thankyou for helping me catbyte, i have done as you have said and here are the 2 logs as you asked
here is the Extras.Txt
OTListIt Extras logfile created on: 5/04/2009 6:13:53 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\Main\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.99 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 64.76% Memory free
3.84 Gb Paging File | 3.30 Gb Available in Paging File | 85.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 109.87 Gb Free Space | 47.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOLPHIN
Current User Name: Main
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1EB8D94B-4AC2-4483-9616-0FD7EDE14B18}" = 101 Kids Games Volume 1
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23970E31-948B-466E-8376-1224D32FDF0C}" = Convert
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{40C03514-89C3-41BA-0090-3B440256DB87}" = The Sims 2
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 4.1
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{611BD998-34B9-4DDA-00AE-0CB4632E86FA}" = SimCity 4
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD [removed]
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E72B982-D54F-486F-B35A-C24B6F171033}" = Nero 7 Essentials
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3 Platinum
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite
"{9FB2CE8C-E86C-4368-B3C9-F472898F926E}" = Desert Storm
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro Internet Security
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BEA2FF8E-50A3-4C6D-955E-5632C881753F}" = NetComm NB6 Series ADSL2+ Router USB Driver
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C3B58B0A-53CE-4A88-8C42-76E18341CA91}" = Eureka's 1000 Games
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"3DGroove" = 3D Groove Playback Engine
"ABC's & 123's" = ABC's & 123's
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Cars - Radiator Springs Adventures" = Cars - Radiator Springs Adventures
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.1.1.0
"FUN ON ALPHABET FARM" = FUN ON ALPHABET FARM
"FUN WITH NUMBERS & PUZZLES" = FUN WITH NUMBERS & PUZZLES
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"Hoyle Casino 2009" = Hoyle Casino 2009
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ImgBurn" = ImgBurn
"Kid's Paint & Puzzles" = Kid's Paint & Puzzles
"Lexmark 510 Series" = Lexmark 510 Series
"LimeWire" = LimeWire 4.18.5
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Monopoly by Parker Brothers" = Monopoly by Parker Brothers
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"Password Safe" = Password Safe
"Pregnancy Count_is1" = Pregnancy Count 4.0
"RollerCoaster Tycoon Setup" = Roll
"The Game Of Life" = The Game Of Life
"UltimateBet" = UltimateBet
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 25/02/2009 12:07:28 PM | Computer Name = DOLPHIN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 25/02/2009 7:24:01 PM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application Play&Learn.exe, version 5.0.1.26, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 25/02/2009 7:24:14 PM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application Play&Learn.exe, version 5.0.1.26, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 25/02/2009 7:24:14 PM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application Play&Learn.exe, version 5.0.1.26, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/03/2009 4:49:01 AM | Computer Name = DOLPHIN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x000ba952.
Error - 1/03/2009 4:49:07 AM | Computer Name = DOLPHIN | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Error - 1/03/2009 4:49:41 AM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/03/2009 5:47:03 PM | Computer Name = DOLPHIN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
[ System Events ]
Error - 3/04/2009 8:30:04 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 3/04/2009 8:30:04 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 3/04/2009 9:04:10 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 3/04/2009 9:04:10 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 3/04/2009 10:52:20 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 4/04/2009 11:20:00 AM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 4/04/2009 11:20:00 AM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 4/04/2009 12:20:00 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 4/04/2009 12:20:00 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 4/04/2009 9:11:00 PM | Computer Name = DOLPHIN | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7C4A95AF-EA25-4AE6-B74E-4C4D26FC8876}
because another computer on the network has the same name. The server could not
start.
< End of report >
AND here is the OTList.Txt
OTListIt logfile created on: 5/04/2009 6:13:53 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\Main\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.99 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 64.76% Memory free
3.84 Gb Paging File | 3.30 Gb Available in Paging File | 85.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 109.87 Gb Free Space | 47.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOLPHIN
Current User Name: Main
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Main\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (fsssvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (InCDsrv [Auto | Running]) – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NMIndexingService [On_Demand | Stopped]) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (SfCtlCom [Auto | Running]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TMBMServer [Auto | Running]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (TmPfw [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (tmproxy [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (fssfltr [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (gdrv [On_Demand | Stopped]) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (InCDfs [Disabled | Running]) – C:\WINDOWS\system32\drivers\InCDFs.sys (Nero AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (incdrm [System | Running]) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RTLE8023xp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (tmactmon [Auto | Running]) – C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmcfw [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmevtmgr [Auto | Running]) – C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmpreflt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\WINDOWS\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (usbbus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (USB_RNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (vsapint [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\vsapint.sys (Trend Micro Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com.au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.com.au"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/11 17:01:11 | 00,000,000 | —D | M]
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Extensions
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Firefox\Profiles\1mqicrfg.default\extensions
[2009/03/08 12:22:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/02/11 17:01:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
O1 HOSTS File: (728 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (no name) - {209ba86b-cd8c-4393-951e-b172ffbca90c} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - C:\WINDOWS\system32\fccdCsst.dll ()
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Main\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (UltimateBet)
O9 - Extra 'Tools' menuitem : UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (UltimateBet)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE}
http://www.worldwinner.com/games/v47/scrab…rabblecubes.cab (ScrabbleCubes Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939}
http://www.worldwinner.com/games/v48/brickout/brickout.cab (Brickout Control)
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8}
http://www.worldwinner.com/games/v47/solit…litairerush.cab (SolitaireRush Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54}
http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab (WWHearts Control)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158}
http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F}
http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab (Blockwerx Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717}
http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42}
http://www.worldwinner.com/games/v49/luxor/luxor.cab (WwLuxor Control)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47}
http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {196d8e11-fd4e-4caa-86d2-58f64970f4ad} - Reg Error: Key error. File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\fccdCsst) - C:\WINDOWS\system32\fccdCsst.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/04/05 18:12:00 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Main\Desktop\OTListIt2.exe
[2009/04/05 16:21:59 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wulbicyu.dll
[2009/04/05 16:21:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gehqvkdg.dll
[2009/04/05 04:24:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wnhthpjx.dll
[2009/04/05 04:21:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\isalhhpy.dll
[2009/04/04 22:57:06 | 00,008,313 | -HS- | C] () – C:\WINDOWS\System32\tssCdccf.ini2
[2009/04/04 12:10:50 | 00,000,095 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/04 11:18:47 | 00,000,933 | —- | C] () – C:\Documents and Settings\Main\Desktop\Spybot - Search & Destroy.lnk
[2009/04/04 11:18:38 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/04/04 11:18:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/04 11:18:37 | 00,001,734 | —- | C] () – C:\Documents and Settings\Main\Desktop\HijackThis.lnk
[2009/04/04 10:32:09 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/04 10:28:51 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/04/04 09:27:33 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wacouvlb.dll
[2009/04/04 09:24:30 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yblhijmh.dll
[2009/04/03 20:05:25 | 00,000,000 | —D | C] – C:\Program Files\RegistryFix7
[2009/04/03 11:14:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\devbvvww.dll
[2009/04/03 11:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wagymaby.dll
[2009/04/02 23:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpcvuxfm.dll
[2009/04/02 11:12:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\mvgnwgfr.dll
[2009/04/02 11:12:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ymaplkre.dll
[2009/04/01 23:18:45 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\rvuljqve.exe
[2009/04/01 23:15:44 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\hopeycbu.dll
[2009/04/01 23:12:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yuskhwwb.dll
[2009/04/01 11:14:59 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\cauyxwrb.exe
[2009/04/01 11:14:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gaaoxvld.dll
[2009/04/01 11:11:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tbsswljo.dll
[2009/03/31 15:50:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fqefrwpx.dll
[2009/03/30 23:34:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\njtynmgo.dll
[2009/03/30 23:31:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\vxgmytmh.dll
[2009/03/29 11:55:07 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\luyejngb.dll
[2009/03/29 11:52:56 | 00,104,448 | —- | C] () – C:\WINDOWS\System32\dhqgul.dll
[2009/03/29 11:52:49 | 00,104,448 | —- | C] () – C:\WINDOWS\System32\aoorbxep.dll
[2009/03/28 10:10:10 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\bnescwdu.dll
[2009/03/28 10:05:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ltscijqs.dll
[2009/03/27 06:41:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\lflxtcpd.dll
[2009/03/27 06:38:52 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\huqngxqh.dll
[2009/03/26 18:41:54 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qqfjqodl.dll
[2009/03/26 18:41:53 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wayfwmay.dll
[2009/03/26 06:44:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\mdqjiqxh.dll
[2009/03/26 06:41:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xgkrwbqm.dll
[2009/03/25 18:28:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\Desktop\sharnie
[2009/03/25 18:26:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\My Documents\sharnie
[2009/03/25 11:23:25 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ejwkxavh.dll
[2009/03/25 11:20:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cqfhvcdr.dll
[2009/03/24 16:26:21 | 00,100,642 | —- | C] () – C:\Documents and Settings\Main\My Documents\m2e.pdf
[2009/03/24 16:24:31 | 00,100,642 | —- | C] () – C:\Documents and Settings\Main\My Documents\m2e - GE Request.pdf
[2009/03/24 11:44:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\byeqdfog.dll
[2009/03/23 21:41:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ssswdpmu.dll
[2009/03/23 21:38:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wygowcfk.dll
[2009/03/23 09:42:43 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfxwxlvb.dll
[2009/03/23 09:39:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\baisxvxh.dll
[2009/03/22 21:42:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\qcbwauql.dll
[2009/03/22 20:09:42 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fopyofuy.dll
[2009/03/21 07:30:41 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hkbfkvct.dll
[2009/03/20 19:30:26 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tohcrtxd.dll
[2009/03/20 19:21:03 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vhjdfjee.dll
[2009/03/19 21:34:15 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/03/19 21:09:17 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/03/19 21:08:50 | 00,055,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
[2009/03/19 21:04:28 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/03/19 20:58:21 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/03/19 20:50:11 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/03/19 20:49:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/03/19 20:48:40 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/03/19 20:26:44 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sygvscyp.dll
[2009/03/19 20:23:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wwxftwfi.dll
[2009/03/19 19:47:53 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/03/19 08:23:42 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tefgcmkq.dll
[2009/03/18 15:45:16 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xbjcprbj.dll
[2009/03/18 03:45:14 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\rxvaummx.dll
[2009/03/17 15:43:09 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ytfueqjp.dll
[2009/03/17 15:43:07 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yfvhwahk.dll
[2009/03/16 07:42:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ifqdwtid.dll
[2009/03/16 00:12:46 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ambkokqe.dll
[2009/03/15 12:35:52 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\fqggapua.dll
[2009/03/15 12:12:37 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tkkqdbja.dll
[2009/03/14 23:16:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dnddfyao.dll
[2009/03/14 23:09:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xraejfbq.dll
[2009/03/14 11:12:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\jgvvjvcy.dll
[2009/03/14 11:09:40 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\strsfxsr.dll
[2009/03/14 08:42:20 | 02,530,850 | —- | C] () – C:\Documents and Settings\Main\My Documents\2009Catalogue.pdf
[2009/03/13 22:07:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yfmwjvpj.dll
[2009/03/13 22:07:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\msumncjk.dll
[2009/03/13 22:05:50 | 00,016,384 | —- | C] () – C:\WINDOWS\DCEBoot.exe
[2009/03/13 10:07:24 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\pjgvvnbj.dll
[2009/03/13 10:07:23 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sohyhmso.dll
[2009/03/12 20:04:22 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfdqqodd.dll
[2009/03/12 20:01:22 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\phreelqa.dll
[2009/03/12 01:05:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qtflxbfk.dll
[2009/03/12 01:02:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xffecacc.dll
[2009/03/11 13:02:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\lrkriggo.dll
[2009/03/11 13:02:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\blvbxadn.dll
[2009/03/10 23:35:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ewudiymt.dll
[2009/03/10 23:35:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ovkqqmpd.dll
[2009/03/10 11:35:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\uflaeoww.dll
[2009/03/10 10:08:50 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\unxrcrrl.dll
[2009/03/09 11:35:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\oukovvqk.dll
[2009/03/09 11:35:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qnsfidhp.dll
[2009/03/08 21:29:06 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\bgwfuwgk.dll
[2009/03/08 21:29:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tnutglap.dll
[2009/03/08 12:20:35 | 00,000,000 | —D | C] – C:\Program Files\The Bar
[2009/03/08 09:32:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vwkgxavx.dll
[2009/03/08 09:29:02 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ljjtoxne.dll
[2009/03/08 08:41:28 | 00,008,678 | -HS- | C] () – C:\Documents and Settings\Main\Desktop\Folder.jpg
[2009/03/08 08:41:28 | 00,002,388 | -HS- | C] () – C:\Documents and Settings\Main\Desktop\AlbumArtSmall.jpg
[2009/03/07 18:20:03 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ndnkostt.dll
[2009/03/07 03:08:18 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ncsutuxx.dll
[2009/03/07 03:08:15 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cslvwuva.dll
[2009/03/06 11:58:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\oxyimmgj.dll
[2009/03/03 22:00:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hafntoso.dll
[2009/03/03 21:57:47 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\xhepesrq.dll
[2009/03/02 21:56:20 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\jhntqtxt.dll
[2009/03/02 21:56:17 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpsbtymx.dll
[2009/03/02 21:55:48 | 00,008,313 | -HS- | C] () – C:\WINDOWS\System32\tssCdccf.ini
[2009/03/02 21:55:41 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\byXPIxyA.dll
[2009/03/02 21:55:30 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\awtqrpoO.dll
[2009/03/02 21:55:18 | 00,236,544 | —- | C] () – C:\WINDOWS\System32\fccdCsst.dll
[2009/03/02 21:54:53 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\hgGxYPFw.dll
[2009/03/02 21:54:28 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\hgGvvtQG.dll
[2009/03/02 21:53:31 | 00,000,026 | —- | C] () – C:\WINDOWS\dksav1.ini
[2009/03/02 21:52:07 | 00,000,018 | —- | C] () – C:\WINDOWS\cnc.ini
[2009/03/02 21:50:37 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\fccdATJY.dll
[2009/03/02 21:50:36 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\nnnoNeEu.dll
[2009/03/02 21:50:10 | 00,005,639 | —- | C] () – C:\WINDOWS\System32\ddcAqNgF.dll
[2009/03/02 21:50:09 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\ljJCtuSi.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\pmnkHAtR.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\mlJYqQki.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\mlJAtULB.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\ddcBRkLd.dll
[2009/02/26 08:16:19 | 00,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2009/02/26 08:16:19 | 00,026,046 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2009/02/11 18:25:13 | 00,000,024 | —- | C] () – C:\WINDOWS\Woabc123.ini
[2009/02/11 18:23:16 | 00,000,108 | —- | C] () – C:\WINDOWS\ABC.ini
[2009/02/11 18:19:39 | 00,000,114 | —- | C] () – C:\WINDOWS\CIF.ini
[2009/02/11 18:14:01 | 00,000,087 | —- | C] () – C:\WINDOWS\KPP.INI
[2009/02/11 18:08:22 | 00,000,082 | —- | C] () – C:\WINDOWS\E1000g.ini
[2009/02/11 17:55:01 | 00,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/02/11 17:54:44 | 00,000,095 | —- | C] () – C:\WINDOWS\101kgv1.ini
[2009/02/09 19:21:28 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2008/12/16 14:11:00 | 00,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2008/10/09 13:26:57 | 00,000,261 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2008/08/25 16:41:01 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/08/20 18:50:28 | 01,355,899 | —- | C] () – C:\WINDOWS\UnInstallNetCommADSL.dll
[2008/08/20 09:37:55 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/08/20 09:09:28 | 00,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2008/08/19 00:49:04 | 00,000,000 | —- | C] () – C:\WINDOWS\control.ini
[2008/08/19 00:47:37 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\desktop.ini
[2008/08/19 00:47:37 | 00,000,002 | —- | C] () – C:\WINDOWS\desktop.ini
[2008/08/19 00:47:18 | 00,000,037 | —- | C] () – C:\WINDOWS\vbaddin.ini
[2008/08/19 00:47:18 | 00,000,036 | —- | C] () – C:\WINDOWS\vb.ini
[2008/08/19 00:46:43 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\tslabels.ini
[2008/08/19 00:46:43 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\msdtcprf.ini
[2008/08/19 00:37:09 | 00,498,742 | —- | C] () – C:\WINDOWS\System32\dxmasf.dll
[2008/08/19 00:37:09 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\msdxmlc.dll
[2008/08/19 00:37:09 | 00,000,576 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/08/19 00:37:03 | 00,053,478 | —- | C] () – C:\WINDOWS\System32\tcpmon.ini
[2008/08/19 00:37:03 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\tsd32.dll
[2008/08/19 00:37:03 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\win87em.dll
[2008/08/19 00:37:03 | 00,000,541 | —- | C] () – C:\WINDOWS\win.ini
[2008/08/19 00:37:03 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2008/08/19 00:37:01 | 00,270,848 | —- | C] () – C:\WINDOWS\System32\sbe.dll
[2008/08/19 00:37:01 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\rsvp.ini
[2008/08/19 00:37:00 | 01,288,192 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2008/08/19 00:37:00 | 00,733,696 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2008/08/19 00:37:00 | 00,562,176 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2008/08/19 00:37:00 | 00,386,048 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2008/08/19 00:37:00 | 00,279,040 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2008/08/19 00:37:00 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2008/08/19 00:37:00 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\pschdprf.ini
[2008/08/19 00:37:00 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\rasctrs.ini
[2008/08/19 00:37:00 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\perfci.ini
[2008/08/19 00:37:00 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\perfwci.ini
[2008/08/19 00:37:00 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\perffilt.ini
[2008/08/19 00:37:00 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\prodspec.ini
[2008/08/19 00:36:59 | 00,035,648 | —- | C] () – C:\WINDOWS\System32\ntio411.sys
[2008/08/19 00:36:59 | 00,035,424 | —- | C] () – C:\WINDOWS\System32\ntio412.sys
[2008/08/19 00:36:59 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio804.sys
[2008/08/19 00:36:59 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio404.sys
[2008/08/19 00:36:59 | 00,033,840 | —- | C] () – C:\WINDOWS\System32\ntio.sys
[2008/08/19 00:36:59 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\ntdos411.sys
[2008/08/19 00:36:59 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\ntdos412.sys
[2008/08/19 00:36:59 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos804.sys
[2008/08/19 00:36:59 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos404.sys
[2008/08/19 00:36:59 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\ntdos.sys
[2008/08/19 00:36:58 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\msencode.dll
[2008/08/19 00:36:58 | 00,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2008/08/19 00:36:58 | 00,001,405 | —- | C] () – C:\WINDOWS\msdfmap.ini
[2008/08/19 00:36:57 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2008/08/19 00:36:56 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\ir32_32.dll
[2008/08/19 00:36:56 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\key01.sys
[2008/08/19 00:36:56 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\keyboard.sys
[2008/08/19 00:36:55 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\esentprf.ini
[2008/08/19 00:36:55 | 00,186,880 | —- | C] () – C:\WINDOWS\System32\encdec.dll
[2008/08/19 00:36:55 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\himem.sys
[2008/08/19 00:36:53 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2008/08/19 00:36:52 | 00,355,112 | —- | C] () – C:\WINDOWS\System32\msjetoledb40.dll
[2008/08/19 00:36:52 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\compatui.dll
[2008/08/19 00:36:52 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2008/08/19 00:36:52 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\country.sys
[2008/08/19 00:36:52 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ansi.sys
[2008/08/18 17:43:21 | 00,458,164 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/08/18 17:43:20 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2001/08/18 08:36:28 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\paqsp.dll
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/04/05 18:16:14 | 00,008,313 | -HS- | M] () – C:\WINDOWS\System32\tssCdccf.ini
[2009/04/05 18:15:30 | 00,008,313 | -HS- | M] () – C:\WINDOWS\System32\tssCdccf.ini2
[2009/04/05 18:12:03 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Main\Desktop\OTListIt2.exe
[2009/04/05 18:10:46 | 00,000,728 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/05 16:21:59 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wulbicyu.dll
[2009/04/05 16:21:57 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\gehqvkdg.dll
[2009/04/05 11:11:23 | 00,458,164 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/05 11:11:23 | 00,392,958 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/05 11:11:23 | 00,059,148 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/05 04:24:55 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wnhthpjx.dll
[2009/04/05 04:21:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\isalhhpy.dll
[2009/04/05 02:20:02 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/04 16:18:46 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/04 16:18:20 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/04 12:10:50 | 00,000,095 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/04/04 11:18:48 | 00,000,933 | —- | M] () – C:\Documents and Settings\Main\Desktop\Spybot - Search & Destroy.lnk
[2009/04/04 11:18:37 | 00,001,734 | —- | M] () – C:\Documents and Settings\Main\Desktop\HijackThis.lnk
[2009/04/04 10:28:35 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/04 09:27:33 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wacouvlb.dll
[2009/04/04 09:24:30 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\yblhijmh.dll
[2009/04/03 12:04:06 | 00,001,167 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/04/03 11:14:56 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\devbvvww.dll
[2009/04/03 11:11:56 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wagymaby.dll
[2009/04/02 23:11:56 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\hpcvuxfm.dll
[2009/04/02 11:12:47 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\mvgnwgfr.dll
[2009/04/02 11:12:46 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ymaplkre.dll
[2009/04/01 23:18:47 | 00,001,108 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/04/01 23:18:45 | 00,061,440 | —- | M] () – C:\WINDOWS\System32\rvuljqve.exe
[2009/04/01 23:15:44 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\hopeycbu.dll
[2009/04/01 23:12:45 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\yuskhwwb.dll
[2009/04/01 16:02:42 | 00,016,384 | —- | M] () – C:\WINDOWS\DCEBoot.exe
[2009/04/01 11:15:01 | 00,061,440 | —- | M] () – C:\WINDOWS\System32\cauyxwrb.exe
[2009/04/01 11:14:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\gaaoxvld.dll
[2009/04/01 11:11:56 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\tbsswljo.dll
[2009/03/31 15:50:57 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\fqefrwpx.dll
[2009/03/31 15:50:28 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/03/30 23:34:50 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\njtynmgo.dll
[2009/03/30 23:31:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\vxgmytmh.dll
[2009/03/30 08:48:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/29 11:55:07 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\luyejngb.dll
[2009/03/29 11:52:55 | 00,104,448 | —- | M] () – C:\WINDOWS\System32\dhqgul.dll
[2009/03/29 11:52:55 | 00,104,448 | —- | M] () – C:\WINDOWS\System32\aoorbxep.dll
[2009/03/28 10:10:10 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\bnescwdu.dll
[2009/03/28 10:05:26 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ltscijqs.dll
[2009/03/27 13:55:26 | 00,000,668 | —- | M] () – C:\Documents and Settings\Main\Application Data\vso_ts_preview.xml
[2009/03/27 06:41:51 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\lflxtcpd.dll
[2009/03/27 06:38:52 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\huqngxqh.dll
[2009/03/26 18:41:54 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qqfjqodl.dll
[2009/03/26 18:41:53 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wayfwmay.dll
[2009/03/26 06:44:51 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\mdqjiqxh.dll
[2009/03/26 06:41:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xgkrwbqm.dll
[2009/03/25 18:25:38 | 00,054,272 | -HS- | M] () – C:\Documents and Settings\Main\My Documents\Thumbs.db
[2009/03/25 11:23:25 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ejwkxavh.dll
[2009/03/25 11:20:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\cqfhvcdr.dll
[2009/03/24 16:26:21 | 00,100,642 | —- | M] () – C:\Documents and Settings\Main\My Documents\m2e.pdf
[2009/03/24 16:24:31 | 00,100,642 | —- | M] () – C:\Documents and Settings\Main\My Documents\m2e - GE Request.pdf
[2009/03/24 11:44:45 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\byeqdfog.dll
[2009/03/23 21:41:45 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ssswdpmu.dll
[2009/03/23 21:38:45 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wygowcfk.dll
[2009/03/23 09:42:43 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dfxwxlvb.dll
[2009/03/23 09:39:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\baisxvxh.dll
[2009/03/22 21:42:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\qcbwauql.dll
[2009/03/22 20:09:42 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\fopyofuy.dll
[2009/03/21 07:30:41 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\hkbfkvct.dll
[2009/03/20 19:30:26 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tohcrtxd.dll
[2009/03/20 19:21:03 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\vhjdfjee.dll
[2009/03/20 19:14:29 | 00,120,544 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/19 21:11:28 | 00,019,448 | —- | M] () – C:\Documents and Settings\Main\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/19 20:51:35 | 00,000,896 | —- | M] () – C:\Documents and Settings\Main\My Documents\My Sharing Folders.lnk
[2009/03/19 20:26:44 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\sygvscyp.dll
[2009/03/19 20:23:46 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wwxftwfi.dll
[2009/03/19 08:23:42 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\tefgcmkq.dll
[2009/03/18 15:45:16 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xbjcprbj.dll
[2009/03/18 03:45:14 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\rxvaummx.dll
[2009/03/17 15:43:09 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ytfueqjp.dll
[2009/03/17 15:43:07 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\yfvhwahk.dll
[2009/03/16 07:42:41 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ifqdwtid.dll
[2009/03/16 00:12:46 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ambkokqe.dll
[2009/03/15 12:35:52 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\fqggapua.dll
[2009/03/15 12:12:37 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tkkqdbja.dll
[2009/03/14 23:16:26 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dnddfyao.dll
[2009/03/14 23:09:35 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xraejfbq.dll
[2009/03/14 11:12:35 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\jgvvjvcy.dll
[2009/03/14 11:09:40 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\strsfxsr.dll
[2009/03/14 08:43:40 | 02,530,850 | —- | M] () – C:\Documents and Settings\Main\My Documents\2009Catalogue.pdf
[2009/03/13 22:07:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\yfmwjvpj.dll
[2009/03/13 22:07:41 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\msumncjk.dll
[2009/03/13 10:07:24 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\pjgvvnbj.dll
[2009/03/13 10:07:23 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\sohyhmso.dll
[2009/03/12 20:04:22 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dfdqqodd.dll
[2009/03/12 20:01:22 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\phreelqa.dll
[2009/03/12 01:05:49 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qtflxbfk.dll
[2009/03/12 01:02:49 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xffecacc.dll
[2009/03/11 13:02:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\lrkriggo.dll
[2009/03/11 13:02:49 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\blvbxadn.dll
[2009/03/10 23:35:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ewudiymt.dll
[2009/03/10 23:35:50 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ovkqqmpd.dll
[2009/03/10 11:35:49 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\uflaeoww.dll
[2009/03/10 10:08:50 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\unxrcrrl.dll
[2009/03/09 13:16:31 | 00,018,944 | —- | M] () – C:\Documents and Settings\Main\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/09 11:35:04 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\oukovvqk.dll
[2009/03/09 11:35:02 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qnsfidhp.dll
[2009/03/08 21:29:06 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\bgwfuwgk.dll
[2009/03/08 21:29:04 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tnutglap.dll
[2009/03/08 09:32:02 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\vwkgxavx.dll
[2009/03/08 09:29:02 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ljjtoxne.dll
[2009/03/08 08:41:28 | 00,008,678 | -HS- | M] () – C:\Documents and Settings\Main\Desktop\Folder.jpg
[2009/03/08 08:41:28 | 00,002,388 | -HS- | M] () – C:\Documents and Settings\Main\Desktop\AlbumArtSmall.jpg
[2009/03/07 18:20:03 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ndnkostt.dll
[2009/03/07 03:08:18 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ncsutuxx.dll
[2009/03/07 03:08:15 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\cslvwuva.dll
========== LOP Check ==========
[2009/04/04 11:18:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/08 19:47:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/08/20 11:32:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/12/08 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/12/08 19:47:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/13 09:38:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/08/20 20:18:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/08/21 20:14:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/04/04 10:28:51 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/19 18:51:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2009/04/04 11:21:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/08 23:03:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/08/21 17:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2008/10/06 19:04:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/08/28 21:37:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/08/21 11:14:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/03/25 18:40:00 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Main\Application Data
[2008/09/28 16:00:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Adobe
[2008/08/20 19:20:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\AdobeUM
[2008/11/12 19:35:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Ahead
[2008/12/08 23:05:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Apple Computer
[2009/02/09 20:03:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Atari
[2008/08/20 21:07:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Google
[2008/10/15 01:30:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Help
[2009/03/04 23:41:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Hoyle
[2009/01/01 09:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Hoyle FaceCreator
[2008/08/19 00:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Identities
[2008/11/12 17:48:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\ImgBurn
[2008/08/20 09:11:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\InstallShield
[2009/02/11 18:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\InterTrust
[2009/02/09 19:19:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Leadertech
[2008/12/18 23:06:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\LG Electronics
[2009/03/22 17:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\LimeWire
[2008/08/22 11:02:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Macromedia
[2009/03/19 20:57:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\Main\Application Data\Microsoft
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Mozilla
[2009/03/10 12:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\OpenOffice.org2
[2008/08/25 10:16:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\SecondLife
[2009/01/26 19:58:15 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Main\Application Data\SecuROM
[2008/08/20 20:36:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Sun
[2009/02/22 12:38:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\uTorrent
[2009/03/27 13:55:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Vso
[2008/10/06 18:46:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\WinRAR
[2009/03/30 08:48:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 22:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/05 02:20:02 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/04/04 16:18:46 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93EB7685
< End of report >