OTL logfile created on: 26/12/2011 22:03:58 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Dawn\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.24 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 62.89% Memory free
1.46 Gb Paging File | 1.17 Gb Available in Paging File | 79.84% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 3.91 Gb Free Space | 10.50% Space Free | Partition Type: NTFS
Computer Name: DAWN-321 | User Name: Dawn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/12/26 22:00:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\OTL.exe
PRC - [2011/11/27 20:32:45 | 000,129,304 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
PRC - [2011/11/24 14:51:35 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2010/03/14 00:07:59 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/12/07 11:50:52 | 001,584,640 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
========== Modules (No Company Name) ========== MOD - [2010/02/05 18:27:45 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2009/11/03 15:51:42 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2008/04/14 00:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 00:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2006/11/01 12:48:02 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (NMIndexingService)
SRV - File not found [Auto | Stopped] -- -- (LMIRescue_a8da63e7-3f18-4e19-b062-d02d8d19bdf5) LogMeIn Rescue (a8da63e7-3f18-4e19-b062-d02d8d19bdf5)
SRV - File not found [Auto | Stopped] -- -- (LMIRescue_64f4aa97-c861-4b8c-80cf-736d8eacc507) LogMeIn Rescue (64f4aa97-c861-4b8c-80cf-736d8eacc507)
SRV - File not found [On_Demand | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/11/27 20:32:30 | 000,200,632 | ---- | M] (Trend Micro Inc.) [Auto | Stopped] -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe -- (Amsp)
SRV - [2011/11/24 14:51:35 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2011/08/24 15:01:02 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe -- (GoToAssist)
========== Driver Services (SafeList) ========== DRV - [2011/11/27 16:08:33 | 000,205,072 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2011/11/27 16:08:33 | 000,171,280 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tmnciesc.sys -- (tmnciesc)
DRV - [2011/11/27 16:08:33 | 000,092,432 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2011/11/27 16:08:33 | 000,084,752 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tmeext.sys -- (tmeext)
DRV - [2011/11/27 16:08:33 | 000,081,168 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2011/11/27 16:08:33 | 000,068,368 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2011/05/26 15:03:56 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2011/05/26 15:03:50 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2007/05/10 10:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/10/12 15:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/05 11:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 11:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 11:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 11:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80359 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.google.com/ [binary data]
IE - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/IE - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{38783831-6098-4faa-A9C9-1EE1E343F4D2}: C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1086\7.0.1086\firefoxextension [2011/12/25 12:54:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension\ [2011/12/25 12:56:16 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2006/02/28 12:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1086\7.0.1086\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (BT Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O3 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" File not found
O4 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE (SEIKO EPSON CORPORATION)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-515967899-1454471165-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E6A0D015-E3E9-46C6-B593-8A6BD4FCCDDB}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1086\7.0.1086\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\570\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dawn\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dawn\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/13 06:44:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{b8a30803-e870-11dd-a33c-0014228f0df6}\Shell\AutoRun\command - "" = setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== File not found -- C:\WINDOWS\System32\
[2011/12/26 22:00:30 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\OTL.exe
[2011/12/26 21:53:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Desktop\log
[2011/12/26 21:28:18 | 001,918,464 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Dawn\Desktop\aswMBR.exe
[2011/12/26 17:16:58 | 000,000,000 | --SD | C] -- C:\sega15930s
[2011/12/26 17:14:49 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011/12/26 15:07:18 | 000,000,000 | --SD | C] -- C:\sega
[2011/12/26 14:40:23 | 004,348,814 | R--- | C] (Swearware) -- C:\Documents and Settings\Dawn\Desktop\sega.com
[2011/12/26 14:25:19 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\TFC.exe
[2011/12/25 16:21:07 | 000,000,000 | ---D | C] -- C:\Gotcha
[2011/12/25 14:57:03 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdrom.sys
[2011/12/25 14:53:46 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/12/25 14:50:20 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/12/25 14:50:20 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/12/25 14:50:20 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/12/25 14:50:20 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/12/25 14:48:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/12/25 14:46:53 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/25 13:16:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Desktop\RK_Quarantine
[2011/12/22 04:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Desktop\ATTK_ZACCESS_KATUSHA
[2011/12/19 18:17:09 | 002,002,320 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Dawn\Desktop\HousecallLauncher.exe
[2011/12/19 17:19:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Desktop\RootkitBuster_POC_ZACCESS
[2011/12/16 10:42:49 | 008,798,208 | ---- | C] (trend_company_name) -- C:\Documents and Settings\Dawn\Desktop\Copy of RootkitBuster.exe
[2011/12/16 10:40:16 | 008,798,208 | ---- | C] (trend_company_name) -- C:\Documents and Settings\Dawn\Desktop\RootkitBuster.exe
[2011/12/16 10:25:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Desktop\TrendMicro AntiThreat Toolkit
[2011/12/16 09:47:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\backup
[2011/12/16 09:38:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/12/16 08:35:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Application Data\TeamViewer
[2011/12/16 08:35:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 7
[2011/12/16 08:34:59 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2011/12/15 17:00:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Local Settings\Application Data\PCHealth
[2011/12/12 16:55:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Start Menu\Programs\HiJackThis
[2011/12/12 16:38:08 | 002,002,424 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Dawn\My Documents\HousecallLauncher.exe
[2011/12/12 16:32:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Local Settings\Application Data\LogMeIn Rescue Applet
[2011/11/27 16:33:54 | 000,084,752 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmeext.sys
[2011/11/27 16:33:51 | 000,171,280 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmnciesc.sys
[2011/11/27 16:33:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Start Menu\Programs\Trend Micro Titanium Internet Security 2012
[2011/11/27 16:31:31 | 000,092,432 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmtdi.sys
[2011/11/27 16:31:21 | 000,205,072 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/11/27 16:31:21 | 000,081,168 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmactmon.sys
[2011/11/27 16:31:21 | 000,068,368 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmevtmgr.sys
========== Files - Modified Within 30 Days ========== File not found -- C:\WINDOWS\System32\
[2011/12/26 22:00:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\OTL.exe
[2011/12/26 21:55:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/26 21:51:52 | 000,000,506 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\MBR.zip
[2011/12/26 21:47:20 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\MBR.dat
[2011/12/26 21:28:31 | 001,918,464 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Dawn\Desktop\aswMBR.exe
[2011/12/26 14:51:59 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\Word.lnk
[2011/12/26 14:40:24 | 004,348,814 | R--- | M] (Swearware) -- C:\Documents and Settings\Dawn\Desktop\sega.com
[2011/12/26 14:25:31 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\TFC.exe
[2011/12/25 14:53:51 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/12/25 14:30:05 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/12/25 14:28:12 | 000,771,072 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\RogueKiller.exe
[2011/12/25 10:10:42 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/24 22:07:34 | 000,102,400 | ---- | M] () -- C:\WINDOWS\RegBootClean.exe
[2011/12/24 22:07:34 | 000,022,032 | ---- | M] () -- C:\WINDOWS\DCEBoot.exe
[2011/12/24 17:44:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\housecall.guid.cache
[2011/12/24 17:34:33 | 000,008,441 | ---- | M] () -- C:\DAWN-321_2011.12.24-1733.20_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/24 17:26:01 | 000,571,760 | ---- | M] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\census.cache
[2011/12/24 17:25:59 | 000,190,575 | ---- | M] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\ars.cache
[2011/12/21 18:08:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/20 23:54:08 | 000,541,466 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/12/20 23:54:07 | 000,109,916 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/12/19 23:56:39 | 000,022,105 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\Scan 19.12.11.CSV
[2011/12/19 18:17:22 | 002,002,320 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Dawn\Desktop\HousecallLauncher.exe
[2011/12/19 17:34:53 | 025,094,960 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\supportcustomizedpackage.exe
[2011/12/19 17:34:14 | 025,093,769 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\ATTK_ZACCESS_KATUSHA.zip
[2011/12/19 17:20:27 | 004,172,551 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\RootkitBuster_POC_ZACCESS.zip
[2011/12/17 20:57:36 | 000,000,204 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\___GeneratedbyATTK___.zip
[2011/12/17 20:50:47 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\TmRCMScanDebug20111216_00.zip
[2011/12/16 10:37:37 | 000,352,678 | ---- | M] () -- C:\DAWN-321_2011.12.16-1025.53_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/16 10:20:52 | 000,357,189 | ---- | M] () -- C:\DAWN-321_2011.12.16-1005.28_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/16 10:04:59 | 000,355,148 | ---- | M] () -- C:\DAWN-321_2011.12.16-0947.30_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/16 08:35:07 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 7.lnk
[2011/12/15 17:25:17 | 000,256,656 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 17:07:18 | 000,000,129 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2011/12/12 16:38:13 | 002,002,424 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Dawn\My Documents\HousecallLauncher.exe
[2011/12/01 20:48:10 | 008,798,208 | ---- | M] (trend_company_name) -- C:\Documents and Settings\Dawn\Desktop\RootkitBuster.exe
[2011/12/01 20:48:10 | 008,798,208 | ---- | M] (trend_company_name) -- C:\Documents and Settings\Dawn\Desktop\Copy of RootkitBuster.exe
[2011/11/27 16:34:33 | 000,000,932 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\Trend Micro Titanium Internet Security 2012.lnk
[2011/11/27 16:27:49 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\SupportTool.exe.bat
[2011/11/27 16:08:33 | 000,205,072 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/11/27 16:08:33 | 000,171,280 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmnciesc.sys
[2011/11/27 16:08:33 | 000,092,432 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmtdi.sys
[2011/11/27 16:08:33 | 000,084,752 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmeext.sys
[2011/11/27 16:08:33 | 000,081,168 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmactmon.sys
[2011/11/27 16:08:33 | 000,068,368 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2011/11/26 22:25:54 | 000,070,142 | ---- | M] () -- C:\Documents and Settings\Dawn\My Documents\ti_50_MR_2012_Generic.exe
========== Files Created - No Company Name ========== [2011/12/26 21:51:52 | 000,000,506 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\MBR.zip
[2011/12/26 21:47:20 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\MBR.dat
[2011/12/25 14:53:51 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/12/25 14:53:47 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/12/25 14:50:20 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/12/25 14:50:20 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/12/25 14:50:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/12/25 14:50:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/12/25 14:50:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/12/25 14:28:01 | 000,771,072 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\RogueKiller.exe
[2011/12/25 13:16:37 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/12/24 17:34:34 | 000,008,441 | ---- | C] () -- C:\DAWN-321_2011.12.24-1733.20_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/19 23:56:39 | 000,022,105 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\Scan 19.12.11.CSV
[2011/12/17 20:57:36 | 000,000,204 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\___GeneratedbyATTK___.zip
[2011/12/17 20:50:47 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\TmRCMScanDebug20111216_00.zip
[2011/12/16 10:37:37 | 000,352,678 | ---- | C] () -- C:\DAWN-321_2011.12.16-1025.53_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/16 10:25:16 | 025,094,960 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\supportcustomizedpackage.exe
[2011/12/16 10:20:52 | 000,357,189 | ---- | C] () -- C:\DAWN-321_2011.12.16-1005.28_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/16 10:04:59 | 000,355,148 | ---- | C] () -- C:\DAWN-321_2011.12.16-0947.30_4576668b-8ad4-49ca-b73c-acb64488dbf3_3790.zip
[2011/12/16 09:45:52 | 025,093,769 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\ATTK_ZACCESS_KATUSHA.zip
[2011/12/16 09:21:49 | 004,172,551 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\RootkitBuster_POC_ZACCESS.zip
[2011/12/16 08:35:06 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 7.lnk
[2011/11/27 16:33:44 | 000,000,932 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\Trend Micro Titanium Internet Security 2012.lnk
[2011/11/26 22:25:53 | 000,070,142 | ---- | C] () -- C:\Documents and Settings\Dawn\My Documents\ti_50_MR_2012_Generic.exe
[2011/11/26 21:05:59 | 000,102,400 | ---- | C] () -- C:\WINDOWS\RegBootClean.exe
[2011/11/26 21:05:59 | 000,022,032 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2011/11/26 21:05:26 | 000,571,760 | ---- | C] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\census.cache
[2011/11/26 21:05:01 | 000,190,575 | ---- | C] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\ars.cache
[2011/11/24 20:17:18 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\housecall.guid.cache
[2011/11/23 18:07:48 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\SupportTool.exe.bat
[2010/02/02 09:41:57 | 000,001,878 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010/01/23 13:26:20 | 000,053,236 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/08/19 20:43:33 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2009/08/19 20:43:33 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2009/08/19 20:43:33 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2009/08/19 20:43:33 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2009/08/19 20:43:33 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2009/08/19 20:43:33 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2009/08/19 20:43:33 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2009/08/19 20:43:33 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2009/08/19 20:43:33 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2009/08/19 20:43:33 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2009/08/19 20:43:33 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2009/08/19 20:43:33 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2009/08/19 20:43:33 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2009/08/19 20:43:33 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2009/08/19 20:43:33 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2009/08/19 20:43:33 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2009/08/19 20:43:33 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2009/08/19 20:43:33 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/08/19 20:43:33 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009/08/19 20:41:36 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDED92Euro.ini
[2009/02/13 19:22:05 | 000,000,129 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/01/22 11:16:43 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/01/15 11:29:18 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/01/14 04:17:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dawn\Application Data\wklnhst.dat
[2009/01/14 03:59:05 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/01/14 03:36:37 | 000,153,088 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2009/01/14 01:56:12 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2009/01/13 17:52:36 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/13 14:53:18 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2009/01/13 14:53:16 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2009/01/13 14:53:15 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/01/13 07:09:08 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/01/13 06:47:27 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/01/13 06:40:27 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/01/13 06:29:13 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/01/13 06:27:50 | 000,256,656 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/02/28 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/02/28 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/28 12:00:00 | 000,541,466 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/02/28 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/28 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/28 12:00:00 | 000,109,916 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/02/28 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/28 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/28 12:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/28 12:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/02/28 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/02/28 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ========== [2009/08/19 20:41:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2009/01/15 11:29:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/01/21 11:08:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/11/23 16:59:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/19 20:45:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2010/04/14 20:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/26 10:44:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/02 17:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\68CE4
[2010/04/01 14:03:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/22 14:17:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\com.roland.FriendJam
[2009/10/01 17:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\EPSON
[2011/11/22 19:58:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\GetRightToGo
[2010/02/15 10:01:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\IObit
[2011/07/21 10:18:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Sammsoft
[2011/12/16 08:35:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\TeamViewer
[2011/03/17 16:29:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Uniblue
[2009/01/13 15:46:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Windows Desktop Search
[2009/02/21 18:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Windows Search
[2009/01/14 03:33:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\wsInspector
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 11:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 10:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2006/02/28 12:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/04/14 00:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 00:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2006/02/28 12:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >[2006/02/28 12:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 00:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 00:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 00:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2006/02/28 12:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 00:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 00:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/10/31 20:56:25 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/10/31 20:56:25 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/10/31 20:56:25 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/10/31 10:46:00 | 000,634,504 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/10/31 20:56:25 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/10/31 20:56:25 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/10/31 20:56:25 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/10/31 10:46:00 | 000,634,504 | ---- | M] (Microsoft Corporation)
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs[/B] >Invalid Switch: B]
========== Alternate Data Streams ========== @Alternate Data Stream - 24 bytes -> C:\WINDOWS:0B9926B101DF72B8
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >