Thanks for adding, let me open those up.
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.16.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
brian adrian :: DHYG34D1 [administrator]
2/4/2012 7:54:50 PM
mbam-log-2012-02-04 (19-54-50).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 346058
Time elapsed: 1 hour(s), 43 minute(s), 53 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 6
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{258C9770-1713-4021-8D7E-1F184A2BD754} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB38E21A-0133-419D-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKCU\Software\hblitesa (Adware.HotBar) -> Quarantined and deleted successfully.
HKCU\Software\ShoppingReport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKCU\Software\voomuusa (Adware.HotBar.VM) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
OTL logfile created on: 2/5/2012 5:59:00 PM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = F:\PC Security
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.85 Mb Total Physical Memory | 611.12 Mb Available Physical Memory | 59.81% Memory free
2.40 Gb Paging File | 2.12 Gb Available in Paging File | 88.43% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.77 Gb Total Space | 174.55 Gb Free Space | 75.97% Space Free | Partition Type: NTFS
Drive E: | 2.16 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 7.45 Gb Total Space | 3.70 Gb Free Space | 49.66% Space Free | Partition Type: FAT32
Computer Name: DHYG34D1 | User Name: brian adrian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011/06/15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/05/26 17:21:02 | 000,580,096 | ---- | M] (OldTimer Tools) -- F:\PC Security\OTL.exe
PRC - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2009/03/05 19:57:33 | 000,108,544 | ---- | M] (iWin Inc.) -- C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/28 20:57:12 | 000,395,776 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2011/05/26 17:21:02 | 000,580,096 | ---- | M] (OldTimer Tools) -- F:\PC Security\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/11/12 11:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) [Disabled | Stopped] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2006/07/06 06:14:30 | 000,090,112 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2004/03/18 15:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2001/08/09 14:46:44 | 000,064,512 | -H-- | M] (America Online, Inc.) [Disabled | Stopped] -- C:\WINDOWS\system32\PackethSvc.exe -- (PackethSvc)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2012/02/05 16:21:55 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D040817-915A-42EC-AD3D-6CB3A96E1BCD}\MpKsl70a179f7.sys -- (MpKsl70a179f7)
DRV - [2009/12/16 13:13:38 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/12/16 13:13:34 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2009/11/10 09:27:06 | 000,018,560 | ---- | M] (LeapFrog) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FlyUsb.sys -- (FlyUsb)
DRV - [2008/05/05 20:30:40 | 000,104,704 | R--- | M] (Dynex ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/03/04 10:31:02 | 000,271,360 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2008/03/04 10:31:01 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2006/07/24 09:20:00 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/06/07 14:08:58 | 001,580,544 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/01/10 10:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/09/08 04:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/09/08 04:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/09/08 04:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/09/08 04:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/09/08 04:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/09/08 04:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/09/08 04:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/08/25 11:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/08/25 11:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2003/11/17 13:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 13:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 13:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2001/08/09 16:26:02 | 000,022,608 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wandrv.sys -- (wandrv)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070620
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »
www.google.com/hws/sb/dell-usuk-···annel=usIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »
www.yahoo.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = »
search.bearshare.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2012/01/16 12:01:52 | 000,000,698 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {167D9323-F7CC-48F5-948A-6F012831A69F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] File not found
O4 - HKCU..\Run: [Weather] File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\brian adrian\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe (iWin Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@install.mar@ ([]msni in My Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msni in Local intranet)
O15 - HKCU\..Trusted Domains: compuserve.com ([]* is out of zone range - 5)
O15 - HKCU\..Trusted Domains: compuserve.com ([objects] * is out of zone range - 6)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} »
fpdownload.macromedia.com/get/fl···shim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} »
java.sun.com/update/1.5.0/jinsta···i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} »
platformdl.adobe.com/NOS/getPlus···6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\brian adrian\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\brian adrian\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/01/13 21:22:40 | 000,000,000 | R--D | M] - E:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2007/01/13 20:35:44 | 000,630,784 | R--- | M] (Electronic Arts Inc.) - E:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2007/01/13 21:13:20 | 000,000,156 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2007/01/13 15:30:07 | 000,585,728 | R--- | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll -- [ UDF ]
O33 - MountPoints2\{5fff9d53-dc4c-11de-9272-00038a000011}\Shell - "" = AutoRun
O33 - MountPoints2\{5fff9d53-dc4c-11de-9272-00038a000011}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5fff9d53-dc4c-11de-9272-00038a000011}\Shell\AutoRun\command - "" = J:\PhotoViewer.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/02/05 17:52:42 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/02/05 17:49:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/05 17:48:05 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/02/05 14:44:00 | 000,104,704 | R--- | C] (Dynex ) -- C:\WINDOWS\System32\drivers\Rtnicxp.sys
[2012/02/05 14:43:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\OPTIONS
[2012/02/05 14:43:51 | 000,000,000 | ---D | C] -- C:\Program Files\Dynex
[2012/02/05 14:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\brian adrian\Application Data\InstallShield
[2012/02/04 19:54:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\brian adrian\Application Data\Malwarebytes
[2012/02/03 20:11:10 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/01/17 14:49:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/01/16 12:04:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/01/16 11:20:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/16 11:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/02/05 17:49:19 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/05 16:26:55 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/05 16:21:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/05 16:21:44 | 1071,562,752 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/04 13:49:31 | 000,002,211 | ---- | M] () -- C:\Documents and Settings\brian adrian\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk
[2012/02/04 13:40:00 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/03 20:08:30 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\brian adrian\Desktop\Windows Media Player.lnk
[2012/01/29 20:19:46 | 000,022,729 | ---- | M] () -- C:\newkey
[2012/01/29 20:19:46 | 000,022,729 | ---- | M] () -- C:\newfile.enc
[2012/01/26 22:27:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/16 14:10:24 | 000,002,319 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RescueIT Calling Card.lnk
[2012/01/16 12:45:50 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/16 12:02:43 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2012/01/16 12:01:52 | 000,000,698 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2012/01/16 11:54:40 | 000,009,349 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\f86fb96e
[2012/01/12 03:10:13 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/12 03:03:39 | 000,445,836 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/12 03:03:39 | 000,073,042 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/02/05 17:49:19 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/04 14:08:41 | 000,001,904 | ---- | C] () -- C:\WINDOWS\System32\SetupBD.din
[2012/01/29 20:19:46 | 000,022,729 | ---- | C] () -- C:\newkey
[2012/01/29 20:19:46 | 000,022,729 | ---- | C] () -- C:\newfile.enc
[2012/01/16 14:22:05 | 1071,562,752 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/16 12:02:43 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/01/16 11:08:20 | 000,009,349 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\f86fb96e
[2011/07/10 19:57:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Captive.INI
[2011/05/21 08:44:13 | 000,014,600 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\e4p658450oy660al14dx
[2011/04/14 15:46:33 | 000,723,294 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2011/04/14 15:46:33 | 000,134,742 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2011/01/01 22:34:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Twister.INI
[2010/12/25 23:53:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Secrets.INI
[2010/11/04 18:57:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Shadow.INI
[2010/02/21 09:22:50 | 000,056,052 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/12/25 21:45:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Waverly.INI
[2009/08/08 16:01:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Ransom.INI
[2009/07/28 18:57:08 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/11/03 18:18:32 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\brian adrian\Application Data\dvd.bmk
[2008/10/30 14:57:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CastleMalloy.INI
[2008/07/09 22:31:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhantomOfVenice.INI
[2008/04/03 19:16:01 | 000,001,004 | ---- | C] () -- C:\Documents and Settings\brian adrian\Application Data\wklnhst.dat
[2008/03/04 10:31:01 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/03/04 10:31:01 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/02/21 17:30:52 | 000,000,190 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2007/12/24 11:04:09 | 000,000,054 | ---- | C] () -- C:\WINDOWS\RCAMPEG4VC.ini
[2007/12/24 10:53:58 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/12/24 10:53:58 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/11/15 21:24:10 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2007/10/06 14:56:39 | 000,001,421 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/09/20 07:40:13 | 000,000,184 | ---- | C] () -- C:\WINDOWS\IKON Payroll Detail.ini
[2007/09/17 06:37:31 | 000,009,216 | ---- | C] () -- C:\Documents and Settings\brian adrian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/19 15:17:08 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\brian adrian\Local Settings\Application Data\fusioncache.dat
[2007/07/01 18:45:55 | 000,104,193 | ---- | C] () -- C:\WINDOWS\hpoins04.dat.temp
[2007/07/01 18:45:55 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat.temp
[2007/07/01 06:06:25 | 000,104,279 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2007/07/01 06:06:25 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2007/06/29 17:24:17 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/06/22 14:00:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\game.INI
[2007/06/20 17:32:21 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/06/20 17:26:47 | 000,000,126 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/06/20 17:05:21 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2007/06/20 17:05:15 | 000,129,112 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2007/06/20 17:03:56 | 000,001,123 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/09/28 14:55:34 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\PhysXLoader.dll
[2006/09/26 14:01:40 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2006/09/08 09:01:50 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2005/11/10 00:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 12:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:57:15 | 000,269,392 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:51:20 | 000,445,836 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:51:20 | 000,073,042 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 11:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 11:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 11:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 11:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:50:56 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[color=#E56717]========== LOP Check ==========[/color]
[2011/02/08 17:33:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1F3A8
[2011/03/04 17:53:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\792
[2011/07/17 15:50:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\America Online
[2011/10/02 11:25:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BSD
[2011/02/08 17:32:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iMesh
[2009/03/05 19:57:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2009/12/22 21:45:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Leapfrog
[2010/12/12 21:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/21 03:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/02/08 17:33:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{DE0AF019-D61B-423F-9C3B-D49ECD51D8A1}
[2011/03/04 18:48:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\bsbandmltbpi
[2011/10/28 15:37:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\BSD
[2011/04/14 15:49:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\Easy MP3 Recorder
[2011/04/14 15:47:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\FCSB000063127
[2011/03/01 19:36:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\imeshbandmltbpi
[2009/03/12 20:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\iWinArcade
[2009/11/26 20:32:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\Leadertech
[2011/04/13 15:32:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\mediabarbs
[2011/03/02 14:32:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\mediabarim
[2008/04/03 19:16:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\Template
[2010/11/10 17:43:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\Wal-Mart Digital Photo Manager
[2011/04/14 15:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\brian adrian\Application Data\WeatherBug
[2012/02/05 16:26:55 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[color=#E56717]========== Purity Check ==========[/color]
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~