dougmcisaac
Topic Starter
This will sound familiar because I found another thread with the same issue and I'll be posting my log file below, but what's happenning is when Googling things in both IE and Firefox and keep getting redirecting via http:// 209.85.171.79/x/… and http:// 216.133.243.28/2.php… I tried Malwarebytes, and SUPERAntispyware, nothing is working. On top of this, Firefox now continues to crash. I also can't get Microsoft updates to work, but I assume that it's related.
Any help is appreciated, I'm about to fdisk and start over
Here's my OTList log
OTListIt logfile created on: 4/4/2009 6:54:29 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\dougm\Local Settings\Temporary Internet Files\Content.IE5\UELKVJBQ
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.26 Gb Available Physical Memory | 63.19% Memory free
3.85 Gb Paging File | 3.10 Gb Available in Paging File | 80.62% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 8.73 Gb Free Space | 11.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOUGMCISAAC
Current User Name: dougm
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - c:\program files\lenovo\system update\suservice.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\System32\TPHDEXLG.exe (Lenovo.)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\dougm\Local Settings\Temporary Internet Files\Content.IE5\UELKVJBQ\OTListIt2[1].exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (acs [Auto | Running]) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c903cbc23535a2 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Stopped]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (IBMPMSVC [Auto | Running]) – C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (lxbx_device [On_Demand | Stopped]) – C:\WINDOWS\system32\lxbxcoms.exe (Lexmark International, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (Net Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (SmcService [Auto | Stopped]) – File not found
SRV - (SNAC [On_Demand | Stopped]) – File not found
SRV - (SUService [Auto | Running]) – c:\program files\lenovo\system update\suservice.exe (Lenovo Group Limited)
SRV - (TPHDEXLGSVC [Auto | Running]) – C:\WINDOWS\System32\TPHDEXLG.exe (Lenovo.)
SRV - (TVT Scheduler [Auto | Running]) – C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AR5211 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ar5211.sys (Atheros Communications, Inc.)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\COH_Mon.sys (Symantec Corporation)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (IBMPMDRV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys (Lenovo.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\motmodem.sys (Motorola)
DRV - (NSCIRDA [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nscirda.sys (National Semiconductor Corporation)
DRV - (PCLEPCI [System | Running]) – C:\WINDOWS\system32\drivers\pclepci.sys (Pinnacle Systems GmbH)
DRV - (psadd [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\psadd.sys (Lenovo (United States) Inc.)
DRV - (PTDMBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMBus.sys (DEVGURU Co,LTD.)
DRV - (PTDMMdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDMVsp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDMWWAN [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDUBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUBus.sys (DEVGURU Co,LTD.)
DRV - (PTDUMdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDUVsp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDUWWAN [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDWBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDWBus.sys (DEVGURU Co,LTD.)
DRV - (PTDWMdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDWMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDWVsp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDWVsp.sys (DEVGURU Co,LTD.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PWCTLDRV [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\PWCTLDRV.sys (DEVGURU Co,LTD.)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Shockprf [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (smihlp [Auto | Running]) – C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys (UPEK Inc.)
DRV - (SMNDIS5 [On_Demand | Stopped]) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (sonypvs1 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sonypvs1.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (SRTSP [System | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPL.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) – C:\WINDOWS\System32\Drivers\SRTSPX.SYS (Symantec Corporation)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (SysPlant [Boot | Running]) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (TcUsb [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\tcusb.sys (UPEK Inc.)
DRV - (Teefer2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\teefer2.sys (Symantec Corporation)
DRV - (TPDIGIMN [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (TPDiskPM [Boot | Running]) – C:\WINDOWS\System32\drivers\TPDiskPM.sys (Lenovo, Ltd. and IBM Corporation)
DRV - (TPHKDRV [System | Running]) – C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys (IBM Corporation)
DRV - (TPInput [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\TPInput.sys (Lenovo, Ltd. and IBM Corporation.)
DRV - (TPM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\tpm.sys (Winbond Electronics Corp.)
DRV - (TPPWRIF [System | Running]) – C:\WINDOWS\System32\drivers\Tppwrif.sys ()
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WPS [System | Running]) – C:\WINDOWS\System32\drivers\wpsdrvnt.sys (Symantec Corporation)
DRV - (WpsHelper [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WpsHelper.sys (Symantec Corporation)
DRV - (WSIMD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wsimd.sys (Atheros Communications, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.simpleology.com/webcockpit/dt.php;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-sunm&p;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.780
FF - prefs.js..extensions.enabledItems: {e1170235-2845-420c-acc3-42261a29dd46}:3.5.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.2.1
FF - prefs.js..extensions.enabledItems: {e2337727-f9c9-411b-929e-287584341d1a}:3.1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.5
FF - prefs.js..extensions.enabledItems: {ada4b710-8346-4b82-8199-5de2b400a6ae}:1.9.1
FF - prefs.js..extensions.enabledItems: [removed]:3.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6
FF - prefs.js..extensions.enabledItems: [removed]:0.7
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.28
FF - prefs.js..extensions.enabledItems: [removed]:1.0.13610
FF - prefs.js..extensions.enabledItems: {7104ec46-5dfb-4609-84f0-915970e383d7}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {d9284e50-81fc-11da-a72b-0800200c9a66}:5.4.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-sunm&p;="
FF - HKLM\software\mozilla\Flock 2.0\extensions\\Components: C:\PROGRAM FILES\FLOCK\COMPONENTS [2009/02/06 18:03:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock 2.0\extensions\\Plugins: C:\PROGRAM FILES\FLOCK\PLUGINS [2009/01/23 09:39:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock 2.0.3\extensions\\Components: C:\PROGRAM FILES\FLOCK\COMPONENTS [2009/02/06 18:03:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock 2.0.3\extensions\\Plugins: C:\PROGRAM FILES\FLOCK\PLUGINS [2009/01/23 09:39:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/31 11:03:59 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/31 11:03:59 | 00,000,000 | —D | M]
[2008/10/15 08:55:40 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions
[2008/10/15 08:55:40 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2009/03/15 14:56:29 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2008/12/08 13:14:17 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/09/05 23:47:43 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\[removed]
[2009/04/04 18:37:28 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions
[2008/12/13 17:59:37 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/03/30 21:45:18 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/06/23 10:19:19 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{7104ec46-5dfb-4609-84f0-915970e383d7}
[2009/03/31 13:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2008/12/08 13:14:53 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/03/31 13:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}
[2008/12/11 17:33:33 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2009/03/31 13:00:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{e2337727-f9c9-411b-929e-287584341d1a}
[2009/03/31 13:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/05/26 19:27:05 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/12/05 16:35:59 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/30 21:45:07 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/30 21:45:07 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/06/06 10:48:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/06/16 17:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/31 13:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/31 13:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]\chrome
[2009/03/31 13:00:09 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]\defaults
[2009/04/04 18:37:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/31 11:03:59 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/10/31 11:03:06 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2007/11/13 16:17:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/04/30 17:40:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/12/23 15:34:39 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/04 18:37:24 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/03/31 11:03:34 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/31 11:03:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/31 11:03:50 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/31 11:03:50 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/31 11:03:50 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/31 11:03:50 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/31 11:03:50 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/31 11:03:50 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/31 11:03:50 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (227608 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 7986 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Clipmarks) - {1205D44C-FFD2-44E5-AA1D-929DCA37EB7A} - C:\Program Files\Clipmarks\clipmarks.dll (Clipmarks, LLC)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {71AAABE5-1F0F-11D7-BD6F-004854603DCE} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKCU..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (Siber Systems)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html File not found
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html File not found
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html File not found
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: stumbleupon.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: 32 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} http://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1188683939343 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199907421484 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} https://ediagnostics.lexmark.com/serval.cab (Lexmark eDiagnostics Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.3.4.cab (DLM Control)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\WINDOWS\system32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\psfus: DllName - C:\WINDOWS\system32\psqlpwd.dll - C:\WINDOWS\system32\psqlpwd.dll (UPEK Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll ()
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{26afc37c-a98a-11dc-93c9-000e9bbfad25}\Shell\Setup\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{8b3105ae-9323-11dc-93c3-000e9bbfad25}\Shell\Setup\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{bb246275-9f00-11dc-93c4-000e9bbfad25}\Shell\Setup\command - "" = C:\WINDOWS\system32\setup.exe – [2008/04/14 05:42:36 | 00,023,040 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{dcfb5f92-e1b6-11dc-93fd-000e9bbfad25}\Shell - "" = AutoRun
O33 - MountPoints2\{dcfb5f92-e1b6-11dc-93fd-000e9bbfad25}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{dcfb5f92-e1b6-11dc-93fd-000e9bbfad25}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[15 C:\WINDOWS\*.tmp files]
[2009/04/04 11:29:56 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2009/04/04 11:29:53 | 00,000,000 | R–D | C] – C:\Program Files\Skype
[2009/04/04 11:11:38 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/04/03 15:09:42 | 25,084,330 | —- | C] (Intellimon Ltd) – C:\Documents and Settings\dougm\Desktop\xsitepro2-update123.exe
[2009/04/03 14:06:18 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\SocialBot
[2009/04/03 13:58:55 | 00,274,284 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SocialBot.zip
[2009/04/03 10:42:23 | 00,001,358 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/04/03 10:40:07 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\SmitfraudFix
[2009/04/03 10:39:48 | 01,580,523 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SmitfraudFix.exe
[2009/04/03 09:43:10 | 00,000,694 | —- | C] () – C:\Documents and Settings\dougm\Desktop\XSitePro2.lnk
[2009/04/02 22:51:13 | 00,162,366 | —- | C] () – C:\Documents and Settings\dougm\Desktop\strategycashmap.pdf
[2009/04/02 16:15:51 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Local Settings\Application Data\Deployment
[2009/04/02 10:55:23 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/04/02 10:55:23 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/02 10:55:22 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/04/02 10:55:21 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/04/02 10:55:19 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/04/02 10:55:19 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/04/02 10:55:19 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/04/02 10:55:18 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/04/02 10:55:18 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/04/02 10:55:00 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/04/02 10:55:00 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/04/02 10:54:54 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/04/01 18:28:00 | 00,153,277 | —- | C] () – C:\Documents and Settings\dougm\Desktop\affiliatebanners.zip
[2009/04/01 14:52:42 | 32,793,088 | —- | C] () – C:\Documents and Settings\dougm\Desktop\setupeng.exe
[2009/04/01 14:43:12 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/04/01 14:43:04 | 00,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/04/01 14:42:47 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/04/01 14:42:47 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Application Data\SUPERAntiSpyware.com
[2009/04/01 14:40:02 | 00,001,548 | —- | C] () – C:\Documents and Settings\dougm\Desktop\CCleaner.lnk
[2009/04/01 14:39:59 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/03/31 14:48:17 | 00,014,050 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SAMP.pdf
[2009/03/31 13:31:04 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\quickcash09
[2009/03/31 10:54:03 | 00,215,922 | —- | C] () – C:\Documents and Settings\dougm\Desktop\marketingguide.doc
[2009/03/30 16:25:50 | 01,678,713 | —- | C] () – C:\Documents and Settings\dougm\Desktop\marketingguide.pdf
[2009/03/30 13:54:33 | 00,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Market Samurai.lnk
[2009/03/30 07:09:07 | 00,556,032 | —- | C] () – C:\Documents and Settings\dougm\Desktop\twitter010909-1231478544984561-2.ppt
[2009/03/30 05:59:10 | 00,014,454 | —- | C] () – C:\Documents and Settings\dougm\Desktop\tweeting-for-biz.pdf
[2009/03/29 21:11:53 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\My Documents\PADGen
[2009/03/29 21:11:53 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Application Data\PADGen
[2009/03/29 21:11:46 | 00,000,654 | —- | C] () – C:\Documents and Settings\dougm\Desktop\PADGen.lnk
[2009/03/29 21:11:45 | 00,000,000 | —D | C] – C:\Program Files\PADGen
[2009/03/29 20:53:58 | 00,000,640 | —- | C] () – C:\Documents and Settings\dougm\Desktop\PromoSoft.lnk
[2009/03/29 20:53:55 | 00,000,000 | —D | C] – C:\Program Files\PromoSoft
[2009/03/29 19:36:41 | 04,363,347 | —- | C] () – C:\Documents and Settings\dougm\Desktop\promosoft.exe
[2009/03/29 07:19:57 | 00,002,561 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SocialBot.lnk
[2009/03/29 07:18:25 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\IS0028
[2009/03/29 07:08:29 | 02,848,507 | —- | C] () – C:\Documents and Settings\dougm\Desktop\IS0028.zip
[2009/03/28 21:15:01 | 71,430,100 | —- | C] () – C:\Documents and Settings\dougm\Desktop\WPD_MC-PartA1_Basics-MPEG-4 .mp4
[2009/03/28 15:33:42 | 00,253,957 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Flippingreportandbonuses.zip
[2009/03/28 11:02:05 | 00,730,249 | —- | C] () – C:\Documents and Settings\dougm\Desktop\ShoeMoney-LAMG-3-28.pdf
[2009/03/27 10:07:11 | 00,501,188 | —- | C] () – C:\Documents and Settings\dougm\Desktop\jan09-articles.zip
[2009/03/27 08:30:25 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\perry_affiliate_peel
[2009/03/27 08:29:57 | 00,000,437 | —- | C] () – C:\Documents and Settings\dougm\Desktop\perry_affiliate_peel.zip
[2009/03/26 21:48:03 | 00,229,729 | —- | C] () – C:\Documents and Settings\dougm\Desktop\JohnnyCantSell.zip
[2009/03/26 21:46:39 | 00,283,115 | —- | C] () – C:\Documents and Settings\dougm\Desktop\johnnycantsell.pdf
[2009/03/26 20:31:22 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\TBNreport1
[2009/03/26 20:26:05 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\TrackingAce
[2009/03/26 20:23:28 | 00,343,646 | —- | C] () – C:\Documents and Settings\dougm\Desktop\TrackingAce.zip
[2009/03/26 20:20:49 | 00,091,848 | —- | C] () – C:\Documents and Settings\dougm\Desktop\TBNreport1.zip
[2009/03/26 13:00:42 | 00,039,424 | —- | C] () – C:\Documents and Settings\dougm\Desktop\R700.doc
[2009/03/26 13:00:06 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\My Documents\Aotoblogs
[2009/03/24 11:30:46 | 00,082,785 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Glen.pdf
[2009/03/23 23:09:20 | 00,422,680 | —- | C] () – C:\Documents and Settings\dougm\Desktop\ChinchillaSecrets.pdf
[2009/03/23 21:51:38 | 01,361,920 | —- | C] () – C:\Documents and Settings\dougm\My Documents\chinchilla.msam
[2009/03/23 21:50:46 | 00,000,000 | —D | C] – C:\Program Files\New Folder (3)
[2009/03/23 21:50:40 | 00,000,000 | —D | C] – C:\Program Files\New Folder (2)
[2009/03/23 21:50:31 | 00,000,000 | —D | C] – C:\Program Files\New Folder
[2009/03/23 21:24:45 | 00,780,227 | —- | C] () – C:\Documents and Settings\dougm\Desktop\MarketSamurai.0.80.17.air
[2009/03/23 15:11:20 | 00,860,636 | —- | C] () – C:\Documents and Settings\dougm\Desktop\wp-e-commerce.3.6.10.zip
[2009/03/23 12:56:58 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/03/22 17:21:24 | 00,177,666 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SalesReport.zip
[2009/03/22 13:23:20 | 02,991,384 | —- | C] (Siber Systems) – C:\Documents and Settings\dougm\Desktop\AiRoboForm.exe
[2009/03/21 13:15:52 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\NeedToKnow
[2009/03/21 13:15:29 | 00,389,442 | —- | C] () – C:\Documents and Settings\dougm\Desktop\NeedToKnow.zip
[2009/03/21 10:55:27 | 00,297,984 | —- | C] () – C:\Documents and Settings\dougm\My Documents\aig outrage.msam
[2009/03/20 20:13:53 | 00,139,138 | —- | C] () – C:\Documents and Settings\dougm\Desktop\142106359549c44d9bb7ab7.zip
[2009/03/20 20:09:28 | 03,378,176 | —- | C] () – C:\Documents and Settings\dougm\My Documents\Dog diets 2.msam
[2009/03/20 20:07:27 | 00,000,000 | —D | C] – C:\Program Files\Market Samurai
[2009/03/20 20:00:01 | 55,035,311 | —- | C] () – C:\Documents and Settings\dougm\Desktop\YouTube-Tools.m4v
[2009/03/17 21:52:11 | 28,346,644 | —- | C] (Web CEO Ltd. ) – C:\Documents and Settings\dougm\Desktop\webceo.exe
[2009/03/17 14:14:58 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Application Data\CoreFTP
[2009/03/17 14:14:10 | 00,000,656 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Core FTP Lite.lnk
[2009/03/17 14:14:09 | 00,000,000 | —D | C] – C:\Program Files\CoreFTP
[2009/03/17 14:13:09 | 03,493,695 | —- | C] () – C:\Documents and Settings\dougm\Desktop\coreftplite.exe
[2009/03/17 13:45:14 | 07,171,728 | —- | C] (GlobalSCAPE, Inc. ) – C:\Documents and Settings\dougm\Desktop\cuteftp.exe
[2009/03/13 21:52:14 | 80,390,232 | —- | C] () – C:\Documents and Settings\dougm\Desktop\quickcash09.zip
[2009/03/12 19:14:04 | 01,632,783 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Killer_Content.zip
[2009/03/12 16:36:17 | 00,021,180 | —- | C] () – C:\Documents and Settings\dougm\Desktop\google-friend-connect-integration.0.9.7.4.zip
[2009/03/11 09:16:30 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\spreadsheets
[2009/03/10 19:00:27 | 00,464,170 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Willie%20Crawford%20Build%20a%20Six%20%20Seven%20Figure%20Business%20(2).pdf
[2009/03/10 09:51:19 | 03,475,128 | —- | C] (YouSendIt ) – C:\Documents and Settings\dougm\Desktop\YouSendItExpressSetup2_2_0.exe
[2009/03/10 09:40:31 | 00,025,807 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Willie.wav
[2009/03/08 14:22:30 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/03/08 14:22:18 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/03/08 14:21:06 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/03/08 14:20:54 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/03/07 17:51:42 | 27,660,255 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Google-FriendConnect-Communities.m4v
[2009/03/07 01:12:57 | 00,003,602 | —- | C] () – C:\Documents and Settings\dougm\Desktop\spreadsheets.zip
[2009/03/05 20:39:40 | 00,000,757 | —- | C] () – C:\Documents and Settings\dougm\My Documents\ChatLog Extra Income University 101 2009_03_05 19_39.rtf
[2009/03/05 19:30:04 | 00,000,397 | —- | C] () – C:\Documents and Settings\dougm\My Documents\ChatLog Meet Now 2009_03_05 18_30.rtf
[2008/07/03 14:28:28 | 00,408,576 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2008/07/03 14:28:02 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/07/01 19:25:05 | 00,000,386 | —- | C] () – C:\WINDOWS\SoftWriting.ini
[2008/06/06 14:43:52 | 00,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2008/05/28 08:39:58 | 00,000,051 | —- | C] () – C:\WINDOWS\KeyScript.ini
[2008/03/05 17:50:25 | 03,345,408 | —- | C] () – C:\WINDOWS\System32\avcodec-51.dll
[2008/03/05 17:50:25 | 00,448,512 | —- | C] () – C:\WINDOWS\System32\avformat-50.dll
[2008/03/05 17:50:25 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\avutil-49.dll
[2008/03/04 19:52:34 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2008/02/06 15:00:08 | 01,060,864 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2008/02/06 15:00:06 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2008/01/09 20:00:52 | 00,000,236 | —- | C] () – C:\WINDOWS\ANS2000.INI
[2008/01/09 20:00:52 | 00,000,020 | -H– | C] () – C:\WINDOWS\akebook.ini
[2008/01/09 20:00:52 | 00,000,004 | -H– | C] () – C:\WINDOWS\a3kebook.ini
[2008/01/09 18:45:03 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/09 18:45:03 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/11 16:39:50 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxbxvs.dll
[2007/11/20 11:19:37 | 00,000,438 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2007/11/09 05:01:59 | 00,000,164 | —- | C] () – C:\WINDOWS\System32\psyswin32.dll
[2007/10/31 10:39:54 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/10/25 14:24:28 | 00,012,244 | —- | C] () – C:\WINDOWS\MSUMLT_Y.INI
[2007/09/01 16:45:27 | 00,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2007/09/01 14:23:49 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2007/09/01 13:55:42 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/09/01 13:35:01 | 00,000,000 | —- | C] () – C:\WINDOWS\control.ini
[2007/09/01 13:32:55 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\desktop.ini
[2007/09/01 13:32:55 | 00,000,002 | —- | C] () – C:\WINDOWS\desktop.ini
[2007/09/01 13:32:33 | 00,007,168 | —- | C] () – C:\WINDOWS\System32\bitsprx3.dll
[2007/09/01 13:31:20 | 00,000,037 | —- | C] () – C:\WINDOWS\vbaddin.ini
[2007/09/01 13:31:20 | 00,000,036 | —- | C] () – C:\WINDOWS\vb.ini
[2007/09/01 13:30:36 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\tslabels.ini
[2007/09/01 13:30:35 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\msdtcprf.ini
[2007/08/31 13:00:04 | 00,527,658 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2007/08/31 13:00:03 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/05/17 14:58:10 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/05 14:20:36 | 00,079,400 | —- | C] () – C:\WINDOWS\System32\DEVMAN.DLL
[2006/05/02 16:38:24 | 00,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2005/10/14 16:09:48 | 00,051,304 | —- | C] () – C:\WINDOWS\System32\drivers\atnt40k.sys
[2004/08/04 06:00:00 | 00,001,178 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 06:00:00 | 00,000,285 | —- | C] () – C:\WINDOWS\system.ini
[2003/06/24 14:43:48 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2003/05/07 02:11:58 | 00,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 01,288,192 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2002/08/29 06:00:00 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\esentprf.ini
[2002/08/29 06:00:00 | 00,733,696 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2002/08/29 06:00:00 | 00,562,176 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2002/08/29 06:00:00 | 00,498,742 | —- | C] () – C:\WINDOWS\System32\dxmasf.dll
[2002/08/29 06:00:00 | 00,386,048 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2002/08/29 06:00:00 | 00,355,112 | —- | C] () – C:\WINDOWS\System32\msjetoledb40.dll
[2002/08/29 06:00:00 | 00,279,040 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2002/08/29 06:00:00 | 00,270,848 | —- | C] () – C:\WINDOWS\System32\sbe.dll
[2002/08/29 06:00:00 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\compatui.dll
[2002/08/29 06:00:00 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\ir32_32.dll
[2002/08/29 06:00:00 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2002/08/29 06:00:00 | 00,186,880 | —- | C] () – C:\WINDOWS\System32\encdec.dll
[2002/08/29 06:00:00 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\msencode.dll
[2002/08/29 06:00:00 | 00,071,552 | —- | C] () – C:\WINDOWS\System32\drivers\bridge.sys
[2002/08/29 06:00:00 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2002/08/29 06:00:00 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2002/08/29 06:00:00 | 00,053,478 | —- | C] () – C:\WINDOWS\System32\tcpmon.ini
[2002/08/29 06:00:00 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\key01.sys
[2002/08/29 06:00:00 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\keyboard.sys
[2002/08/29 06:00:00 | 00,035,648 | —- | C] () – C:\WINDOWS\System32\ntio411.sys
[2002/08/29 06:00:00 | 00,035,424 | —- | C] () – C:\WINDOWS\System32\ntio412.sys
[2002/08/29 06:00:00 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2002/08/29 06:00:00 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio804.sys
[2002/08/29 06:00:00 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio404.sys
[2002/08/29 06:00:00 | 00,033,840 | —- | C] () – C:\WINDOWS\System32\ntio.sys
[2002/08/29 06:00:00 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\ntdos411.sys
[2002/08/29 06:00:00 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\ntdos412.sys
[2002/08/29 06:00:00 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos804.sys
[2002/08/29 06:00:00 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos404.sys
[2002/08/29 06:00:00 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\ntdos.sys
[2002/08/29 06:00:00 | 00,027,200 | —- | C] () – C:\WINDOWS\System32\ctl3dv2.dll
[2002/08/29 06:00:00 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\country.sys
[2002/08/29 06:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\w32topl.dll
[2002/08/29 06:00:00 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\tsd32.dll
[2002/08/29 06:00:00 | 00,014,848 | —- | C] () – C:\WINDOWS\System32\mgmtapi.dll
[2002/08/29 06:00:00 | 00,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2002/08/29 06:00:00 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\win87em.dll
[2002/08/29 06:00:00 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\rsvp.ini
[2002/08/29 06:00:00 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\scriptpw.dll
[2002/08/29 06:00:00 | 00,010,110 | —- | C] () – C:\WINDOWS\System32\mqperf.ini
[2002/08/29 06:00:00 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ansi.sys
[2002/08/29 06:00:00 | 00,008,192 | —- | C] () – C:\WINDOWS\System32\mqperf.dll
[2002/08/29 06:00:00 | 00,007,168 | —- | C] () – C:\WINDOWS\System32\wshnetbs.dll
[2002/08/29 06:00:00 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\pschdprf.ini
[2002/08/29 06:00:00 | 00,005,120 | —- | C] () – C:\WINDOWS\System32\winnls.dll
[2002/08/29 06:00:00 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\himem.sys
[2002/08/29 06:00:00 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\msdxmlc.dll
[2002/08/29 06:00:00 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\rasctrs.ini
[2002/08/29 06:00:00 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\perfci.ini
[2002/08/29 06:00:00 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\perfwci.ini
[2002/08/29 06:00:00 | 00,002,656 | —- | C] () – C:\WINDOWS\System32\netware.drv
[2002/08/29 06:00:00 | 00,001,405 | —- | C] () – C:\WINDOWS\msdfmap.ini
[2002/08/29 06:00:00 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\perffilt.ini
[2002/08/29 06:00:00 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\prodspec.ini
[2002/08/29 06:00:00 | 00,000,016 | —- | C] () – C:\WINDOWS\System32\mssqta32.sys
[2002/01/14 23:36:28 | 00,172,032 | —- | C] () – C:\WINDOWS\System32\MP2enc.dll
[2001/08/17 16:36:28 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\paqsp.dll
[1996/02/23 15:34:48 | 00,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[1996/02/22 13:09:20 | 00,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll
========== Files - Modified Within 30 Days ==========
[6 C:\*.tmp files]
[10 C:\WINDOWS\System32\*.tmp files]
[15 C:\WINDOWS\*.tmp files]
[2009/04/04 18:47:02 | 00,000,346 | —- | M] () – C:\WINDOWS\tasks\DesktopMentorDynamic.job
[2009/04/04 18:31:49 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\DesktopMentorDaily.job
[2009/04/04 16:42:42 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/04/04 16:33:14 | 00,001,358 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/04/04 13:36:55 | 00,013,742 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/04 13:33:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/04 13:33:32 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/04 11:18:58 | 00,000,076 | -HS- | M] () – C:\Documents and Settings\dougm\My Documents\desktop.ini
[2009/04/03 15:17:17 | 01,406,983 | —- | M] () – C:\WINDOWS\XSitePro2 Uninstaller.exe
[2009/04/03 15:17:16 | 00,000,694 | —- | M] () – C:\Documents and Settings\dougm\Desktop\XSitePro2.lnk
[2009/04/03 15:13:49 | 25,084,330 | —- | M] (Intellimon Ltd) – C:\Documents and Settings\dougm\Desktop\xsitepro2-update123.exe
[2009/04/03 13:58:57 | 00,274,284 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SocialBot.zip
[2009/04/02 22:51:13 | 00,162,366 | —- | M] () – C:\Documents and Settings\dougm\Desktop\strategycashmap.pdf
[2009/04/02 10:55:23 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/02 10:55:18 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/04/02 10:18:52 | 00,271,784 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/01 22:19:12 | 00,002,561 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SocialBot.lnk
[2009/04/01 18:28:02 | 00,153,277 | —- | M] () – C:\Documents and Settings\dougm\Desktop\affiliatebanners.zip
[2009/04/01 15:32:25 | 00,072,176 | —- | M] () – C:\Documents and Settings\dougm\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/01 14:56:09 | 32,793,088 | —- | M] () – C:\Documents and Settings\dougm\Desktop\setupeng.exe
[2009/04/01 14:43:04 | 00,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/04/01 14:40:02 | 00,001,548 | —- | M] () – C:\Documents and Settings\dougm\Desktop\CCleaner.lnk
[2009/03/31 14:48:20 | 00,014,050 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SAMP.pdf
[2009/03/31 13:21:24 | 00,134,656 | —- | M] () – C:\Documents and Settings\dougm\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/31 10:55:14 | 00,215,922 | —- | M] () – C:\Documents and Settings\dougm\Desktop\marketingguide.doc
[2009/03/30 16:25:50 | 01,678,713 | —- | M] () – C:\Documents and Settings\dougm\Desktop\marketingguide.pdf
[2009/03/30 15:28:28 | 01,336,320 | —- | M] () – C:\Documents and Settings\dougm\My Documents\fireplaces.msam
[2009/03/30 13:54:33 | 00,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Market Samurai.lnk
[2009/03/30 07:09:10 | 00,556,032 | —- | M] () – C:\Documents and Settings\dougm\Desktop\twitter010909-1231478544984561-2.ppt
[2009/03/30 05:59:10 | 00,014,454 | —- | M] () – C:\Documents and Settings\dougm\Desktop\tweeting-for-biz.pdf
[2009/03/29 21:11:46 | 00,000,654 | —- | M] () – C:\Documents and Settings\dougm\Desktop\PADGen.lnk
[2009/03/29 20:53:58 | 00,000,640 | —- | M] () – C:\Documents and Settings\dougm\Desktop\PromoSoft.lnk
[2009/03/29 19:38:18 | 04,363,347 | —- | M] () – C:\Documents and Settings\dougm\Desktop\promosoft.exe
[2009/03/29 07:08:37 | 02,848,507 | —- | M] () – C:\Documents and Settings\dougm\Desktop\IS0028.zip
[2009/03/28 21:20:09 | 71,430,100 | —- | M] () – C:\Documents and Settings\dougm\Desktop\WPD_MC-PartA1_Basics-MPEG-4 .mp4
[2009/03/28 15:33:43 | 00,253,957 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Flippingreportandbonuses.zip
[2009/03/28 11:02:05 | 00,730,249 | —- | M] () – C:\Documents and Settings\dougm\Desktop\ShoeMoney-LAMG-3-28.pdf
[2009/03/27 10:07:13 | 00,501,188 | —- | M] () – C:\Documents and Settings\dougm\Desktop\jan09-articles.zip
[2009/03/27 08:29:58 | 00,000,437 | —- | M] () – C:\Documents and Settings\dougm\Desktop\perry_affiliate_peel.zip
[2009/03/26 21:48:04 | 00,229,729 | —- | M] () – C:\Documents and Settings\dougm\Desktop\JohnnyCantSell.zip
[2009/03/26 21:46:41 | 00,283,115 | —- | M] () – C:\Documents and Settings\dougm\Desktop\johnnycantsell.pdf
[2009/03/26 20:23:28 | 00,343,646 | —- | M] () – C:\Documents and Settings\dougm\Desktop\TrackingAce.zip
[2009/03/26 20:20:50 | 00,091,848 | —- | M] () – C:\Documents and Settings\dougm\Desktop\TBNreport1.zip
[2009/03/26 16:49:56 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/26 16:49:50 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/26 13:00:43 | 00,039,424 | —- | M] () – C:\Documents and Settings\dougm\Desktop\R700.doc
[2009/03/24 11:39:59 | 01,361,920 | —- | M] () – C:\Documents and Settings\dougm\My Documents\chinchilla.msam
[2009/03/24 11:30:47 | 00,082,785 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Glen.pdf
[2009/03/24 00:09:22 | 00,422,680 | —- | M] () – C:\Documents and Settings\dougm\Desktop\ChinchillaSecrets.pdf
[2009/03/23 21:24:46 | 00,780,227 | —- | M] () – C:\Documents and Settings\dougm\Desktop\MarketSamurai.0.80.17.air
[2009/03/23 15:12:07 | 00,860,636 | —- | M] () – C:\Documents and Settings\dougm\Desktop\wp-e-commerce.3.6.10.zip
[2009/03/23 12:56:44 | 21,453,86496 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2009/03/22 17:21:25 | 00,177,666 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SalesReport.zip
[2009/03/22 13:23:40 | 02,991,384 | —- | M] (Siber Systems) – C:\Documents and Settings\dougm\Desktop\AiRoboForm.exe
[2009/03/21 13:15:30 | 00,389,442 | —- | M] () – C:\Documents and Settings\dougm\Desktop\NeedToKnow.zip
[2009/03/21 11:38:25 | 00,297,984 | —- | M] () – C:\Documents and Settings\dougm\My Documents\aig outrage.msam
[2009/03/20 20:39:10 | 03,378,176 | —- | M] () – C:\Documents and Settings\dougm\My Documents\Dog diets 2.msam
[2009/03/20 20:16:07 | 55,035,311 | —- | M] () – C:\Documents and Settings\dougm\Desktop\YouTube-Tools.m4v
[2009/03/20 20:14:00 | 00,139,138 | —- | M] () – C:\Documents and Settings\dougm\Desktop\142106359549c44d9bb7ab7.zip
[2009/03/17 21:55:28 | 28,346,644 | —- | M] (Web CEO Ltd. ) – C:\Documents and Settings\dougm\Desktop\webceo.exe
[2009/03/17 14:14:10 | 00,000,656 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Core FTP Lite.lnk
[2009/03/17 14:13:44 | 03,493,695 | —- | M] () – C:\Documents and Settings\dougm\Desktop\coreftplite.exe
[2009/03/17 13:46:04 | 07,171,728 | —- | M] (GlobalSCAPE, Inc. ) – C:\Documents and Settings\dougm\Desktop\cuteftp.exe
[2009/03/13 22:00:20 | 80,390,232 | —- | M] () – C:\Documents and Settings\dougm\Desktop\quickcash09.zip
[2009/03/12 19:14:12 | 01,632,783 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Killer_Content.zip
[2009/03/12 16:36:17 | 00,021,180 | —- | M] () – C:\Documents and Settings\dougm\Desktop\google-friend-connect-integration.0.9.7.4.zip
[2009/03/12 07:05:51 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/10 19:00:27 | 00,464,170 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Willie%20Crawford%20Build%20a%20Six%20%20Seven%20Figure%20Business%20(2).pdf
[2009/03/10 18:04:54 | 00,445,532 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/10 18:04:54 | 00,073,014 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/10 18:04:51 | 00,527,658 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/10 09:51:44 | 03,475,128 | —- | M] (YouSendIt ) – C:\Documents and Settings\dougm\Desktop\YouSendItExpressSetup2_2_0.exe
[2009/03/10 09:40:33 | 00,025,807 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Willie.wav
[2009/03/08 14:22:46 | 01,241,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/03/08 14:22:46 | 01,241,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/03/08 14:22:30 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/03/08 14:22:18 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/03/08 14:21:06 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/03/08 14:21:06 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/03/08 14:20:54 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/03/08 14:09:26 | 00,391,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/03/08 14:09:26 | 00,391,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/03/08 04:41:16 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/03/08 04:41:16 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/03/08 04:39:48 | 11,063,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/03/08 04:39:48 | 11,063,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/03/08 04:35:10 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/03/08 04:34:58 | 00,914,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/03/08 04:34:58 | 00,914,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/03/08 04:34:56 | 01,206,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/03/08 04:34:56 | 01,206,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/03/08 04:34:52 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/03/08 04:34:52 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/03/08 04:34:48 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/03/08 04:34:48 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/03/08 04:34:48 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/03/08 04:34:30 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/03/08 04:34:30 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/03/08 04:34:28 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/03/08 04:34:28 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/03/08 04:34:18 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/03/08 04:34:18 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/03/08 04:34:18 | 00,109,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/03/08 04:34:18 | 00,109,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/03/08 04:33:48 | 00,759,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/03/08 04:33:40 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/03/08 04:33:40 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/03/08 04:33:26 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/03/08 04:33:26 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/03/08 04:33:16 | 00,726,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/03/08 04:33:16 | 00,726,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/03/08 04:33:08 | 00,229,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/03/08 04:33:08 | 00,229,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/03/08 04:33:06 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/03/08 04:33:06 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/03/08 04:33:02 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/03/08 04:33:02 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/03/08 04:32:56 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/03/08 04:32:56 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/03/08 04:32:54 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/03/08 04:32:54 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/03/08 04:32:52 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/03/08 04:32:52 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/03/08 04:32:52 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/03/08 04:32:50 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/03/08 04:32:50 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/03/08 04:32:50 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/03/08 04:32:50 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/03/08 04:32:48 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/03/08 04:32:48 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/03/08 04:32:46 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/03/08 04:32:46 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/03/08 04:32:26 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/03/08 04:32:26 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/03/08 04:32:22 | 01,985,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/03/08 04:32:22 | 01,985,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/03/08 04:32:04 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/03/08 04:32:04 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/03/08 04:31:56 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/03/08 04:31:56 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/03/08 04:31:54 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/03/08 04:31:52 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/03/08 04:31:52 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/03/08 04:31:52 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/03/08 04:31:52 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/03/08 04:31:44 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/03/08 04:31:44 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/03/08 04:31:38 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/03/08 04:31:38 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/03/08 04:31:38 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/03/08 04:31:38 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/03/08 04:31:36 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/03/08 04:31:36 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/03/08 04:31:26 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/03/08 04:31:26 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/03/08 04:31:18 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/03/08 04:31:18 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/03/08 04:31:02 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/03/08 04:31:02 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/03/08 04:31:02 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/03/08 04:31:02 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/03/08 04:30:56 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/03/08 04:30:56 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/03/08 04:24:28 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/03/08 04:22:46 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/03/08 04:22:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/03/08 04:22:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/03/08 04:15:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/03/08 04:11:12 | 00,445,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/03/08 04:11:12 | 00,445,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/03/07 17:51:42 | 27,660,255 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Google-FriendConnect-Communities.m4v
[2009/03/07 01:12:51 | 00,003,602 | —- | M] () – C:\Documents and Settings\dougm\Desktop\spreadsheets.zip
[2009/03/05 20:39:40 | 00,000,757 | —- | M] () – C:\Documents and Settings\dougm\My Documents\ChatLog Extra Income University 101 2009_03_05 19_39.rtf
[2009/03/05 19:30:04 | 00,000,397 | —- | M] () – C:\Documents and Settings\dougm\My Documents\ChatLog Meet Now 2009_03_05 18_30.rtf
========== LOP Check ==========
[2009/04/02 10:18:50 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/07/10 13:08:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/01 14:33:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2008/06/12 12:17:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/04/01 14:59:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/01/09 18:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2008/04/04 20:07:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bryxen Software
[2007/12/10 18:29:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2007/10/25 21:43:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2009/03/05 15:05:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/02/28 10:51:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/02/17 14:51:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2008/07/08 15:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/11/18 10:35:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/18 12:52:18 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/01/17 18:36:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/02/08 08:53:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/10/23 13:09:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/06/12 16:05:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PAS
[2008/06/06 15:00:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Picture Perfect Software
[2008/07/20 08:23:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/03/07 10:12:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/04/04 11:29:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2008/06/14 16:34:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/01 14:43:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/03/28 17:48:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/01/01 17:16:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/02/27 20:37:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/27 21:12:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/10/23 10:44:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2007/09/01 16:06:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/01 17:20:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/04/04 16:33:15 | 00,000,000 | RH-D | M] – C:\Documents and Settings\dougm\Application Data
[2007/12/25 00:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Adobe
[2008/05/09 14:43:01 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\AdobeUM
[2008/02/25 18:24:46 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Apple Computer
[2007/10/22 10:28:06 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\ATI
[2008/01/09 18:46:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\AVS4YOU
[2007/11/20 16:03:52 | 00,000,000 | R–D | M] – C:\Documents and Settings\dougm\Application Data\Brother
[2009/04/03 14:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\CoreFTP
[2008/05/21 15:36:26 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2009/02/22 18:58:21 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Desktop Spider
[2008/02/28 10:57:06 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Download Manager
[2007/11/14 13:12:40 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\eBookPro6
[2008/03/05 17:50:37 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Eltima Software
[2007/11/27 15:04:02 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\FileMaker
[2008/06/04 09:28:23 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Flock
[2008/09/04 08:07:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Gael
[2009/03/17 13:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\GlobalSCAPE
[2007/12/26 17:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Good Keywords v2
[2009/03/12 14:54:02 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\GoodSync
[2009/03/15 14:56:25 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Google
[2008/02/28 10:05:47 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Grisoft
[2008/07/30 13:50:38 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\HBA
[2008/07/01 18:55:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Help
[2007/10/23 05:30:59 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Identities
[2009/02/07 23:40:49 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\KompoZer
[2008/05/01 13:40:43 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\LumaPix
[2007/10/23 09:54:58 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Macromedia
[2008/11/18 10:35:11 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Malwarebytes
[2008/08/02 15:57:39 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2008/01/21 08:57:19 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Media Player Classic
[2009/02/18 12:52:18 | 00,000,000 | –SD | M] – C:\Documents and Settings\dougm\Application Data\Microsoft
[2008/09/05 23:47:43 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Mozilla
[2009/02/08 08:53:04 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\NCH Swift Sound
[2007/10/23 13:15:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\OfficeUpdate12
[2009/03/29 21:11:54 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\PADGen
[2008/06/12 16:08:01 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Palo Alto Software
[2008/09/05 23:47:39 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Scribd
[2008/09/05 23:47:39 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Scribd.com
[2009/04/04 11:30:55 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Skype
[2009/04/04 09:47:49 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\skypePM
[2009/01/27 19:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Smith Micro
[2009/02/22 18:59:45 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Spider
[2007/12/25 00:04:02 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\StomperScrutinizer.80D30D081DF260F3E4CECC0C2A6ADDA2F74D545F.1
[2007/10/31 11:02:36 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Sun
[2009/04/01 14:42:47 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\SUPERAntiSpyware.com
[2008/12/09 12:26:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/03/02 19:21:29 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\U3
[2008/07/31 15:49:27 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\WinRAR
[2009/02/27 20:35:14 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\XnView
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/04 18:31:49 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\DesktopMentorDaily.job
[2009/04/04 18:47:02 | 00,000,346 | —- | M] () – C:\WINDOWS\Tasks\DesktopMentorDynamic.job
[2009/04/04 16:42:42 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2008/02/28 12:42:09 | 00,000,300 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job
[2009/04/04 13:33:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44807EFA
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Any help is appreciated, I'm about to fdisk and start over
Here's my OTList log
OTListIt logfile created on: 4/4/2009 6:54:29 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\dougm\Local Settings\Temporary Internet Files\Content.IE5\UELKVJBQ
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.26 Gb Available Physical Memory | 63.19% Memory free
3.85 Gb Paging File | 3.10 Gb Available in Paging File | 80.62% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 8.73 Gb Free Space | 11.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOUGMCISAAC
Current User Name: dougm
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - c:\program files\lenovo\system update\suservice.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\System32\TPHDEXLG.exe (Lenovo.)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\dougm\Local Settings\Temporary Internet Files\Content.IE5\UELKVJBQ\OTListIt2[1].exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (acs [Auto | Running]) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c903cbc23535a2 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Stopped]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (IBMPMSVC [Auto | Running]) – C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (lxbx_device [On_Demand | Stopped]) – C:\WINDOWS\system32\lxbxcoms.exe (Lexmark International, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (Net Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (SmcService [Auto | Stopped]) – File not found
SRV - (SNAC [On_Demand | Stopped]) – File not found
SRV - (SUService [Auto | Running]) – c:\program files\lenovo\system update\suservice.exe (Lenovo Group Limited)
SRV - (TPHDEXLGSVC [Auto | Running]) – C:\WINDOWS\System32\TPHDEXLG.exe (Lenovo.)
SRV - (TVT Scheduler [Auto | Running]) – C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AR5211 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ar5211.sys (Atheros Communications, Inc.)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\COH_Mon.sys (Symantec Corporation)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (IBMPMDRV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys (Lenovo.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\motmodem.sys (Motorola)
DRV - (NSCIRDA [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nscirda.sys (National Semiconductor Corporation)
DRV - (PCLEPCI [System | Running]) – C:\WINDOWS\system32\drivers\pclepci.sys (Pinnacle Systems GmbH)
DRV - (psadd [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\psadd.sys (Lenovo (United States) Inc.)
DRV - (PTDMBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMBus.sys (DEVGURU Co,LTD.)
DRV - (PTDMMdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDMVsp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDMWWAN [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDMWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDUBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUBus.sys (DEVGURU Co,LTD.)
DRV - (PTDUMdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDUVsp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDUWWAN [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDUWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDWBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDWBus.sys (DEVGURU Co,LTD.)
DRV - (PTDWMdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDWMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDWVsp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PTDWVsp.sys (DEVGURU Co,LTD.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PWCTLDRV [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\PWCTLDRV.sys (DEVGURU Co,LTD.)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Shockprf [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (smihlp [Auto | Running]) – C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys (UPEK Inc.)
DRV - (SMNDIS5 [On_Demand | Stopped]) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (sonypvs1 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sonypvs1.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (SRTSP [System | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPL.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) – C:\WINDOWS\System32\Drivers\SRTSPX.SYS (Symantec Corporation)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (SysPlant [Boot | Running]) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (TcUsb [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\tcusb.sys (UPEK Inc.)
DRV - (Teefer2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\teefer2.sys (Symantec Corporation)
DRV - (TPDIGIMN [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (TPDiskPM [Boot | Running]) – C:\WINDOWS\System32\drivers\TPDiskPM.sys (Lenovo, Ltd. and IBM Corporation)
DRV - (TPHKDRV [System | Running]) – C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys (IBM Corporation)
DRV - (TPInput [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\TPInput.sys (Lenovo, Ltd. and IBM Corporation.)
DRV - (TPM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\tpm.sys (Winbond Electronics Corp.)
DRV - (TPPWRIF [System | Running]) – C:\WINDOWS\System32\drivers\Tppwrif.sys ()
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WPS [System | Running]) – C:\WINDOWS\System32\drivers\wpsdrvnt.sys (Symantec Corporation)
DRV - (WpsHelper [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WpsHelper.sys (Symantec Corporation)
DRV - (WSIMD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wsimd.sys (Atheros Communications, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.simpleology.com/webcockpit/dt.php;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-sunm&p;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.780
FF - prefs.js..extensions.enabledItems: {e1170235-2845-420c-acc3-42261a29dd46}:3.5.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.2.1
FF - prefs.js..extensions.enabledItems: {e2337727-f9c9-411b-929e-287584341d1a}:3.1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.5
FF - prefs.js..extensions.enabledItems: {ada4b710-8346-4b82-8199-5de2b400a6ae}:1.9.1
FF - prefs.js..extensions.enabledItems: [removed]:3.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6
FF - prefs.js..extensions.enabledItems: [removed]:0.7
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.28
FF - prefs.js..extensions.enabledItems: [removed]:1.0.13610
FF - prefs.js..extensions.enabledItems: {7104ec46-5dfb-4609-84f0-915970e383d7}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {d9284e50-81fc-11da-a72b-0800200c9a66}:5.4.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-sunm&p;="
FF - HKLM\software\mozilla\Flock 2.0\extensions\\Components: C:\PROGRAM FILES\FLOCK\COMPONENTS [2009/02/06 18:03:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock 2.0\extensions\\Plugins: C:\PROGRAM FILES\FLOCK\PLUGINS [2009/01/23 09:39:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock 2.0.3\extensions\\Components: C:\PROGRAM FILES\FLOCK\COMPONENTS [2009/02/06 18:03:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock 2.0.3\extensions\\Plugins: C:\PROGRAM FILES\FLOCK\PLUGINS [2009/01/23 09:39:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/31 11:03:59 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/31 11:03:59 | 00,000,000 | —D | M]
[2008/10/15 08:55:40 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions
[2008/10/15 08:55:40 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2009/03/15 14:56:29 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2008/12/08 13:14:17 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/09/05 23:47:43 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Extensions\[removed]
[2009/04/04 18:37:28 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions
[2008/12/13 17:59:37 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/03/30 21:45:18 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/06/23 10:19:19 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{7104ec46-5dfb-4609-84f0-915970e383d7}
[2009/03/31 13:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2008/12/08 13:14:53 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/03/31 13:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}
[2008/12/11 17:33:33 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2009/03/31 13:00:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\{e2337727-f9c9-411b-929e-287584341d1a}
[2009/03/31 13:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/05/26 19:27:05 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/12/05 16:35:59 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/30 21:45:07 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/30 21:45:07 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/06/06 10:48:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2008/06/16 17:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/31 13:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]
[2009/03/31 13:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]\chrome
[2009/03/31 13:00:09 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\mozilla\Firefox\Profiles\6rdbemrt.default\extensions\[removed]\defaults
[2009/04/04 18:37:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/31 11:03:59 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/10/31 11:03:06 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2007/11/13 16:17:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/04/30 17:40:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/12/23 15:34:39 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/04 18:37:24 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/03/31 11:03:34 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/31 11:03:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/31 11:03:50 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/31 11:03:50 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/31 11:03:50 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/31 11:03:50 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/31 11:03:50 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/31 11:03:50 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/31 11:03:50 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (227608 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 7986 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Clipmarks) - {1205D44C-FFD2-44E5-AA1D-929DCA37EB7A} - C:\Program Files\Clipmarks\clipmarks.dll (Clipmarks, LLC)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {71AAABE5-1F0F-11D7-BD6F-004854603DCE} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKCU..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (Siber Systems)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html File not found
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html File not found
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html File not found
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: stumbleupon.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: 32 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} http://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1188683939343 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199907421484 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} https://ediagnostics.lexmark.com/serval.cab (Lexmark eDiagnostics Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.3.4.cab (DLM Control)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\WINDOWS\system32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\psfus: DllName - C:\WINDOWS\system32\psqlpwd.dll - C:\WINDOWS\system32\psqlpwd.dll (UPEK Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll ()
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{26afc37c-a98a-11dc-93c9-000e9bbfad25}\Shell\Setup\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{8b3105ae-9323-11dc-93c3-000e9bbfad25}\Shell\Setup\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{bb246275-9f00-11dc-93c4-000e9bbfad25}\Shell\Setup\command - "" = C:\WINDOWS\system32\setup.exe – [2008/04/14 05:42:36 | 00,023,040 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{dcfb5f92-e1b6-11dc-93fd-000e9bbfad25}\Shell - "" = AutoRun
O33 - MountPoints2\{dcfb5f92-e1b6-11dc-93fd-000e9bbfad25}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{dcfb5f92-e1b6-11dc-93fd-000e9bbfad25}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[15 C:\WINDOWS\*.tmp files]
[2009/04/04 11:29:56 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2009/04/04 11:29:53 | 00,000,000 | R–D | C] – C:\Program Files\Skype
[2009/04/04 11:11:38 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/04/03 15:09:42 | 25,084,330 | —- | C] (Intellimon Ltd) – C:\Documents and Settings\dougm\Desktop\xsitepro2-update123.exe
[2009/04/03 14:06:18 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\SocialBot
[2009/04/03 13:58:55 | 00,274,284 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SocialBot.zip
[2009/04/03 10:42:23 | 00,001,358 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/04/03 10:40:07 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\SmitfraudFix
[2009/04/03 10:39:48 | 01,580,523 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SmitfraudFix.exe
[2009/04/03 09:43:10 | 00,000,694 | —- | C] () – C:\Documents and Settings\dougm\Desktop\XSitePro2.lnk
[2009/04/02 22:51:13 | 00,162,366 | —- | C] () – C:\Documents and Settings\dougm\Desktop\strategycashmap.pdf
[2009/04/02 16:15:51 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Local Settings\Application Data\Deployment
[2009/04/02 10:55:23 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/04/02 10:55:23 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/02 10:55:22 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/04/02 10:55:21 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/04/02 10:55:19 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/04/02 10:55:19 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/04/02 10:55:19 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/04/02 10:55:18 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/04/02 10:55:18 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/04/02 10:55:00 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/04/02 10:55:00 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/04/02 10:54:54 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/04/01 18:28:00 | 00,153,277 | —- | C] () – C:\Documents and Settings\dougm\Desktop\affiliatebanners.zip
[2009/04/01 14:52:42 | 32,793,088 | —- | C] () – C:\Documents and Settings\dougm\Desktop\setupeng.exe
[2009/04/01 14:43:12 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/04/01 14:43:04 | 00,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/04/01 14:42:47 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/04/01 14:42:47 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Application Data\SUPERAntiSpyware.com
[2009/04/01 14:40:02 | 00,001,548 | —- | C] () – C:\Documents and Settings\dougm\Desktop\CCleaner.lnk
[2009/04/01 14:39:59 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/03/31 14:48:17 | 00,014,050 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SAMP.pdf
[2009/03/31 13:31:04 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\quickcash09
[2009/03/31 10:54:03 | 00,215,922 | —- | C] () – C:\Documents and Settings\dougm\Desktop\marketingguide.doc
[2009/03/30 16:25:50 | 01,678,713 | —- | C] () – C:\Documents and Settings\dougm\Desktop\marketingguide.pdf
[2009/03/30 13:54:33 | 00,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Market Samurai.lnk
[2009/03/30 07:09:07 | 00,556,032 | —- | C] () – C:\Documents and Settings\dougm\Desktop\twitter010909-1231478544984561-2.ppt
[2009/03/30 05:59:10 | 00,014,454 | —- | C] () – C:\Documents and Settings\dougm\Desktop\tweeting-for-biz.pdf
[2009/03/29 21:11:53 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\My Documents\PADGen
[2009/03/29 21:11:53 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Application Data\PADGen
[2009/03/29 21:11:46 | 00,000,654 | —- | C] () – C:\Documents and Settings\dougm\Desktop\PADGen.lnk
[2009/03/29 21:11:45 | 00,000,000 | —D | C] – C:\Program Files\PADGen
[2009/03/29 20:53:58 | 00,000,640 | —- | C] () – C:\Documents and Settings\dougm\Desktop\PromoSoft.lnk
[2009/03/29 20:53:55 | 00,000,000 | —D | C] – C:\Program Files\PromoSoft
[2009/03/29 19:36:41 | 04,363,347 | —- | C] () – C:\Documents and Settings\dougm\Desktop\promosoft.exe
[2009/03/29 07:19:57 | 00,002,561 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SocialBot.lnk
[2009/03/29 07:18:25 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\IS0028
[2009/03/29 07:08:29 | 02,848,507 | —- | C] () – C:\Documents and Settings\dougm\Desktop\IS0028.zip
[2009/03/28 21:15:01 | 71,430,100 | —- | C] () – C:\Documents and Settings\dougm\Desktop\WPD_MC-PartA1_Basics-MPEG-4 .mp4
[2009/03/28 15:33:42 | 00,253,957 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Flippingreportandbonuses.zip
[2009/03/28 11:02:05 | 00,730,249 | —- | C] () – C:\Documents and Settings\dougm\Desktop\ShoeMoney-LAMG-3-28.pdf
[2009/03/27 10:07:11 | 00,501,188 | —- | C] () – C:\Documents and Settings\dougm\Desktop\jan09-articles.zip
[2009/03/27 08:30:25 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\perry_affiliate_peel
[2009/03/27 08:29:57 | 00,000,437 | —- | C] () – C:\Documents and Settings\dougm\Desktop\perry_affiliate_peel.zip
[2009/03/26 21:48:03 | 00,229,729 | —- | C] () – C:\Documents and Settings\dougm\Desktop\JohnnyCantSell.zip
[2009/03/26 21:46:39 | 00,283,115 | —- | C] () – C:\Documents and Settings\dougm\Desktop\johnnycantsell.pdf
[2009/03/26 20:31:22 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\TBNreport1
[2009/03/26 20:26:05 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\TrackingAce
[2009/03/26 20:23:28 | 00,343,646 | —- | C] () – C:\Documents and Settings\dougm\Desktop\TrackingAce.zip
[2009/03/26 20:20:49 | 00,091,848 | —- | C] () – C:\Documents and Settings\dougm\Desktop\TBNreport1.zip
[2009/03/26 13:00:42 | 00,039,424 | —- | C] () – C:\Documents and Settings\dougm\Desktop\R700.doc
[2009/03/26 13:00:06 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\My Documents\Aotoblogs
[2009/03/24 11:30:46 | 00,082,785 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Glen.pdf
[2009/03/23 23:09:20 | 00,422,680 | —- | C] () – C:\Documents and Settings\dougm\Desktop\ChinchillaSecrets.pdf
[2009/03/23 21:51:38 | 01,361,920 | —- | C] () – C:\Documents and Settings\dougm\My Documents\chinchilla.msam
[2009/03/23 21:50:46 | 00,000,000 | —D | C] – C:\Program Files\New Folder (3)
[2009/03/23 21:50:40 | 00,000,000 | —D | C] – C:\Program Files\New Folder (2)
[2009/03/23 21:50:31 | 00,000,000 | —D | C] – C:\Program Files\New Folder
[2009/03/23 21:24:45 | 00,780,227 | —- | C] () – C:\Documents and Settings\dougm\Desktop\MarketSamurai.0.80.17.air
[2009/03/23 15:11:20 | 00,860,636 | —- | C] () – C:\Documents and Settings\dougm\Desktop\wp-e-commerce.3.6.10.zip
[2009/03/23 12:56:58 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/03/22 17:21:24 | 00,177,666 | —- | C] () – C:\Documents and Settings\dougm\Desktop\SalesReport.zip
[2009/03/22 13:23:20 | 02,991,384 | —- | C] (Siber Systems) – C:\Documents and Settings\dougm\Desktop\AiRoboForm.exe
[2009/03/21 13:15:52 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\NeedToKnow
[2009/03/21 13:15:29 | 00,389,442 | —- | C] () – C:\Documents and Settings\dougm\Desktop\NeedToKnow.zip
[2009/03/21 10:55:27 | 00,297,984 | —- | C] () – C:\Documents and Settings\dougm\My Documents\aig outrage.msam
[2009/03/20 20:13:53 | 00,139,138 | —- | C] () – C:\Documents and Settings\dougm\Desktop\142106359549c44d9bb7ab7.zip
[2009/03/20 20:09:28 | 03,378,176 | —- | C] () – C:\Documents and Settings\dougm\My Documents\Dog diets 2.msam
[2009/03/20 20:07:27 | 00,000,000 | —D | C] – C:\Program Files\Market Samurai
[2009/03/20 20:00:01 | 55,035,311 | —- | C] () – C:\Documents and Settings\dougm\Desktop\YouTube-Tools.m4v
[2009/03/17 21:52:11 | 28,346,644 | —- | C] (Web CEO Ltd. ) – C:\Documents and Settings\dougm\Desktop\webceo.exe
[2009/03/17 14:14:58 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Application Data\CoreFTP
[2009/03/17 14:14:10 | 00,000,656 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Core FTP Lite.lnk
[2009/03/17 14:14:09 | 00,000,000 | —D | C] – C:\Program Files\CoreFTP
[2009/03/17 14:13:09 | 03,493,695 | —- | C] () – C:\Documents and Settings\dougm\Desktop\coreftplite.exe
[2009/03/17 13:45:14 | 07,171,728 | —- | C] (GlobalSCAPE, Inc. ) – C:\Documents and Settings\dougm\Desktop\cuteftp.exe
[2009/03/13 21:52:14 | 80,390,232 | —- | C] () – C:\Documents and Settings\dougm\Desktop\quickcash09.zip
[2009/03/12 19:14:04 | 01,632,783 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Killer_Content.zip
[2009/03/12 16:36:17 | 00,021,180 | —- | C] () – C:\Documents and Settings\dougm\Desktop\google-friend-connect-integration.0.9.7.4.zip
[2009/03/11 09:16:30 | 00,000,000 | —D | C] – C:\Documents and Settings\dougm\Desktop\spreadsheets
[2009/03/10 19:00:27 | 00,464,170 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Willie%20Crawford%20Build%20a%20Six%20%20Seven%20Figure%20Business%20(2).pdf
[2009/03/10 09:51:19 | 03,475,128 | —- | C] (YouSendIt ) – C:\Documents and Settings\dougm\Desktop\YouSendItExpressSetup2_2_0.exe
[2009/03/10 09:40:31 | 00,025,807 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Willie.wav
[2009/03/08 14:22:30 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/03/08 14:22:18 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/03/08 14:21:06 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/03/08 14:20:54 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/03/07 17:51:42 | 27,660,255 | —- | C] () – C:\Documents and Settings\dougm\Desktop\Google-FriendConnect-Communities.m4v
[2009/03/07 01:12:57 | 00,003,602 | —- | C] () – C:\Documents and Settings\dougm\Desktop\spreadsheets.zip
[2009/03/05 20:39:40 | 00,000,757 | —- | C] () – C:\Documents and Settings\dougm\My Documents\ChatLog Extra Income University 101 2009_03_05 19_39.rtf
[2009/03/05 19:30:04 | 00,000,397 | —- | C] () – C:\Documents and Settings\dougm\My Documents\ChatLog Meet Now 2009_03_05 18_30.rtf
[2008/07/03 14:28:28 | 00,408,576 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2008/07/03 14:28:02 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/07/01 19:25:05 | 00,000,386 | —- | C] () – C:\WINDOWS\SoftWriting.ini
[2008/06/06 14:43:52 | 00,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2008/05/28 08:39:58 | 00,000,051 | —- | C] () – C:\WINDOWS\KeyScript.ini
[2008/03/05 17:50:25 | 03,345,408 | —- | C] () – C:\WINDOWS\System32\avcodec-51.dll
[2008/03/05 17:50:25 | 00,448,512 | —- | C] () – C:\WINDOWS\System32\avformat-50.dll
[2008/03/05 17:50:25 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\avutil-49.dll
[2008/03/04 19:52:34 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2008/02/06 15:00:08 | 01,060,864 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2008/02/06 15:00:06 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2008/01/09 20:00:52 | 00,000,236 | —- | C] () – C:\WINDOWS\ANS2000.INI
[2008/01/09 20:00:52 | 00,000,020 | -H– | C] () – C:\WINDOWS\akebook.ini
[2008/01/09 20:00:52 | 00,000,004 | -H– | C] () – C:\WINDOWS\a3kebook.ini
[2008/01/09 18:45:03 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/09 18:45:03 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/11 16:39:50 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxbxvs.dll
[2007/11/20 11:19:37 | 00,000,438 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2007/11/09 05:01:59 | 00,000,164 | —- | C] () – C:\WINDOWS\System32\psyswin32.dll
[2007/10/31 10:39:54 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/10/25 14:24:28 | 00,012,244 | —- | C] () – C:\WINDOWS\MSUMLT_Y.INI
[2007/09/01 16:45:27 | 00,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2007/09/01 14:23:49 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2007/09/01 13:55:42 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/09/01 13:35:01 | 00,000,000 | —- | C] () – C:\WINDOWS\control.ini
[2007/09/01 13:32:55 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\desktop.ini
[2007/09/01 13:32:55 | 00,000,002 | —- | C] () – C:\WINDOWS\desktop.ini
[2007/09/01 13:32:33 | 00,007,168 | —- | C] () – C:\WINDOWS\System32\bitsprx3.dll
[2007/09/01 13:31:20 | 00,000,037 | —- | C] () – C:\WINDOWS\vbaddin.ini
[2007/09/01 13:31:20 | 00,000,036 | —- | C] () – C:\WINDOWS\vb.ini
[2007/09/01 13:30:36 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\tslabels.ini
[2007/09/01 13:30:35 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\msdtcprf.ini
[2007/08/31 13:00:04 | 00,527,658 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2007/08/31 13:00:03 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/05/17 14:58:10 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/05 14:20:36 | 00,079,400 | —- | C] () – C:\WINDOWS\System32\DEVMAN.DLL
[2006/05/02 16:38:24 | 00,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2005/10/14 16:09:48 | 00,051,304 | —- | C] () – C:\WINDOWS\System32\drivers\atnt40k.sys
[2004/08/04 06:00:00 | 00,001,178 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 06:00:00 | 00,000,285 | —- | C] () – C:\WINDOWS\system.ini
[2003/06/24 14:43:48 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2003/05/07 02:11:58 | 00,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 01,288,192 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2002/08/29 06:00:00 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\esentprf.ini
[2002/08/29 06:00:00 | 00,733,696 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2002/08/29 06:00:00 | 00,562,176 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2002/08/29 06:00:00 | 00,498,742 | —- | C] () – C:\WINDOWS\System32\dxmasf.dll
[2002/08/29 06:00:00 | 00,386,048 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2002/08/29 06:00:00 | 00,355,112 | —- | C] () – C:\WINDOWS\System32\msjetoledb40.dll
[2002/08/29 06:00:00 | 00,279,040 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2002/08/29 06:00:00 | 00,270,848 | —- | C] () – C:\WINDOWS\System32\sbe.dll
[2002/08/29 06:00:00 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\compatui.dll
[2002/08/29 06:00:00 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\ir32_32.dll
[2002/08/29 06:00:00 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2002/08/29 06:00:00 | 00,186,880 | —- | C] () – C:\WINDOWS\System32\encdec.dll
[2002/08/29 06:00:00 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\msencode.dll
[2002/08/29 06:00:00 | 00,071,552 | —- | C] () – C:\WINDOWS\System32\drivers\bridge.sys
[2002/08/29 06:00:00 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2002/08/29 06:00:00 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2002/08/29 06:00:00 | 00,053,478 | —- | C] () – C:\WINDOWS\System32\tcpmon.ini
[2002/08/29 06:00:00 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\key01.sys
[2002/08/29 06:00:00 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\keyboard.sys
[2002/08/29 06:00:00 | 00,035,648 | —- | C] () – C:\WINDOWS\System32\ntio411.sys
[2002/08/29 06:00:00 | 00,035,424 | —- | C] () – C:\WINDOWS\System32\ntio412.sys
[2002/08/29 06:00:00 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2002/08/29 06:00:00 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio804.sys
[2002/08/29 06:00:00 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio404.sys
[2002/08/29 06:00:00 | 00,033,840 | —- | C] () – C:\WINDOWS\System32\ntio.sys
[2002/08/29 06:00:00 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\ntdos411.sys
[2002/08/29 06:00:00 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\ntdos412.sys
[2002/08/29 06:00:00 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos804.sys
[2002/08/29 06:00:00 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos404.sys
[2002/08/29 06:00:00 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\ntdos.sys
[2002/08/29 06:00:00 | 00,027,200 | —- | C] () – C:\WINDOWS\System32\ctl3dv2.dll
[2002/08/29 06:00:00 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\country.sys
[2002/08/29 06:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\w32topl.dll
[2002/08/29 06:00:00 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\tsd32.dll
[2002/08/29 06:00:00 | 00,014,848 | —- | C] () – C:\WINDOWS\System32\mgmtapi.dll
[2002/08/29 06:00:00 | 00,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2002/08/29 06:00:00 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\win87em.dll
[2002/08/29 06:00:00 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\rsvp.ini
[2002/08/29 06:00:00 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\scriptpw.dll
[2002/08/29 06:00:00 | 00,010,110 | —- | C] () – C:\WINDOWS\System32\mqperf.ini
[2002/08/29 06:00:00 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ansi.sys
[2002/08/29 06:00:00 | 00,008,192 | —- | C] () – C:\WINDOWS\System32\mqperf.dll
[2002/08/29 06:00:00 | 00,007,168 | —- | C] () – C:\WINDOWS\System32\wshnetbs.dll
[2002/08/29 06:00:00 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\pschdprf.ini
[2002/08/29 06:00:00 | 00,005,120 | —- | C] () – C:\WINDOWS\System32\winnls.dll
[2002/08/29 06:00:00 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\himem.sys
[2002/08/29 06:00:00 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\msdxmlc.dll
[2002/08/29 06:00:00 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\rasctrs.ini
[2002/08/29 06:00:00 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\perfci.ini
[2002/08/29 06:00:00 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\perfwci.ini
[2002/08/29 06:00:00 | 00,002,656 | —- | C] () – C:\WINDOWS\System32\netware.drv
[2002/08/29 06:00:00 | 00,001,405 | —- | C] () – C:\WINDOWS\msdfmap.ini
[2002/08/29 06:00:00 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\perffilt.ini
[2002/08/29 06:00:00 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\prodspec.ini
[2002/08/29 06:00:00 | 00,000,016 | —- | C] () – C:\WINDOWS\System32\mssqta32.sys
[2002/01/14 23:36:28 | 00,172,032 | —- | C] () – C:\WINDOWS\System32\MP2enc.dll
[2001/08/17 16:36:28 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\paqsp.dll
[1996/02/23 15:34:48 | 00,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[1996/02/22 13:09:20 | 00,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll
========== Files - Modified Within 30 Days ==========
[6 C:\*.tmp files]
[10 C:\WINDOWS\System32\*.tmp files]
[15 C:\WINDOWS\*.tmp files]
[2009/04/04 18:47:02 | 00,000,346 | —- | M] () – C:\WINDOWS\tasks\DesktopMentorDynamic.job
[2009/04/04 18:31:49 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\DesktopMentorDaily.job
[2009/04/04 16:42:42 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/04/04 16:33:14 | 00,001,358 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/04/04 13:36:55 | 00,013,742 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/04 13:33:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/04 13:33:32 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/04 11:18:58 | 00,000,076 | -HS- | M] () – C:\Documents and Settings\dougm\My Documents\desktop.ini
[2009/04/03 15:17:17 | 01,406,983 | —- | M] () – C:\WINDOWS\XSitePro2 Uninstaller.exe
[2009/04/03 15:17:16 | 00,000,694 | —- | M] () – C:\Documents and Settings\dougm\Desktop\XSitePro2.lnk
[2009/04/03 15:13:49 | 25,084,330 | —- | M] (Intellimon Ltd) – C:\Documents and Settings\dougm\Desktop\xsitepro2-update123.exe
[2009/04/03 13:58:57 | 00,274,284 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SocialBot.zip
[2009/04/02 22:51:13 | 00,162,366 | —- | M] () – C:\Documents and Settings\dougm\Desktop\strategycashmap.pdf
[2009/04/02 10:55:23 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/02 10:55:18 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/04/02 10:18:52 | 00,271,784 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/01 22:19:12 | 00,002,561 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SocialBot.lnk
[2009/04/01 18:28:02 | 00,153,277 | —- | M] () – C:\Documents and Settings\dougm\Desktop\affiliatebanners.zip
[2009/04/01 15:32:25 | 00,072,176 | —- | M] () – C:\Documents and Settings\dougm\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/01 14:56:09 | 32,793,088 | —- | M] () – C:\Documents and Settings\dougm\Desktop\setupeng.exe
[2009/04/01 14:43:04 | 00,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/04/01 14:40:02 | 00,001,548 | —- | M] () – C:\Documents and Settings\dougm\Desktop\CCleaner.lnk
[2009/03/31 14:48:20 | 00,014,050 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SAMP.pdf
[2009/03/31 13:21:24 | 00,134,656 | —- | M] () – C:\Documents and Settings\dougm\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/31 10:55:14 | 00,215,922 | —- | M] () – C:\Documents and Settings\dougm\Desktop\marketingguide.doc
[2009/03/30 16:25:50 | 01,678,713 | —- | M] () – C:\Documents and Settings\dougm\Desktop\marketingguide.pdf
[2009/03/30 15:28:28 | 01,336,320 | —- | M] () – C:\Documents and Settings\dougm\My Documents\fireplaces.msam
[2009/03/30 13:54:33 | 00,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Market Samurai.lnk
[2009/03/30 07:09:10 | 00,556,032 | —- | M] () – C:\Documents and Settings\dougm\Desktop\twitter010909-1231478544984561-2.ppt
[2009/03/30 05:59:10 | 00,014,454 | —- | M] () – C:\Documents and Settings\dougm\Desktop\tweeting-for-biz.pdf
[2009/03/29 21:11:46 | 00,000,654 | —- | M] () – C:\Documents and Settings\dougm\Desktop\PADGen.lnk
[2009/03/29 20:53:58 | 00,000,640 | —- | M] () – C:\Documents and Settings\dougm\Desktop\PromoSoft.lnk
[2009/03/29 19:38:18 | 04,363,347 | —- | M] () – C:\Documents and Settings\dougm\Desktop\promosoft.exe
[2009/03/29 07:08:37 | 02,848,507 | —- | M] () – C:\Documents and Settings\dougm\Desktop\IS0028.zip
[2009/03/28 21:20:09 | 71,430,100 | —- | M] () – C:\Documents and Settings\dougm\Desktop\WPD_MC-PartA1_Basics-MPEG-4 .mp4
[2009/03/28 15:33:43 | 00,253,957 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Flippingreportandbonuses.zip
[2009/03/28 11:02:05 | 00,730,249 | —- | M] () – C:\Documents and Settings\dougm\Desktop\ShoeMoney-LAMG-3-28.pdf
[2009/03/27 10:07:13 | 00,501,188 | —- | M] () – C:\Documents and Settings\dougm\Desktop\jan09-articles.zip
[2009/03/27 08:29:58 | 00,000,437 | —- | M] () – C:\Documents and Settings\dougm\Desktop\perry_affiliate_peel.zip
[2009/03/26 21:48:04 | 00,229,729 | —- | M] () – C:\Documents and Settings\dougm\Desktop\JohnnyCantSell.zip
[2009/03/26 21:46:41 | 00,283,115 | —- | M] () – C:\Documents and Settings\dougm\Desktop\johnnycantsell.pdf
[2009/03/26 20:23:28 | 00,343,646 | —- | M] () – C:\Documents and Settings\dougm\Desktop\TrackingAce.zip
[2009/03/26 20:20:50 | 00,091,848 | —- | M] () – C:\Documents and Settings\dougm\Desktop\TBNreport1.zip
[2009/03/26 16:49:56 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/26 16:49:50 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/26 13:00:43 | 00,039,424 | —- | M] () – C:\Documents and Settings\dougm\Desktop\R700.doc
[2009/03/24 11:39:59 | 01,361,920 | —- | M] () – C:\Documents and Settings\dougm\My Documents\chinchilla.msam
[2009/03/24 11:30:47 | 00,082,785 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Glen.pdf
[2009/03/24 00:09:22 | 00,422,680 | —- | M] () – C:\Documents and Settings\dougm\Desktop\ChinchillaSecrets.pdf
[2009/03/23 21:24:46 | 00,780,227 | —- | M] () – C:\Documents and Settings\dougm\Desktop\MarketSamurai.0.80.17.air
[2009/03/23 15:12:07 | 00,860,636 | —- | M] () – C:\Documents and Settings\dougm\Desktop\wp-e-commerce.3.6.10.zip
[2009/03/23 12:56:44 | 21,453,86496 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2009/03/22 17:21:25 | 00,177,666 | —- | M] () – C:\Documents and Settings\dougm\Desktop\SalesReport.zip
[2009/03/22 13:23:40 | 02,991,384 | —- | M] (Siber Systems) – C:\Documents and Settings\dougm\Desktop\AiRoboForm.exe
[2009/03/21 13:15:30 | 00,389,442 | —- | M] () – C:\Documents and Settings\dougm\Desktop\NeedToKnow.zip
[2009/03/21 11:38:25 | 00,297,984 | —- | M] () – C:\Documents and Settings\dougm\My Documents\aig outrage.msam
[2009/03/20 20:39:10 | 03,378,176 | —- | M] () – C:\Documents and Settings\dougm\My Documents\Dog diets 2.msam
[2009/03/20 20:16:07 | 55,035,311 | —- | M] () – C:\Documents and Settings\dougm\Desktop\YouTube-Tools.m4v
[2009/03/20 20:14:00 | 00,139,138 | —- | M] () – C:\Documents and Settings\dougm\Desktop\142106359549c44d9bb7ab7.zip
[2009/03/17 21:55:28 | 28,346,644 | —- | M] (Web CEO Ltd. ) – C:\Documents and Settings\dougm\Desktop\webceo.exe
[2009/03/17 14:14:10 | 00,000,656 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Core FTP Lite.lnk
[2009/03/17 14:13:44 | 03,493,695 | —- | M] () – C:\Documents and Settings\dougm\Desktop\coreftplite.exe
[2009/03/17 13:46:04 | 07,171,728 | —- | M] (GlobalSCAPE, Inc. ) – C:\Documents and Settings\dougm\Desktop\cuteftp.exe
[2009/03/13 22:00:20 | 80,390,232 | —- | M] () – C:\Documents and Settings\dougm\Desktop\quickcash09.zip
[2009/03/12 19:14:12 | 01,632,783 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Killer_Content.zip
[2009/03/12 16:36:17 | 00,021,180 | —- | M] () – C:\Documents and Settings\dougm\Desktop\google-friend-connect-integration.0.9.7.4.zip
[2009/03/12 07:05:51 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/10 19:00:27 | 00,464,170 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Willie%20Crawford%20Build%20a%20Six%20%20Seven%20Figure%20Business%20(2).pdf
[2009/03/10 18:04:54 | 00,445,532 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/10 18:04:54 | 00,073,014 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/10 18:04:51 | 00,527,658 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/10 09:51:44 | 03,475,128 | —- | M] (YouSendIt ) – C:\Documents and Settings\dougm\Desktop\YouSendItExpressSetup2_2_0.exe
[2009/03/10 09:40:33 | 00,025,807 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Willie.wav
[2009/03/08 14:22:46 | 01,241,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/03/08 14:22:46 | 01,241,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/03/08 14:22:30 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/03/08 14:22:18 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/03/08 14:21:06 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/03/08 14:21:06 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/03/08 14:20:54 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/03/08 14:09:26 | 00,391,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/03/08 14:09:26 | 00,391,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/03/08 04:41:16 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/03/08 04:41:16 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/03/08 04:39:48 | 11,063,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/03/08 04:39:48 | 11,063,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/03/08 04:35:10 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/03/08 04:34:58 | 00,914,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/03/08 04:34:58 | 00,914,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/03/08 04:34:56 | 01,206,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/03/08 04:34:56 | 01,206,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/03/08 04:34:52 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/03/08 04:34:52 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/03/08 04:34:48 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/03/08 04:34:48 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/03/08 04:34:48 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/03/08 04:34:30 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/03/08 04:34:30 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/03/08 04:34:28 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/03/08 04:34:28 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/03/08 04:34:18 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/03/08 04:34:18 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/03/08 04:34:18 | 00,109,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/03/08 04:34:18 | 00,109,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/03/08 04:33:48 | 00,759,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/03/08 04:33:40 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/03/08 04:33:40 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/03/08 04:33:26 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/03/08 04:33:26 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/03/08 04:33:16 | 00,726,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/03/08 04:33:16 | 00,726,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/03/08 04:33:08 | 00,229,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/03/08 04:33:08 | 00,229,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/03/08 04:33:06 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/03/08 04:33:06 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/03/08 04:33:02 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/03/08 04:33:02 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/03/08 04:32:56 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/03/08 04:32:56 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/03/08 04:32:54 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/03/08 04:32:54 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/03/08 04:32:52 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/03/08 04:32:52 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/03/08 04:32:52 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/03/08 04:32:50 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/03/08 04:32:50 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/03/08 04:32:50 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/03/08 04:32:50 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/03/08 04:32:48 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/03/08 04:32:48 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/03/08 04:32:46 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/03/08 04:32:46 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/03/08 04:32:26 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/03/08 04:32:26 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/03/08 04:32:22 | 01,985,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/03/08 04:32:22 | 01,985,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/03/08 04:32:04 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/03/08 04:32:04 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/03/08 04:31:56 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/03/08 04:31:56 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/03/08 04:31:54 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/03/08 04:31:52 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/03/08 04:31:52 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/03/08 04:31:52 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/03/08 04:31:52 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/03/08 04:31:44 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/03/08 04:31:44 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/03/08 04:31:38 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/03/08 04:31:38 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/03/08 04:31:38 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/03/08 04:31:38 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/03/08 04:31:36 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/03/08 04:31:36 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/03/08 04:31:26 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/03/08 04:31:26 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/03/08 04:31:18 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/03/08 04:31:18 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/03/08 04:31:02 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/03/08 04:31:02 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/03/08 04:31:02 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/03/08 04:31:02 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/03/08 04:30:56 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/03/08 04:30:56 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/03/08 04:24:28 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/03/08 04:22:46 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/03/08 04:22:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/03/08 04:22:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/03/08 04:15:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/03/08 04:11:12 | 00,445,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/03/08 04:11:12 | 00,445,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/03/07 17:51:42 | 27,660,255 | —- | M] () – C:\Documents and Settings\dougm\Desktop\Google-FriendConnect-Communities.m4v
[2009/03/07 01:12:51 | 00,003,602 | —- | M] () – C:\Documents and Settings\dougm\Desktop\spreadsheets.zip
[2009/03/05 20:39:40 | 00,000,757 | —- | M] () – C:\Documents and Settings\dougm\My Documents\ChatLog Extra Income University 101 2009_03_05 19_39.rtf
[2009/03/05 19:30:04 | 00,000,397 | —- | M] () – C:\Documents and Settings\dougm\My Documents\ChatLog Meet Now 2009_03_05 18_30.rtf
========== LOP Check ==========
[2009/04/02 10:18:50 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/07/10 13:08:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/01 14:33:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2008/06/12 12:17:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/04/01 14:59:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/01/09 18:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2008/04/04 20:07:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bryxen Software
[2007/12/10 18:29:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2007/10/25 21:43:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2009/03/05 15:05:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/02/28 10:51:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/02/17 14:51:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2008/07/08 15:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/11/18 10:35:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/18 12:52:18 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/01/17 18:36:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/02/08 08:53:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/10/23 13:09:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/06/12 16:05:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PAS
[2008/06/06 15:00:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Picture Perfect Software
[2008/07/20 08:23:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/03/07 10:12:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/04/04 11:29:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2008/06/14 16:34:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/01 14:43:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/03/28 17:48:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/01/01 17:16:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/02/27 20:37:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/27 21:12:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/10/23 10:44:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2007/09/01 16:06:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/01 17:20:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/04/04 16:33:15 | 00,000,000 | RH-D | M] – C:\Documents and Settings\dougm\Application Data
[2007/12/25 00:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Adobe
[2008/05/09 14:43:01 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\AdobeUM
[2008/02/25 18:24:46 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Apple Computer
[2007/10/22 10:28:06 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\ATI
[2008/01/09 18:46:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\AVS4YOU
[2007/11/20 16:03:52 | 00,000,000 | R–D | M] – C:\Documents and Settings\dougm\Application Data\Brother
[2009/04/03 14:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\CoreFTP
[2008/05/21 15:36:26 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2009/02/22 18:58:21 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Desktop Spider
[2008/02/28 10:57:06 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Download Manager
[2007/11/14 13:12:40 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\eBookPro6
[2008/03/05 17:50:37 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Eltima Software
[2007/11/27 15:04:02 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\FileMaker
[2008/06/04 09:28:23 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Flock
[2008/09/04 08:07:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Gael
[2009/03/17 13:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\GlobalSCAPE
[2007/12/26 17:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Good Keywords v2
[2009/03/12 14:54:02 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\GoodSync
[2009/03/15 14:56:25 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Google
[2008/02/28 10:05:47 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Grisoft
[2008/07/30 13:50:38 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\HBA
[2008/07/01 18:55:24 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Help
[2007/10/23 05:30:59 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Identities
[2009/02/07 23:40:49 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\KompoZer
[2008/05/01 13:40:43 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\LumaPix
[2007/10/23 09:54:58 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Macromedia
[2008/11/18 10:35:11 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Malwarebytes
[2008/08/02 15:57:39 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2008/01/21 08:57:19 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Media Player Classic
[2009/02/18 12:52:18 | 00,000,000 | –SD | M] – C:\Documents and Settings\dougm\Application Data\Microsoft
[2008/09/05 23:47:43 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Mozilla
[2009/02/08 08:53:04 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\NCH Swift Sound
[2007/10/23 13:15:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\OfficeUpdate12
[2009/03/29 21:11:54 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\PADGen
[2008/06/12 16:08:01 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Palo Alto Software
[2008/09/05 23:47:39 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Scribd
[2008/09/05 23:47:39 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Scribd.com
[2009/04/04 11:30:55 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Skype
[2009/04/04 09:47:49 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\skypePM
[2009/01/27 19:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Smith Micro
[2009/02/22 18:59:45 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Spider
[2007/12/25 00:04:02 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\StomperScrutinizer.80D30D081DF260F3E4CECC0C2A6ADDA2F74D545F.1
[2007/10/31 11:02:36 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\Sun
[2009/04/01 14:42:47 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\SUPERAntiSpyware.com
[2008/12/09 12:26:12 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/03/02 19:21:29 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\U3
[2008/07/31 15:49:27 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\WinRAR
[2009/02/27 20:35:14 | 00,000,000 | —D | M] – C:\Documents and Settings\dougm\Application Data\XnView
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/04 18:31:49 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\DesktopMentorDaily.job
[2009/04/04 18:47:02 | 00,000,346 | —- | M] () – C:\WINDOWS\Tasks\DesktopMentorDynamic.job
[2009/04/04 16:42:42 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2008/02/28 12:42:09 | 00,000,300 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job
[2009/04/04 13:33:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44807EFA
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >