpoints2\##vikki#vikki\shell\open\command - "" = z:\x3xh.exe -- file not found
o33 - mountpoints2\{55f4f74d-4c4a-11df-be04-001d60b163ce}\shell\autorun\command - "" = h:\get_started_for_win.exe -- file not found
o33 - mountpoints2\{877f949f-4016-11df-be02-001d60b163ce}\shell\autorun\command - "" = i:\scct_launcher.exe -- file not found
o33 - mountpoints2\{ac1848c2-2f2d-11de-aea4-806d6172696f}\shell - "" = autorun
o33 - mountpoints2\{ac1848c2-2f2d-11de-aea4-806d6172696f}\shell\autorun - "" = auto&play
o33 - mountpoints2\{ac1848c2-2f2d-11de-aea4-806d6172696f}\shell\autorun\command - "" = d:\falloutlauncher.exe -- [2008/09/18 14:38:35 | 006,981,048 | r--- | m] (bethesda softworks)
o33 - mountpoints2\{c54e4336-21e3-11df-bdfc-001d60b163ce}\shell\autorun\command - "" = 9qqigqwf.exe
o33 - mountpoints2\{c54e4336-21e3-11df-bdfc-001d60b163ce}\shell\open\command - "" = 9qqigqwf.exe
o34 - hklm bootexecute: (autocheck autochk *) - file not found
o34 - hklm bootexecute: (lsdelete) - c:\windows\system32\lsdelete.exe ()
o35 - hklm\..comfile [open] -- "%1" %*
o35 - hklm\..exefile [open] -- "%1" %*
o37 - hklm\...com [@ = comfile] -- "%1" %*
o37 - hklm\...exe [@ = exefile] -- "%1" %*
netsvcs: 6to4 - file not found
netsvcs: Appmgmt - c:\windows\system32\appmgmts.dll file not found
netsvcs: Ias - file not found
netsvcs: Iprip - file not found
netsvcs: Irmon - file not found
netsvcs: Nwcworkstation - file not found
netsvcs: Nwsapagent - file not found
netsvcs: Wmdmpmsp - file not found
drivers32: Msacm.ac3acm - c:\windows\system32\ac3acm.acm (fcchandler)
drivers32: Msacm.alf2cd - c:\windows\system32\alf2cd.acm (nct company)
drivers32: Msacm.iac2 - c:\windows\system32\iac25_32.ax (intel corporation)
drivers32: Msacm.l3acm - c:\windows\system32\l3codeca.acm (fraunhofer institut integrierte schaltungen iis)
drivers32: Msacm.scg726 - c:\windows\system32\scg726.acm (sharp corporation)
drivers32: Msacm.sl_anet - c:\windows\system32\sl_anet.acm (sipro lab telecom inc.)
drivers32: Msacm.trspch - c:\windows\system32\tssoft32.acm (dsp group, inc.)
drivers32: Msacm.voxacm160 - c:\windows\system32\vct3216.acm (voxware, inc.)
drivers32: Vidc.cvid - c:\windows\system32\iccvid.dll (radius inc.)
drivers32: Vidc.divx - c:\windows\system32\divx.dll (divx, inc.)
drivers32: Vidc.dvsd - c:\windows\system32\mcdvd_32.dll (mainconcept)
drivers32: Vidc.ffds - c:\windows\system32\ff_vfw.dll ()
drivers32: Vidc.fps1 - c:\windows\system32\frapsvid.dll (beepa p/l)
drivers32: Vidc.iv31 - c:\windows\system32\ir32_32.dll ()
drivers32: Vidc.iv32 - c:\windows\system32\ir32_32.dll ()
drivers32: Vidc.iv41 - c:\windows\system32\ir41_32.ax ()
drivers32: Vidc.iv50 - c:\windows\system32\ir50_32.dll ()
drivers32: Vidc.xvid - c:\windows\system32\xvidvfw.dll ()
drivers32: Vidc.yv12 - c:\windows\system32\divx.dll (divx, inc.)
createrestorepoint
restore point set: Otl restore point (81641353997451264)
========== files/folders - created within 30 days ==========
[2010/09/29 20:16:06 | 000,000,000 | ---d | c] -- c:\program files\starcraft ii
[2010/09/29 20:16:06 | 000,000,000 | ---d | c] -- c:\documents and settings\robert\my documents\starcraft ii
[5 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
[1 c:\windows\system32\*.tmp files -> c:\windows\system32\*.tmp -> ]
========== files - modified within 30 days ==========
[2010/10/23 11:34:07 | 000,000,288 | ---- | m] () -- c:\windows\tasks\realupgradescheduledtasks-1-5-21-746137067-1229272821-1801674531-1004.job
[2010/10/23 11:34:07 | 000,000,280 | ---- | m] () -- c:\windows\tasks\realupgradelogontasks-1-5-21-746137067-1229272821-1801674531-1004.job
[2010/10/23 11:24:58 | 000,000,424 | -h-- | m] () -- c:\windows\tasks\user_feed_synchronization-{828a94af-0ac4-4ae2-9d22-849cac953923}.job
[2010/10/23 11:15:00 | 000,000,982 | ---- | m] () -- c:\windows\tasks\googleupdatetaskusers-1-5-21-746137067-1229272821-1801674531-1004ua.job
[2010/10/23 11:09:16 | 000,000,310 | ---- | m] () -- c:\windows\tasks\orb index when idle.job
[2010/10/23 11:06:00 | 000,000,886 | ---- | m] () -- c:\windows\tasks\googleupdatetaskmachineua.job
[2010/10/23 09:06:00 | 000,000,882 | ---- | m] () -- c:\windows\tasks\googleupdatetaskmachinecore.job
[2010/10/23 08:28:18 | 066,727,532 | ---- | m] () -- c:\windows\system32\drivers\avg\incavi.avm
[2010/10/23 05:15:00 | 000,000,930 | ---- | m] () -- c:\windows\tasks\googleupdatetaskusers-1-5-21-746137067-1229272821-1801674531-1004core.job
[2010/10/22 23:04:54 | 000,012,656 | ---- | m] () -- c:\windows\system32\wpa.dbl
[2010/10/22 19:33:02 | 000,000,472 | ---- | m] () -- c:\windows\tasks\ad-aware update (weekly).job
[2010/10/21 21:48:31 | 000,002,048 | --s- | m] () -- c:\windows\bootstat.dat
[2010/10/20 19:38:00 | 000,012,598 | ---- | m] () -- c:\windows\system32\wpa.bak
[2010/10/20 11:08:01 | 000,000,284 | ---- | m] () -- c:\windows\tasks\applesoftwareupdate.job
[2010/10/19 00:16:04 | 000,000,000 | ---- | m] () -- c:\documents and settings\robert\application data\avsdvdplayer.m3u
[2010/10/14 23:11:53 | 000,003,063 | ---- | m] () -- c:\documents and settings\robert\.recently-used.xbel
[2010/10/14 18:43:58 | 000,032,768 | ---- | m] () -- c:\documents and settings\robert\my documents\dis meals.xls
[2010/10/14 18:21:36 | 000,089,088 | ---- | m] () -- c:\documents and settings\robert\local settings\application data\dcbc2a71-70d8-4dan-ehr8-e0d61dea3fdf.ini
[2010/10/14 16:54:03 | 000,195,368 | ---- | m] () -- c:\windows\system32\fntcache.dat
[2010/10/14 03:14:20 | 000,001,393 | ---- | m] () -- c:\windows\imsins.bak
[2010/10/14 00:02:33 | 000,000,650 | ---- | m] () -- c:\windows\pagebreeze.ini
[2010/10/13 21:05:06 | 000,000,048 | ---- | m] () -- c:\windows\.prj
[2010/10/10 11:48:50 | 000,001,539 | ---- | m] () -- c:\documents and settings\all users\desktop\vuze.lnk
[2010/10/08 03:05:13 | 000,444,358 | ---- | m] () -- c:\windows\system32\perfh009.dat
[2010/10/08 03:05:13 | 000,072,108 | ---- | m] () -- c:\windows\system32\perfc009.dat
[2010/10/03 20:20:21 | 000,000,069 | ---- | m] () -- c:\windows\nerodigital.ini
[2010/10/03 16:51:58 | 000,039,424 | ---- | m] () -- c:\documents and settings\robert\my documents\robert w taylor.doc
[2010/10/03 15:45:56 | 000,266,752 | ---- | m] () -- c:\documents and settings\robert\my documents\vikki licence.doc
[2010/09/30 13:21:48 | 000,000,664 | ---- | m] () -- c:\windows\system32\d3d9caps.dat
[2010/09/29 21:48:10 | 000,000,802 | ---- | m] () -- c:\documents and settings\all users\desktop\starcraft ii.lnk
[2010/09/25 20:04:06 | 000,001,949 | ---- | m] () -- c:\documents and settings\all users\desktop\google earth.lnk
[5 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
[1 c:\windows\system32\*.tmp files -> c:\windows\system32\*.tmp -> ]
========== files created - no company name ==========
[2010/10/18 21:10:39 | 000,001,884 | ---- | c] () -- c:\documents and settings\robert\desktop\fallout 3.lnk
[2010/10/14 23:11:53 | 000,003,063 | ---- | c] () -- c:\documents and settings\robert\.recently-used.xbel
[2010/10/14 18:43:58 | 000,032,768 | ---- | c] () -- c:\documents and settings\robert\my documents\dis meals.xls
[2010/10/10 11:48:50 | 000,001,539 | ---- | c] () -- c:\documents and settings\all users\desktop\vuze.lnk
[2010/10/03 16:51:58 | 000,039,424 | ---- | c] () -- c:\documents and settings\robert\my documents\robert w taylor.doc
[2010/10/03 15:45:55 | 000,266,752 | ---- | c] () -- c:\documents and settings\robert\my documents\vikki licence.doc
[2010/09/29 20:16:06 | 000,000,802 | ---- | c] () -- c:\documents and settings\all users\desktop\starcraft ii.lnk
[2010/09/25 20:04:06 | 000,001,949 | ---- | c] () -- c:\documents and settings\all users\desktop\google earth.lnk
[2010/08/30 19:19:20 | 000,000,650 | ---- | c] () -- c:\windows\pagebreeze.ini
[2010/08/30 19:19:20 | 000,000,044 | ---- | c] () -- c:\windows\formbreeze.ini
[2010/07/13 19:51:32 | 000,000,025 | ---- | c] () -- c:\windows\cdplayer.ini
[2010/04/02 17:17:34 | 000,179,091 | ---- | c] () -- c:\windows\system32\xlive.dll.cat
[2010/03/31 17:24:22 | 000,000,674 | ---- | c] () -- c:\documents and settings\robert\application data\mympq.ini
[2010/01/28 21:10:29 | 000,000,600 | ---- | c] () -- c:\documents and settings\robert\application data\winscp.rnd
[2010/01/28 20:38:42 | 000,000,251 | ---- | c] () -- c:\windows\myheritage.ini
[2010/01/28 20:36:53 | 000,454,656 | ---- | c] () -- c:\windows\system32\paintx.dll
[2009/10/19 10:55:31 | 000,138,464 | ---- | c] () -- c:\windows\system32\drivers\pnkbstrk.sys
[2009/10/19 10:55:30 | 000,022,328 | ---- | c] () -- c:\documents and settings\robert\application data\pnkbstrk.sys
[2009/09/16 17:19:38 | 000,000,129 | ---- | c] () -- c:\documents and settings\robert\local settings\application data\fusioncache.dat
[2009/05/29 21:56:45 | 000,000,376 | ---- | c] () -- c:\windows\odbc.ini
[2009/05/19 19:43:02 | 000,089,088 | ---- | c] () -- c:\documents and settings\robert\local settings\application data\dcbc2a71-70d8-4dan-ehr8-e0d61dea3fdf.ini
[2009/05/03 21:52:57 | 000,000,062 | ---- | c] () -- c:\windows\cm108.ini.cfl
[2009/05/03 21:52:37 | 000,000,939 | r--- | c] () -- c:\windows\cm108.ini.cfg
[2009/05/03 21:52:36 | 000,001,096 | r--- | c] () -- c:\windows\cm108.ini
[2009/04/30 22:40:14 | 000,000,000 | ---- | c] () -- c:\documents and settings\robert\application data\avsdvdplayer.m3u
[2009/04/30 22:37:11 | 000,524,288 | ---- | c] () -- c:\windows\system32\xvidcore.dll
[2009/04/30 22:37:11 | 000,139,264 | ---- | c] () -- c:\windows\system32\xvidvfw.dll
[2009/04/30 22:30:43 | 000,084,480 | ---- | c] () -- c:\windows\system32\ff_vfw.dll
[2009/04/30 22:22:10 | 000,000,069 | ---- | c] () -- c:\windows\nerodigital.ini
[2009/04/28 21:53:09 | 000,000,262 | ---- | c] () -- c:\windows\{789289ca-f73a-4a16-a331-54d498ce069f}_wisefw.ini
[2009/04/28 00:11:36 | 000,354,816 | ---- | c] () -- c:\windows\system32\psisdecd.dll
[2009/04/27 20:12:52 | 000,045,056 | ---- | c] () -- c:\windows\system32\cmdrvrmu.dll
[2009/04/27 20:12:52 | 000,004,899 | ---- | c] () -- c:\windows\cmudau.ini
[2009/04/27 17:15:18 | 000,000,044 | ---- | c] () -- c:\windows\system32\msssc.dll
[2009/04/27 16:28:55 | 000,000,419 | ---- | c] () -- c:\windows\brwmark.ini
[2009/04/27 16:28:55 | 000,000,027 | ---- | c] () -- c:\windows\brpp2ka.ini
[2009/04/22 12:41:01 | 000,024,576 | ---- | c] () -- c:\windows\system32\asio.dll
[2009/04/22 12:41:01 | 000,012,400 | ---- | c] () -- c:\windows\system32\drivers\asio.sys
[2009/04/22 07:09:43 | 000,004,161 | ---- | c] () -- c:\windows\odbcinst.ini
[2009/03/03 12:18:04 | 000,073,728 | ---- | c] () -- c:\windows\system32\rtnicprop32.dll
[2008/10/07 10:13:30 | 000,197,912 | ---- | c] () -- c:\windows\system32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpaneltraditionalchinese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelswedish.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelspanish.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelsimplifiedchinese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelportugese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelkorean.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpaneljapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelgerman.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | c] () -- c:\windows\system32\agcpanelfrench.dll
[2008/04/14 08:00:00 | 000,755,200 | ---- | c] () -- c:\windows\system32\ir50_32.dll
[2008/04/14 08:00:00 | 000,338,432 | ---- | c] () -- c:\windows\system32\ir41_qcx.dll
[2008/04/14 08:00:00 | 000,200,192 | ---- | c] () -- c:\windows\system32\ir50_qc.dll
[2008/04/14 08:00:00 | 000,183,808 | ---- | c] () -- c:\windows\system32\ir50_qcx.dll
[2008/04/14 08:00:00 | 000,120,320 | ---- | c] () -- c:\windows\system32\ir41_qc.dll
[2007/05/24 12:20:34 | 000,014,848 | ---- | c] () -- c:\windows\system32\disney.wdpro.dreamsscreensaver.directshow.dll
[2004/08/13 18:56:20 | 000,005,810 | ---- | c] () -- c:\windows\system32\drivers\asacpi.sys
========== custom scans ==========
< %systemdrive%\*.* >
[2010/10/21 21:48:23 | 000,028,668 | ---- | m] () -- c:\aaw7boot.log
[2009/04/22 11:25:19 | 000,000,000 | ---- | m] () -- c:\autoexec.bat
[2009/04/22 11:20:40 | 000,000,211 | -hs- | m] () -- c:\boot.ini
[2009/04/22 11:25:19 | 000,000,000 | ---- | m] () -- c:\config.sys
[2010/02/03 20:06:14 | 000,031,232 | ---- | m] () -- c:\copy of movies.xls
[2009/04/22 11:25:19 | 000,000,000 | rhs- | m] () -- c:\io.sys
[2009/04/22 11:25:19 | 000,000,000 | rhs- | m] () -- c:\msdos.sys
[2008/04/14 08:00:00 | 000,047,564 | rhs- | m] () -- c:\ntdetect.com
[2008/04/14 08:00:00 | 000,250,048 | rhs- | m] () -- c:\ntldr
[2010/07/15 14:32:31 | 000,000,689 | ---- | m] () -- c:\output.log
[2010/10/21 21:48:27 | 2145,386,496 | -hs- | m] () -- c:\pagefile.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\config\*.sav >
[2009/04/22 07:06:04 | 000,094,208 | ---- | m] () -- c:\windows\system32\config\default.sav
[2009/04/22 07:06:04 | 001,064,960 | ---- | m] () -- c:\windows\system32\config\software.sav
[2009/04/22 07:06:04 | 000,942,080 | ---- | m] () -- c:\windows\system32\config\system.sav
< hkey_local_machine\software\policies\microsoft\windows\windowsupdate\au >
< hkey_local_machine\software\microsoft\windows\currentversion\windowsupdate\auto update\results\install|lastsuccesstime /rs >
hkey_local_machine\software\microsoft\windows\currentversion\windowsupdate\auto update\results\install\\lastsuccesstime: 2010-10-14 07:14:33
< end of report >