OTLISTIT
OTListIt logfile created on: 2/23/2009 6:27:01 PM - Run
OTListIt2 by OldTimer - Version 2.0.1.1 Folder = C:\Documents and Settings\Queenie Leung\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.42 Mb Total Physical Memory | 87.66 Mb Available Physical Memory | 17.45% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 10240;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.68 Gb Total Space | 15.17 Gb Free Space | 27.24% Space Free | Partition Type: NTFS
Drive D: | 58.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: QUEENIE
Current User Name: Queenie Leung
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (CVPND [Auto | Running]) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmi [On_Demand | Stopped]) – C:\Program Files\HPQ\SHARED\HPQWMI.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe ()
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CAMCAUD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (CAMCHALA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CamDrL [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINDOWS\system32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (eabfiltr [System | Running]) – C:\WINDOWS\system32\drivers\EABFiltr.sys (Hewlett-Packard Company)
DRV - (eabusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\eabusb.sys (Hewlett-Packard Company)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilDrvI7 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI7.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mchInjDrv [System | Running]) – C:\WINDOWS\system32\Drivers\mchInjDrv.sys ()
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090223.002\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090223.002\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RTL8023xp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (SAVRT [On_Demand | Running]) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (sea1bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1bus.sys (MCCI)
DRV - (sea1mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys (MCCI)
DRV - (sea1mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdm.sys (MCCI)
DRV - (sea1mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys (MCCI)
DRV - (sea1nd5 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1nd5.sys (MCCI)
DRV - (sea1obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1obex.sys (MCCI)
DRV - (sea1unic [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1unic.sys (MCCI)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMCIRDA [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\smcirda.sys (SMC)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vcddev [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vcdvnic.sys (VNN B.J.)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs Inc.)
DRV - (w29n51 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\w29n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/puccini/start
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {534C9916-EC47-46DE-B7F6-10F06C309F04} - C:\WINDOWS\system32\khfCstrQ.dll File not found
O2 - BHO: (no name) - {57F7EDCC-EB32-4082-A098-318E931773D1} - C:\WINDOWS\system32\ljJDUNHx.dll File not found
O2 - BHO: (no name) - {5BA73F0D-7B52-4E5A-9763-DDAD6268CD02} - C:\WINDOWS\system32\urqOGWMd.dll File not found
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {88a796be-b4ec-4cfe-9074-198b28ab0973} - C:\WINDOWS\system32\gitdlk.dll ()
O2 - BHO: (no name) - {96D496B3-D54E-42D9-86E5-5456E9F2D262} - C:\WINDOWS\system32\pmnljKbX.dll ()
O2 - BHO: (no name) - {E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024} - C:\WINDOWS\system32\byXQKDUO.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [314c2356] rundll32.exe "C:\WINDOWS\system32\lnebwupq.dll",b ()
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3}
http://www.uproar.com/applets/activex/shiz…pside_web18.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1160454364500 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: RaptisoftGameLoader
http://www.raptisoft.com/webgames/raptisoftgameloader.cab (Reg Error: Key error.)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (gitdlk.dll) - C:\WINDOWS\system32\gitdlk.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\cbXNDWnO: DllName - cbXNDWnO.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\ssqQhfde: DllName - ssqQhfde.dll - C:\WINDOWS\system32\ssqQhfde.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\pmnljKbX) - C:\WINDOWS\system32\pmnljKbX.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{17f9b040-328d-11dd-b9f7-0015000583e0}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\Shell\Auto\command - "" = G:\Ghost.pif – File not found
O33 - MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\1\Command - "" = .\RECYCLER\Lcass.exe
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\2\Command - "" = .\RECYCLER\Lcass.exe
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell - "" = AutoRun
O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell\AutoRun\command - "" = E:\Launcher.exe – File not found
O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell - "" = AutoRun
O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell - "" = AutoRun
O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
File not found – C:\WINDOWS\System32\wgsjsume.dll
File not found – C:\WINDOWS\System32\unedukru.dll
File not found – C:\WINDOWS\System32\tnakrraf.dll
File not found – C:\WINDOWS\System32\nxoxwvsj.dll
File not found – C:\WINDOWS\System32\nnpkyh.dll
File not found – C:\WINDOWS\System32\nfjmuvpe.dll
File not found – C:\WINDOWS\System32\maxaolvg.dll
File not found – C:\WINDOWS\System32\kslddono.dll
File not found – C:\WINDOWS\System32\kppkvlgu.dll
File not found – C:\WINDOWS\System32\kgfktdjh.dll
File not found – C:\WINDOWS\System32\gxkggp.dll
File not found – C:\WINDOWS\System32\espjawnf.dll
File not found – C:\WINDOWS\System32\cbsnpz.dll
[2009/02/23 18:30:04 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\ofivoilk.dll
[2009/02/23 18:27:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gitdlk.dll
[2009/02/23 18:27:31 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\bhgvdkdv.dll
[2009/02/23 18:27:02 | 00,002,409 | -HS- | C] () – C:\WINDOWS\System32\XbKjlnmp.ini2
[2009/02/23 18:27:01 | 00,002,409 | -HS- | C] () – C:\WINDOWS\System32\XbKjlnmp.ini
[2009/02/23 18:26:57 | 00,302,592 | —- | C] () – C:\WINDOWS\System32\pmnljKbX.dll
[2009/02/23 18:26:03 | 00,494,080 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe
[2009/02/23 18:12:26 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/23 18:10:57 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTMoveIt3.exe
[2009/02/23 17:50:23 | 00,038,447 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\n1331910049_30524037_6342.jpg
[2009/02/23 17:46:46 | 33,911,485 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\CIMG1040.zip
[2009/02/23 17:34:24 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/23 17:33:36 | 00,268,052 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\Rooter.exe
[2009/02/23 12:37:55 | 01,587,449 | -HS- | C] () – C:\WINDOWS\System32\qpuwbenl.ini
[2009/02/23 12:37:49 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\lnebwupq.dll
[2009/02/23 12:36:14 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\vaajnx.dll
[2009/02/23 12:34:58 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\mjnrhbkw.dll
[2009/02/23 00:50:20 | 00,001,734 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\HijackThis.lnk
[2009/02/23 00:50:19 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/22 23:17:33 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\nvnhqo.dll
[2009/02/22 23:17:29 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\jumdlpmd.dll
[2009/02/22 23:14:50 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\onrjonwo.ini
[2009/02/22 23:14:48 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\ownojrno.dll
[2009/02/22 20:25:01 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\vafgovpp.ini
[2009/02/22 19:35:41 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\rqvfuvma.ini
[2009/02/22 19:33:27 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\dhyuej.dll
[2009/02/22 19:33:25 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\klcmlevu.dll
[2009/02/19 23:29:22 | 04,045,312 | —- | C] () – C:\Documents and Settings\Queenie Leung\My Documents\hsmai.ppt
[2009/02/10 13:22:59 | 52,689,7152 | -HS- | C] () – C:\hiberfil.sys
[2009/02/02 23:40:06 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/02/02 23:28:17 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\fccaAsRH.dll
[2009/02/02 23:26:54 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\ssqQhfde.dll
[2009/02/02 22:53:57 | 01,508,191 | -HS- | C] () – C:\WINDOWS\System32\xwteoaey.ini
[2009/02/02 22:47:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/02/02 22:47:16 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\STKIT432.DLL
[2009/02/02 22:47:12 | 00,000,000 | —D | C] – C:\Program Files\Registry Mechanic
[2009/02/02 21:34:39 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/02 21:34:39 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/29 00:13:12 | 01,515,358 | -HS- | C] () – C:\WINDOWS\System32\smmcfbpc.ini
[2009/01/28 00:10:33 | 01,516,535 | -HS- | C] () – C:\WINDOWS\System32\farrkant.ini
[2009/01/26 21:19:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Queenie Leung\My Documents\Spring 09
[2009/01/26 17:14:40 | 01,525,122 | -HS- | C] () – C:\WINDOWS\System32\wsftufxc.ini
[2009/01/25 21:05:33 | 01,434,061 | -HS- | C] () – C:\WINDOWS\System32\tacithut.ini
========== Files - Modified Within 30 Days ==========
[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
[2009/02/23 18:33:42 | 00,002,409 | -HS- | M] () – C:\WINDOWS\System32\XbKjlnmp.ini
[2009/02/23 18:33:12 | 00,002,409 | -HS- | M] () – C:\WINDOWS\System32\XbKjlnmp.ini2
[2009/02/23 18:30:21 | 01,587,501 | -HS- | M] () – C:\WINDOWS\System32\kliovifo.ini
[2009/02/23 18:30:06 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\ofivoilk.dll
[2009/02/23 18:27:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\gitdlk.dll
[2009/02/23 18:27:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\bhgvdkdv.dll
[2009/02/23 18:26:59 | 00,302,592 | —- | M] () – C:\WINDOWS\System32\pmnljKbX.dll
[2009/02/23 18:26:15 | 00,494,080 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe
[2009/02/23 18:21:17 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/23 18:20:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/23 18:20:08 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/23 18:19:58 | 00,364,120 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/23 18:19:54 | 52,689,7152 | -HS- | M] () – C:\hiberfil.sys
[2009/02/23 18:10:58 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTMoveIt3.exe
[2009/02/23 17:50:23 | 00,038,447 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\n1331910049_30524037_6342.jpg
[2009/02/23 17:49:23 | 33,911,485 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\CIMG1040.zip
[2009/02/23 17:33:37 | 00,268,052 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\Rooter.exe
[2009/02/23 12:38:10 | 01,587,449 | -HS- | M] () – C:\WINDOWS\System32\qpuwbenl.ini
[2009/02/23 12:37:49 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\lnebwupq.dll
[2009/02/23 12:36:12 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\vaajnx.dll
[2009/02/23 12:36:12 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\mjnrhbkw.dll
[2009/02/23 00:50:20 | 00,001,734 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\HijackThis.lnk
[2009/02/22 23:17:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\nvnhqo.dll
[2009/02/22 23:17:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\jumdlpmd.dll
[2009/02/22 23:15:03 | 01,607,788 | -HS- | M] () – C:\WINDOWS\System32\onrjonwo.ini
[2009/02/22 23:14:49 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\ownojrno.dll
[2009/02/22 20:25:12 | 01,607,788 | -HS- | M] () – C:\WINDOWS\System32\vafgovpp.ini
[2009/02/22 19:35:45 | 01,607,788 | -HS- | M] () – C:\WINDOWS\System32\rqvfuvma.ini
[2009/02/22 19:33:26 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\klcmlevu.dll
[2009/02/22 19:33:26 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\dhyuej.dll
[2009/02/20 01:52:15 | 04,045,312 | —- | M] () – C:\Documents and Settings\Queenie Leung\My Documents\hsmai.ppt
[2009/02/20 00:26:22 | 00,102,392 | —- | M] () – C:\Documents and Settings\Queenie Leung\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/19 19:00:54 | 00,002,560 | —- | M] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/02/10 13:32:21 | 00,000,624 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/10 13:32:21 | 00,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/10 13:32:21 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/02/02 23:35:25 | 00,380,918 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/02 23:35:25 | 00,053,166 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/02 23:35:23 | 00,439,376 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/02 23:28:18 | 00,036,352 | —- | M] () – C:\WINDOWS\System32\fccaAsRH.dll
[2009/02/02 23:26:57 | 00,036,352 | —- | M] () – C:\WINDOWS\System32\ssqQhfde.dll
[2009/02/02 22:54:13 | 01,508,191 | -HS- | M] () – C:\WINDOWS\System32\xwteoaey.ini
[2009/01/29 00:13:17 | 01,515,358 | -HS- | M] () – C:\WINDOWS\System32\smmcfbpc.ini
[2009/01/28 00:10:38 | 01,516,535 | -HS- | M] () – C:\WINDOWS\System32\farrkant.ini
[2009/01/26 17:15:04 | 01,525,122 | -HS- | M] () – C:\WINDOWS\System32\wsftufxc.ini
[2009/01/25 21:05:36 | 01,434,061 | -HS- | M] () – C:\WINDOWS\System32\tacithut.ini
========== LOP Check ==========
[2009/02/19 19:14:52 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/12 21:16:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/11/30 13:01:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/05/08 10:00:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2005/12/07 23:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2007/12/24 14:05:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/11/30 12:51:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/14 02:39:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/08/13 21:01:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/10/04 02:36:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2005/12/26 02:55:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2007/07/03 23:19:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2005/09/05 13:47:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2005/09/03 05:44:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hpqwmi
[2005/04/10 07:51:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/12/24 13:25:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2007/08/04 09:08:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/08/19 13:02:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2005/12/26 07:13:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/04/10 08:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2007/08/08 18:36:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2006/06/29 02:56:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/09/05 10:06:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2005/04/10 05:56:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/08/30 12:37:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2006/01/17 13:23:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/19 19:13:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/30 13:02:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/07/19 22:37:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/22 20:11:27 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Queenie Leung\Application Data
[2005/10/11 21:19:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\.bittorrent
[2007/10/28 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\.purple
[2007/12/24 14:14:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\acccore
[2008/02/04 17:30:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Adobe
[2008/05/08 09:50:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\AdobeUM
[2007/12/13 19:04:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Aim
[2008/11/12 21:36:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Apple Computer
[2005/10/13 04:04:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Azureus
[2008/06/30 22:21:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\com.zipeg
[2005/12/27 01:41:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Google
[2005/09/07 22:11:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Help
[2005/09/05 13:40:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\HP
[2005/04/10 05:56:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Identities
[2005/12/07 22:51:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Image Zone Express
[2005/10/11 23:22:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\iMesh
[2006/01/30 01:45:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\InterVideo
[2006/09/28 21:20:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\JAMS
[2006/01/17 13:27:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Lavasoft
[2005/11/09 22:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Leadertech
[2007/08/13 21:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\LimeWire
[2005/09/05 15:46:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Macromedia
[2007/11/08 22:28:47 | 00,000,000 | –SD | M] – C:\Documents and Settings\Queenie Leung\Application Data\Microsoft
[2009/01/17 17:51:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Move Networks
[2008/08/28 22:26:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Mozilla
[2007/07/28 22:56:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\MP3Downloads
[2007/07/09 10:45:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\MSNInstaller
[2005/11/09 22:03:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\muvee Technologies
[2005/12/09 03:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Opera
[2006/06/29 02:56:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\PlayFirst
[2006/04/21 23:02:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Raptisoft
[2008/03/28 08:29:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Real
[2007/04/15 12:59:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Ringjacker
[2005/12/18 01:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Shareaza
[2008/04/13 15:57:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Skype
[2005/11/09 22:03:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Sonic
[2007/07/06 12:20:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Sony Ericsson
[2005/09/04 02:48:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Sun
[2006/01/17 13:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Symantec
[2008/05/11 17:29:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Talkback
[2007/07/06 12:21:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Teleca
[2009/02/23 09:18:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\U3
[2007/09/05 17:45:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Viewpoint
[2005/11/23 04:27:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Wildfire
[2007/09/07 00:16:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\WinRAR
[2005/10/17 19:55:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Zen Puzzle Garden
[2008/11/21 20:34:05 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 03:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/23 18:20:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
========== Net Services ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\NetSvcs
6to4 - -
AppMgmt - C:\WINDOWS\System32\appmgmts.dll - (Microsoft Corporation)
AudioSrv - C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation)
Browser - -
CryptSvc - C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation)
DMServer - C:\WINDOWS\System32\dmserver.dll - (Microsoft Corp.)
DHCP - C:\WINDOWS\System32\dhcpcsvc.dll - (Microsoft Corporation)
ERSvc - C:\WINDOWS\System32\ersvc.dll - (Microsoft Corporation)
EventSystem - C:\WINDOWS\system32\es.dll - (Microsoft Corporation)
FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
HidServ - C:\WINDOWS\System32\hidserv.dll - (Microsoft Corporation)
Ias - -
Iprip - -
Irmon - -
LanmanServer - C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - -
Messenger - -
Netman - C:\WINDOWS\System32\netman.dll - (Microsoft Corporation)
Nla - C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation)
Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation)
NWCWorkstation - -
Nwsapagent - -
Rasauto - C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation)
Rasman - C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation)
Remoteaccess - C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation)
Schedule - C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation)
Seclogon - C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation)
SENS - C:\WINDOWS\system32\sens.dll - (Microsoft Corporation)
Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll - (Microsoft Corporation)
SRService - C:\WINDOWS\system32\srsvc.dll - (Microsoft Corporation)
Tapisrv - C:\WINDOWS\System32\tapisrv.dll - (Microsoft Corporation)
Themes - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
TrkWks - C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation)
W32Time - C:\WINDOWS\system32\w32time.dll - (Microsoft Corporation)
WZCSVC - C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation)
Wmi - C:\WINDOWS\System32\advapi32.dll - (Microsoft Corporation)
WmdmPmSp - -
winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
wscsvc - C:\WINDOWS\system32\wscsvc.dll - (Microsoft Corporation)
xmlprov - C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation)
BITS - C:\WINDOWS\system32\qmgr.dll - (Microsoft Corporation)
wuauserv - C:\WINDOWS\system32\wuauserv.dll - (Microsoft Corporation)
ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll - (Microsoft Corporation)
napagent - C:\WINDOWS\System32\qagentrt.dll - (Microsoft Corporation)
hkmsvc - C:\WINDOWS\System32\kmsvc.dll - (Microsoft Corporation)
========== Disabled MS Config ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk - %ProgramFiles%\Microsoft Office\Office10\OSA.EXE - (Microsoft Corporation)
C:^Documents and Settings^Queenie Leung^Start Menu^Programs^Startup^Rainlendar.lnk - %SystemDrive%\PROGRA~1\RAINLE~1\RAINLE~1.EXE - File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
46052968763107085995260575741194 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Antivirus 2009\av2009.exe -> File not found
Aim6 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> File not found
ares hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Ares\Ares.exe -> File not found
BearShare hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\BearShare\BearShare.exe -> File not found
Cpqset hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HPQ\Default Settings\cpqset.exe -> ()
eabconfg.cpl hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HPQ\Quick Launch Buttons\EabServr.exe -> (Hewlett-Packard )
foxy hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Foxy\Foxy.exe -> File not found
Glass2k hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemDrive%\My Downloads\Glass2k.exe -> File not found
HP Software Update hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HP\HP Software Update\HPWuSchd2.exe -> (Hewlett-Packard Co.)
hpWirelessAssistant hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe -> (Hewlett-Packard Company)
iTunesHelper hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iTunes\iTunesHelper.exe -> (Apple Inc.)
LSBWatcher hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemDrive%\hp\drivers\hplsbwatcher\lsburnwatcher.exe -> (Hewlett-Packard Company)
QuickTime Task hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\QuickTime\QTTask.exe -> (Apple Inc.)
SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe -> (Sun Microsystems, Inc.)
SynTPEnh hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> (Synaptics, Inc.)
SynTPLpr hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> (Synaptics, Inc.)
TkBellExe hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> (RealNetworks, Inc.)
vptray hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> (Symantec Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
"system.ini" - 0
"win.ini" - 0
"bootini" - 0
"services" - 0
"startup" - 2
========== SafeBoot-Minimal Settings ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
Netlogon - Service
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
Primary disk - Driver Group
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
System Bus Extender - Driver Group
vds - Service
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
========== SafeBoot-Network Settings ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\
AFD - %SystemRoot%\System32\drivers\afd.sys - (Microsoft Corporation)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
Browser - Service
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
Dhcp - %SystemRoot%\System32\dhcpcsvc.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
DnsCache - %SystemRoot%\System32\dnsrslvr.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys - (Microsoft Corporation)
ipnat.sys - %SystemRoot%\system32\DRIVERS\ipnat.sys - (Microsoft Corporation)
LanmanServer - %SystemRoot%\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - Service
LmHosts - %SystemRoot%\System32\lmhsvc.dll - (Microsoft Corporation)
Messenger - - File not found
NDIS - %SystemRoot%\System32\drivers\ndis.sys - (Microsoft Corporation)
NDIS Wrapper - Driver Group
Ndisuio - %SystemRoot%\system32\DRIVERS\ndisuio.sys - (Microsoft Corporation)
NetBIOS - Service
NetBIOSGroup - Driver Group
NetBT - %SystemRoot%\system32\DRIVERS\netbt.sys - (Microsoft Corporation)
NetDDEGroup - Driver Group
Netlogon - Service
NetMan - %SystemRoot%\System32\netman.dll - (Microsoft Corporation)
Network - Driver Group
NetworkProvider - Driver Group
NtLmSsp - Service
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
PNP_TDI - Driver Group
Primary disk - Driver Group
rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys - (Microsoft Corporation)
rdpdd.sys - %SystemRoot%\System32\rdpdd.dll - (Microsoft Corporation)
rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys - (Microsoft Corporation)
rdsessmgr - %SystemRoot%\system32\sessmgr.exe - (Microsoft Corporation)
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
SharedAccess - %SystemRoot%\System32\ipnathlp.dll - (Microsoft Corporation)
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
Streams Drivers - Driver Group
System Bus Extender - Driver Group
Tcpip - %SystemRoot%\system32\DRIVERS\tcpip.sys - (Microsoft Corporation)
TDI - Driver Group
tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys - (Microsoft Corporation)
tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys - (Microsoft Corporation)
termservice - %SystemRoot%\System32\termsrv.dll - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
WZCSVC - %SystemRoot%\System32\wzcsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} - Net
{4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
< %systemroot%\System32\antiwpa.dll >
< %systemroot%\SYSTEM32\wpa.dll >
< %systemroot%\setup\scripts\biestart.exe >
< %systemroot%\system32\serauth1.dll >
< %systemroot%\system32\serauth2.dll >
< %systemroot%\system32\sysaudio.sys >
< %systemroot%\system32\wdmaud.sys >
< %systemroot%\system32\aeaudio.sys >
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Queenie Leung\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Queenie Leung\Desktop\Thumbs.db:encryptable
< End of report >