They did not succeed.
I removed uTorrent.
I tried running GMER, both in safe mode and in normal mode. When the scan would not freeze, it would briefly blue screen my computer and cause it to restart.
Here is Extras.txt
OTL Extras logfile created on: 7/19/2010 1:01:13 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 81.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 374.81 Gb Free Space | 80.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HONESTLY
Current User Name: Kevin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_USERS\S-1-5-21-220523388-842925246-839522115-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Kevin\Local Settings\Temp\Blizzard Installer Bootstrap - 00c6eee1\Installer.exe" = C:\Documents and Settings\Kevin\Local Settings\Temp\Blizzard Installer Bootstrap - 00c6eee1\Installer.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Documents and Settings\Kevin\Local Settings\Temp\Blizzard Installer Bootstrap - 00eb1361\Installer.exe" = C:\Documents and Settings\Kevin\Local Settings\Temp\Blizzard Installer Bootstrap - 00eb1361\Installer.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Documents and Settings\Kevin\Local Settings\Temp\Blizzard Installer Bootstrap - 01028798\Installer.exe" = C:\Documents and Settings\Kevin\Local Settings\Temp\Blizzard Installer Bootstrap - 01028798\Installer.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Launcher -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe" = C:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer -- (Activision Inc)
"C:\Program Files\World of Warcraft Public Test\WoW-0.3.0.10522-enUS-ptr-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.3.0.10522-enUS-ptr-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft Public Test\Launcher.exe" = C:\Program Files\World of Warcraft Public Test\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\DU Super Controler\DUSuperControler.exe" = C:\Program Files\DU Super Controler\DUSuperControler.exe:*:Enabled:DU Super Controler -- File not found
"C:\Program Files\Heroes of Newerth\hon.exe" = C:\Program Files\Heroes of Newerth\hon.exe:*:Enabled:Heroes of Newerth -- (S2 Games)
"C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe" = C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2 -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{1C63AA59-66B2-418C-BDF5-53A534DA5690}_is1" = Sothink SWF to Video Converter
"{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}" = Star Wars Jedi Knight Jedi Academy
"{23D683DD-93C6-48E6-B84E-78B57778F126}" = Oblivion - Construction Set
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{3AA75ADB-113C-4FA1-954E-DD3E76BC1524}" = D-Link Wireless 150 USB Adapter DWA-125
"{458207CA-1B0C-4A35-AEDF-9C9D5B0579C5}" = Livestream Procaster
"{48FE73F3-4C3A-4871-BCD0-A7726A08BD64}" = Hex Workshop v6
"{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008
"{5EE83279-5FEA-4885-823A-B90C23A72DF0}" = D-Link Wireless 150 USB Adapter DWA-125
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{793A260C-CDBF-499C-ABBA-B51E8E076867}_is1" = Uniblue PowerSuite
"{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B8.1015.1
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"{A062A15F-9CAC-4B88-98DF-87628A0BD721}" = Corel MediaOne
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7E07C2B-2220-4415-87E3-784D5814BC93}" = NVIDIA PhysX v8.09.04
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"ACDSee" = ACDSee
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity_is1" = Audacity 1.2.6
"BeyondCompare3_is1" = Beyond Compare version 3.0.7
"CCleaner" = CCleaner (remove only)
"Diablo II" = Diablo II
"HijackThis" = HijackThis 1.99.1
"hon" = Heroes of Newerth
"InstallWIX_{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.8.3 (Basic)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NVIDIA Drivers" = NVIDIA Drivers
"Oblivion mod manager_is1" = Oblivion mod manager 1.1.12
"PowerISO" = PowerISO
"Steam App 10180" = Call of Duty: Modern Warfare 2
"Steam App 550" = Left 4 Dead 2
"Unofficial Oblivion Patch_is1" = Unofficial Oblivion Patch v3.2.0
"Unofficial Shivering Isles Patch_is1" = Unofficial Shivering Isles Patch v1.4.0
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-220523388-842925246-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"15fe0b4b2de5f74f" = WoW Table Viewer
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 4/8/2010 2:21:23 AM | Computer Name = HONESTLY | Source = Application Error | ID = 1000
Description = Faulting application oblivion.exe, version 1.2.0.416, faulting module
oblivion.exe, version 1.2.0.416, fault address 0x00152a34.
Error - 4/8/2010 2:32:43 AM | Computer Name = HONESTLY | Source = Application Error | ID = 1000
Description = Faulting application oblivion.exe, version 1.2.0.416, faulting module
weocps.dll, version 0.0.0.0, fault address 0x00002df9.
Error - 4/12/2010 6:18:43 PM | Computer Name = HONESTLY | Source = Application Error | ID = 1000
Description = Faulting application wzcsldr2.exe, version 1.0.10.7034, faulting module
anioapi.dll, version 2.0.6.209, fault address 0x00004531.
Error - 5/24/2010 9:23:23 PM | Computer Name = HONESTLY | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 dbc editor.exe, P2 0.1.0.0, P3 44408737, P4
system.windows.forms, P5 2.0.0.0, P6 4333aefa, P7 130d, P8 39, P9 system.outofmemoryexception,
P10 NIL.
Error - 5/24/2010 9:32:57 PM | Computer Name = HONESTLY | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 dbceditor.exe, P2 1.0.0.0, P3 4bf9a855, P4 dbceditor,
P5 1.0.0.0, P6 4bf9a855, P7 c2, P8 b, P9 system.typeinitialization, P10 NIL.
Error - 5/24/2010 9:33:09 PM | Computer Name = HONESTLY | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 dbceditor.exe, P2 1.0.0.0, P3 4bf9a855, P4 dbceditor,
P5 1.0.0.0, P6 4bf9a855, P7 c2, P8 b, P9 system.typeinitialization, P10 NIL.
Error - 5/24/2010 9:34:21 PM | Computer Name = HONESTLY | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 dbceditor.exe, P2 1.0.0.0, P3 4bf9a855, P4 dbceditor,
P5 1.0.0.0, P6 4bf9a855, P7 c2, P8 b, P9 system.typeinitialization, P10 NIL.
Error - 5/24/2010 9:46:58 PM | Computer Name = HONESTLY | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 dbc editor.exe, P2 0.1.0.0, P3 44408737, P4
mscorlib, P5 2.0.0.0, P6 4333ab80, P7 32f8, P8 21c, P9 system.io.ioexception, P10
NIL.
Error - 5/24/2010 10:12:14 PM | Computer Name = HONESTLY | Source = Application Error | ID = 1000
Description = Faulting application mywarcraftstudio.exe, version 1.0.0.2719, faulting
module msvcr71.dll, version 7.10.3052.4, fault address 0x000017fb.
Error - 5/24/2010 10:12:23 PM | Computer Name = HONESTLY | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
[ System Events ]
Error - 7/18/2010 12:14:28 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/18/2010 12:14:28 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/18/2010 12:14:28 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/18/2010 12:14:28 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/18/2010 12:14:28 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/19/2010 1:51:04 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/19/2010 1:51:04 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/19/2010 1:51:04 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/19/2010 1:51:04 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
Error - 7/19/2010 1:51:04 PM | Computer Name = HONESTLY | Source = JRAID | ID = 262153
Description = The device, \Device\Scsi\JRAID1, did not respond within the timeout
period.
< End of report >
Here is OTL.Txt
OTL logfile created on: 7/19/2010 1:01:05 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 81.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 374.81 Gb Free Space | 80.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HONESTLY
Current User Name: Kevin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe (Kaspersky Lab)
PRC - C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe (D-Link Corp.)
PRC - C:\WINDOWS\system32\ANIWConnService.exe ()
PRC - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Kevin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software GmbH)
SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
SRV - (ANIWConnService) -- C:\WINDOWS\system32\ANIWConnService.exe ()
SRV - (GEST Service) -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (ProtexisLicensing) -- C:\WINDOWS\system32\PSIService.exe ()
SRV - (ANIWZCSdService) -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (Wireless Service)
========== Driver Services (SafeList) ========== DRV - (klbg) -- C:\WINDOWS\System32\drivers\klbg.sys File not found
DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows (R) 2000 DDK provider)
DRV - (rt2870) -- C:\WINDOWS\system32\drivers\Drt2870.sys (Ralink Technology, Corp.)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (KLIF) -- C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (klim5) -- C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab)
DRV - (kl1) -- C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab)
DRV - (ANIO) -- C:\WINDOWS\system32\ANIO.sys ()
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (JRAID) -- C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (SCDEmu) -- C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-220523388-842925246-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems:
linkfilter@kaspersky.ru:9.0.0.736
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/04 21:02:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/29 13:10:03 | 000,000,000 | ---D | M]
[2010/03/07 13:25:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2010/03/07 13:25:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\wm130o2g.default\extensions
[2010/07/17 22:36:19 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/03/07 14:00:13 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
O1 HOSTS File: ([2001/08/23 16:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [D-Link D-Link Wireless 150 USB Adapter DWA-125] C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe (D-Link Corp.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-220523388-842925246-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/06 17:24:34 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/07/19 12:55:38 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2010/07/19 11:56:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/07/04 22:46:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\My Documents\blegh2
[2010/06/24 19:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\Desktop\wowmodelview-v0.5.08-alfred-r536
[2010/06/24 04:16:16 | 000,413,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MPG4c32.dll
[2010/06/24 04:16:15 | 000,000,000 | ---D | C] -- C:\Program Files\SourceTec
[2010/06/24 04:15:53 | 006,335,573 | ---- | C] (SourceTec Software Co., LTD ) -- C:\Documents and Settings\Kevin\Desktop\Setup.exe
[2010/06/21 17:36:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/07/19 12:55:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2010/07/19 10:52:25 | 000,003,284 | ---- | M] () -- C:\WINDOWS\System32\ANIWZCS{C2013B00-6A3E-4C37-8467-6EA423FC80D8}
[2010/07/19 10:52:17 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2010/07/19 10:52:16 | 000,000,006 | ---- | M] () -- C:\WINDOWS\System32\ANIWZCSUSERNAME{C2013B00-6A3E-4C37-8467-6EA423FC80D8}
[2010/07/19 10:51:24 | 000,000,007 | ---- | M] () -- C:\WINDOWS\System32\ANIWZCSUSERNAME
[2010/07/19 10:51:22 | 000,200,712 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/07/19 10:51:06 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys
[2010/07/19 10:51:02 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/19 10:51:02 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/19 10:50:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/19 01:43:57 | 003,932,160 | ---- | M] () -- C:\Documents and Settings\Kevin\NTUSER.DAT
[2010/07/19 01:43:35 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Kevin\ntuser.ini
[2010/07/13 11:19:32 | 000,129,178 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\1279043139951.jpg
[2010/07/13 11:17:48 | 000,053,095 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\54467286.jpg
[2010/07/13 01:05:01 | 000,039,936 | ---- | M] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/10 18:38:33 | 002,453,101 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\IMG_1271.jpg
[2010/07/10 18:27:24 | 002,465,372 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\IMG_1250.jpg
[2010/07/10 16:53:40 | 000,254,292 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\fuzzyphoto.JPG
[2010/07/01 19:55:48 | 000,075,402 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\ec2.JPG
[2010/07/01 19:53:45 | 000,045,261 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\ec1.JPG
[2010/06/30 19:53:59 | 002,390,220 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\IMG_1230.jpg
[2010/06/30 18:05:35 | 000,135,926 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\eye.JPG
[2010/06/30 04:51:23 | 001,577,428 | -H-- | M] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\IconCache.db
[2010/06/29 17:52:34 | 000,063,506 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\nope.jpg
[2010/06/24 04:23:53 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/06/24 04:16:24 | 000,000,037 | ---- | M] () -- C:\WINDOWS\SWFConverter.INI
[2010/06/23 11:20:45 | 000,089,610 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\spree-1.jpg
[2010/06/23 01:03:01 | 000,214,808 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\edp.jpg
[2010/06/22 16:19:47 | 000,194,567 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\wtf.JPG
[2010/06/21 16:30:22 | 000,050,776 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf8.jpg
[2010/06/21 16:28:57 | 000,068,553 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf7.jpg
[2010/06/21 16:25:40 | 000,081,521 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf6.jpg
[2010/06/21 16:23:13 | 000,064,906 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf5.jpg
[2010/06/21 16:20:07 | 000,008,732 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf4.jpg
[2010/06/21 16:19:56 | 000,043,384 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf3.jpg
[2010/06/21 16:19:37 | 000,061,730 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\trf2.jpg
[2010/06/19 18:04:21 | 000,015,900 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\td.jpg
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/07/14 20:42:10 | 000,002,335 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2010/07/14 15:19:13 | 002,589,618 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\WoW 2008-07-31 23-15-09-81.bmp
[2010/07/13 11:19:31 | 000,129,178 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\1279043139951.jpg
[2010/07/13 11:17:48 | 000,053,095 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\54467286.jpg
[2010/07/10 18:38:33 | 002,453,101 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\IMG_1271.jpg
[2010/07/10 18:27:24 | 002,465,372 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\IMG_1250.jpg
[2010/07/10 16:53:40 | 000,254,292 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\fuzzyphoto.JPG
[2010/07/01 19:55:48 | 000,075,402 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\ec2.JPG
[2010/07/01 19:53:45 | 000,045,261 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\ec1.JPG
[2010/06/30 19:53:59 | 002,390,220 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\IMG_1230.jpg
[2010/06/30 18:05:35 | 000,135,926 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\eye.JPG
[2010/06/29 17:52:33 | 000,063,506 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\nope.jpg
[2010/06/24 04:16:24 | 000,000,037 | ---- | C] () -- C:\WINDOWS\SWFConverter.INI
[2010/06/23 11:20:44 | 000,089,610 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\spree-1.jpg
[2010/06/23 01:07:17 | 000,214,808 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\edp.jpg
[2010/06/22 16:19:47 | 000,194,567 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\wtf.JPG
[2010/06/21 16:30:21 | 000,050,776 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf8.jpg
[2010/06/21 16:28:57 | 000,068,553 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf7.jpg
[2010/06/21 16:25:39 | 000,081,521 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf6.jpg
[2010/06/21 16:23:13 | 000,064,906 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf5.jpg
[2010/06/21 16:20:06 | 000,008,732 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf4.jpg
[2010/06/21 16:19:56 | 000,043,384 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf3.jpg
[2010/06/21 16:19:36 | 000,061,730 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\trf2.jpg
[2010/06/19 18:04:20 | 000,015,900 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\td.jpg
[2010/05/12 21:35:52 | 000,000,074 | ---- | C] () -- C:\WINDOWS\sstools.ini
[2010/03/16 19:38:42 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/03/14 19:42:23 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2010/03/09 23:39:29 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/03/07 21:55:17 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2010/03/07 16:46:57 | 000,335,872 | ---- | C] () -- C:\WINDOWS\System32\ldf252.dll
[2010/03/07 16:45:37 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/03/07 16:45:37 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/03/07 16:42:10 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/03/07 11:05:46 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\wlanapp.dll
[2010/03/07 11:05:46 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\aIPH.dll
[2010/03/07 11:05:46 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\JJAKEn.dll
[2010/03/07 11:05:46 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\AQCKGen.dll
[2010/03/07 11:05:46 | 000,045,115 | ---- | C] () -- C:\WINDOWS\System32\ANICtl.dll
[2010/03/07 11:05:32 | 000,315,392 | ---- | C] () -- C:\WINDOWS\System32\ANIOApi.dll
[2010/03/07 11:05:32 | 000,048,640 | ---- | C] () -- C:\WINDOWS\System32\ANIO64.sys
[2010/03/07 11:05:32 | 000,029,411 | ---- | C] () -- C:\WINDOWS\System32\ANIO.sys
[2010/03/07 11:05:26 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\ANIOWPS.dll
[2008/09/16 18:55:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/09/16 18:55:00 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/09/16 18:55:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/09/16 18:55:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/09/16 18:55:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/06/11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/06/11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/06/11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/06/11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/06/11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/06/11 10:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/06/11 10:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/06/11 10:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/06/05 09:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
========== Files - Unicode (All) ==========[2010/03/07 20:33:55 | 000,000,000 | ---D | M](C:\Documents and Settings\Kevin\My Documents\F?nts) -- C:\Documents and Settings\Kevin\My Documents\F?nts
[2010/03/07 20:33:55 | 000,000,000 | ---D | C](C:\Documents and Settings\Kevin\My Documents\F?nts) -- C:\Documents and Settings\Kevin\My Documents\F?nts
========== Alternate Data Streams ========== @Alternate Data Stream - 478 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
< End of report >