I thought I'd already uninstalled Norton but I think that now it's cleaned from my computer. AVG is what I'll be keeping for AV protection.
Here are the scan results from the OTListIt:
OTListIt logfile created on: 5/10/2009 3:34:47 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\Sally\My Documents\Downloads
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
990.54 Mb Total Physical Memory | 205.98 Mb Available Physical Memory | 20.79% Memory free
2.33 Gb Paging File | 1.66 Gb Available in Paging File | 71.33% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 61.96 Gb Total Space | 6.41 Gb Free Space | 10.34% Space Free | Partition Type: NTFS
Drive D: | 11.53 Gb Total Space | 1.09 Gb Free Space | 9.46% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-0CDC4F5844
Current User Name: Sally
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 90 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe ()
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\system32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Sally\My Documents\Downloads\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (AddFiltr [On_Demand | Stopped]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AOL TopSpeedMonitor [Auto | Running]) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MaxBackServiceInt [Auto | Running]) – C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe ()
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (MSCamSvc [Auto | Running]) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (MSMQ [Auto | Running]) – C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
SRV - (MSMQTriggers [Auto | Running]) – C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
SRV - (Net Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NTService1 [Auto | Stopped]) – C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe ( )
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (RampartSvc [On_Demand | Stopped]) – C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe (SonicWALL, Inc.)
SRV - (UMWdf [On_Demand | Stopped]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMConnectCDS [On_Demand | Stopped]) – C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (5U870CAP_VID_1262&PID_25FD [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\5U870CAP.sys (Ricoh)
DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BTWUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (eabfiltr [System | Running]) – C:\WINDOWS\system32\DRIVERS\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabusb [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\eabusb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HBtnKey [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\cpqbttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HdAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (iaStor [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MQAC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MSHUSBVideo [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\nx6000.sys (Microsoft Corporation)
DRV - (MXOPSWD [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\mxopswd.sys (Maxtor Corp.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvsmu [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvsmu.sys (NVIDIA Corporation)
DRV - (NWADI [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBModem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nwusbser.sys (Novatel Wireless Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RCFOX [System | Running]) – C:\WINDOWS\system32\Drivers\RCFOX.sys (SonicWALL, Inc.)
DRV - (rcvpn [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rcvpn.sys (SonicWALL, Inc.)
DRV - (rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (RMCAST [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RMCast.sys (Microsoft Corporation)
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ser2plms [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ser2plms.sys (Prolific Technology Inc.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SMNDIS5 [On_Demand | Stopped]) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USB_RNDIS [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (usb_rndisx [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (wceusbsh [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\wceusbsh.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Mininova Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.conduit.com/ResultsExt.aspx?ctid=CT1396957&SearchSource=3&q="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:0.4.0.9
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: [removed]:2.6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06
FF - prefs.js..extensions.enabledItems: {f592709f-ff4a-4862-b659-4afabda56312}:[removed]
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.28
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "
http://search.conduit.com/ResultsExt.aspx?ctid=CT1396957&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008/05/12 23:53:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2008/10/20 22:29:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/08 04:58:06 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/08 04:58:06 | 00,000,000 | —D | M]
[2008/11/26 01:05:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Extensions
[2008/11/26 01:05:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/09 19:47:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions
[2008/12/30 00:10:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2008/11/30 05:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2008/12/17 00:53:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions\{f592709f-ff4a-4862-b659-4afabda56312}
[2009/01/13 16:42:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions\[removed]
[2009/02/23 20:23:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions\[removed]
[2008/11/22 03:27:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\mozilla\Firefox\Profiles\nr010yrq.default\extensions\[removed]
[2008/11/30 12:12:28 | 00,000,878 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\conduit.xml
[2008/07/28 23:09:55 | 00,002,610 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\cuil.xml
[2009/05/03 21:24:08 | 00,005,500 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\food-network-recipes.xml
[2009/02/04 13:58:28 | 00,006,335 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\goodsearch–support-your-favorite-charity-or-school.xml
[2009/01/13 16:45:29 | 00,002,466 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\google-image-search.xml
[2009/05/03 21:24:08 | 00,002,345 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\google-video-youtube.xml
[2009/01/13 16:43:36 | 00,003,617 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\home—fetlife.xml
[2008/06/19 02:01:26 | 00,000,908 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\imdb.xml
[2009/05/03 21:24:08 | 00,001,973 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\mycroft-project.xml
[2008/06/07 03:46:06 | 00,001,961 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\technorati.xml
[2009/05/03 21:24:08 | 00,001,835 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\weathercom.xml
[2008/06/21 13:20:00 | 00,001,108 | —- | M] () – C:\Documents and Settings\Sally\Application Data\Mozilla\FireFox\Profiles\nr010yrq.default\searchplugins\wikipedia-en.xml
[2009/05/10 08:27:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/05/08 04:58:06 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/06/15 11:37:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
[2009/05/08 04:57:41 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/05/08 04:57:42 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/05/08 04:57:58 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/05/08 04:57:58 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/05/08 04:57:58 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/05/08 04:57:58 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/05/08 04:57:58 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/05/08 04:57:58 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/05/08 04:57:58 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (696740 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtcc1.acecounter.com
O1 - Hosts: 127.0.0.1 gtp1.acecounter.com #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 acestats.com
O1 - Hosts: 127.0.0.1 www.acestats.com
O1 - Hosts: 18522 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (CPrintEnhancer Object) - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe ()
O4 - HKLM..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB004" /M "Stylus CX4600" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EPSON Stylus CX4600 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P35 "EPSON Stylus CX4600 Series (Copy 1)" /O6 "USB004" /M "Stylus CX4600" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
O4 - HKLM..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet /nodetect ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled [2007/12/12 10:04:43 | 00,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Sally\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O15 - HKLM\..Trusted Domains: 41 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {26522409-8BBF-4C5B-A4D3-CF4B1D6F255B}
http://www.umediaserver.net/bin/UMediaControl5.cab (UMediaPlayer Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1168797560279 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 14:01:14 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{09f82558-902b-11db-9568-000fb35c13dd}\Shell - "" = AutoRun
O33 - MountPoints2\{09f82558-902b-11db-9568-000fb35c13dd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{30c9d086-4f7c-11dc-9611-001636875815}\Shell\AutoRun\command - "" = F:\setup.exe – File not found
O33 - MountPoints2\{8edc4ea0-b51a-11dd-9769-001636875815}\Shell\AutoRun\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{dbc187d6-7061-11db-954a-001636875815}\Shell - "" = AutoRun
O33 - MountPoints2\{dbc187d6-7061-11db-954a-001636875815}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dbc187d6-7061-11db-954a-001636875815}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\url.DLL – [2009/02/20 12:09:38 | 00,105,984 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{fa6e9b8e-a7dc-11dc-96df-001636875815}\Shell\Auto\command - "" = F:\Start.exe – File not found
O33 - MountPoints2\{fa6e9b8e-a7dc-11dc-96df-001636875815}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 90 Days ==========
[2009/05/10 10:11:08 | 00,091,320 | —- | C] () – C:\Documents and Settings\Sally\Desktop\adarchives.asp.htm
[2009/05/08 17:36:28 | 00,186,880 | -HS- | C] () – C:\Documents and Settings\Sally\Desktop\Thumbs.db
[2009/05/08 04:28:50 | 02,200,304 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Pocket Guide (2002)(1).pdf
[2009/05/08 04:28:40 | 12,350,144 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography - The Missing Manual (2006).chm
[2009/05/08 04:28:38 | 00,605,800 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography - Expert Techniques, 2nd Edition (2006).chm
[2009/05/08 04:28:10 | 37,703,743 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Art Photography For Dummies (2006).pdf
[2009/05/08 04:17:28 | 17,383,092 | —- | C] () – C:\Documents and Settings\Sally\My Documents\How To Do Everything With Your Digital Camera, 2nd Edition (2002).pdf
[2009/05/08 04:17:25 | 02,200,304 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Pocket Guide (2002).pdf
[2009/05/08 04:15:56 | 12,289,9547 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Just The Steps For Dummies (2005).pdf
[2009/05/08 04:15:40 | 12,331,185 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Hacks - 100 Industrial-Strength Tips & Tools (2004).chm
[2009/05/08 03:00:15 | 25,766,034 | —- | C] () – C:\Documents and Settings\Sally\My Documents\Digital Photography All-In-One Desk Reference For Dummies, 2nd Edition (2005).pdf
[2009/05/07 14:00:41 | 00,009,986 | —- | C] () – C:\Documents and Settings\Sally\Desktop\PACO002733203121120081IDC[1].pdf
[2009/05/06 23:29:31 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Sally\Desktop\HJTInstall.exe
[2009/05/06 22:27:54 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/05/06 22:27:54 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/19 23:01:18 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/19 23:01:18 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/19 23:01:17 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/19 23:01:17 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/19 23:01:17 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/19 23:01:17 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/19 23:01:16 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/19 23:01:14 | 00,617,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/19 23:01:13 | 00,715,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/19 22:39:20 | 01,193,414 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/19 22:39:19 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/15 08:38:05 | 00,001,840 | —- | C] () – C:\Documents and Settings\Sally\Desktop\ExtFiling.html
[2009/04/06 03:28:18 | 00,000,268 | -H– | C] () – C:\sqmdata00.sqm
[2009/04/06 03:28:18 | 00,000,244 | -H– | C] () – C:\sqmnoopt00.sqm
[2009/04/03 16:26:52 | 00,082,664 | —- | C] () – C:\Documents and Settings\Sally\Desktop\L3April09.jpg
[2009/03/30 16:39:53 | 00,035,092 | —- | C] () – C:\Documents and Settings\Sally\Desktop\lolcats3.htm
[2009/03/30 16:38:44 | 00,041,458 | —- | C] () – C:\Documents and Settings\Sally\Desktop\lolcats2.html
[2009/03/30 16:38:06 | 00,062,089 | —- | C] () – C:\Documents and Settings\Sally\Desktop\lolcats.html
[2009/03/30 12:21:59 | 00,126,657 | —- | C] () – C:\Documents and Settings\Sally\Desktop\Card.jpg
[2009/03/30 12:21:54 | 00,292,897 | —- | C] () – C:\Documents and Settings\Sally\Desktop\Card Inside.jpg
[2009/03/30 12:21:50 | 00,129,803 | —- | C] () – C:\Documents and Settings\Sally\Desktop\Card1.jpg
[2009/03/27 20:30:48 | 00,000,000 | —D | C] – C:\Documents and Settings\Sally\Application Data\Move Networks
[2009/03/22 00:49:31 | 00,083,456 | —- | C] () – C:\Documents and Settings\Sally\My Documents\L3 April 17 09.xls
[2009/03/11 20:02:23 | 00,085,504 | —- | C] () – C:\Documents and Settings\Sally\My Documents\L3 Mar 20 09 (version 1).xls
[2009/02/28 15:36:58 | 00,104,982 | —- | C] () – C:\Documents and Settings\Sally\Desktop\making_relationships_suck.pdf
[2009/02/28 12:11:58 | 00,100,634 | —- | C] () – C:\Documents and Settings\Sally\My Documents\n695802179_1415769_6028243.jpg
[2009/02/26 15:14:38 | 00,083,456 | —- | C] () – C:\Documents and Settings\Sally\My Documents\L3 Mar 20 09.xls
[2009/02/18 12:12:41 | 00,004,636 | —- | C] () – C:\Documents and Settings\Sally\My Documents\evilponderings.mht
[2009/02/10 18:31:54 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/02/09 17:15:44 | 00,105,157 | —- | C] () – C:\Documents and Settings\Sally\My Documents\dear-miriam.jpg
[2008/12/11 04:14:37 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/10/13 15:26:15 | 00,000,138 | —- | C] () – C:\WINDOWS\ImageRescue3.INI
[2008/04/16 16:19:06 | 00,000,021 | —- | C] () – C:\WINDOWS\PI_setup.ini
[2008/04/16 16:18:43 | 00,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/04/16 16:15:23 | 00,096,768 | —- | C] () – C:\WINDOWS\SlantAdj.dll
[2008/04/16 16:15:23 | 00,000,072 | —- | C] () – C:\WINDOWS\System32\epDPE.ini
[2008/04/16 16:06:30 | 00,000,044 | —- | C] () – C:\WINDOWS\EPCX4600.ini
[2008/02/18 16:55:34 | 00,782,336 | —- | C] () – C:\WINDOWS\System32\IlmImf.dll
[2008/02/18 16:55:34 | 00,446,464 | —- | C] () – C:\WINDOWS\System32\Photomatix_jpg.dll
[2008/02/18 16:55:34 | 00,353,280 | —- | C] () – C:\WINDOWS\System32\pmtf2.dll
[2008/02/18 16:55:34 | 00,205,824 | —- | C] () – C:\WINDOWS\System32\pmtf1.dll
[2008/02/18 16:55:34 | 00,204,288 | —- | C] () – C:\WINDOWS\System32\pmtf3.dll
[2008/02/18 16:55:34 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\Photomatix25Lib3.dll
[2008/02/18 16:55:34 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\pmexr.dll
[2008/02/18 16:55:34 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\pmbm.dll
[2008/02/18 16:55:33 | 00,266,240 | —- | C] () – C:\WINDOWS\System32\Photomatix25Lib.dll
[2008/02/18 16:55:33 | 00,249,856 | —- | C] () – C:\WINDOWS\System32\Photomatix25Lib2.dll
[2007/06/01 14:32:59 | 00,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2007/06/01 13:06:41 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2007/03/11 00:08:07 | 02,729,472 | —- | C] () – C:\WINDOWS\System32\fun_avcodec.dll
[2006/11/13 17:44:44 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/11/13 17:44:44 | 01,138,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/11/13 17:44:44 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/11/13 17:44:42 | 00,005,120 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2006/11/13 17:44:42 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2006/11/13 17:36:36 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/10/27 17:22:23 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/10/24 21:46:59 | 00,000,054 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2006/10/23 23:01:13 | 00,004,846 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/09/01 03:07:45 | 00,000,174 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/09/01 03:03:50 | 00,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/09/01 02:50:41 | 00,000,488 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/01 02:40:18 | 00,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/18 02:00:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/18 02:00:00 | 01,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/08/18 02:00:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/18 02:00:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/08/18 02:00:00 | 00,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/06/29 13:18:14 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/29 12:46:56 | 00,000,086 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/06/29 12:43:40 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/06/29 12:13:22 | 00,000,752 | —- | C] () – C:\WINDOWS\win.ini
[2006/06/29 05:00:42 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2006/03/04 01:07:34 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/12/02 12:09:10 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/05 20:06:32 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2005/04/27 12:38:00 | 00,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
========== Files - Modified Within 90 Days ==========
[6 C:\Documents and Settings\Sally\My Documents\*.tmp files]
[2009/05/10 15:12:40 | 00,420,520 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/10 15:12:40 | 00,067,732 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/10 15:12:39 | 00,495,740 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/10 15:07:14 | 00,051,048 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/10 15:05:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/10 15:04:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/10 13:11:43 | 00,052,970 | —- | M] () – C:\VETlog.dmp
[2009/05/10 13:11:23 | 00,000,752 | —- | M] () – C:\WINDOWS\win.ini
[2009/05/10 10:11:23 | 00,091,320 | —- | M] () – C:\Documents and Settings\Sally\Desktop\adarchives.asp.htm
[2009/05/08 17:37:07 | 00,186,880 | -HS- | M] () – C:\Documents and Settings\Sally\Desktop\Thumbs.db
[2009/05/08 10:23:12 | 00,434,673 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/08 10:23:12 | 00,051,123 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/08 10:23:11 | 35,920,469 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/08 04:28:51 | 02,200,304 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Pocket Guide (2002)(1).pdf
[2009/05/08 04:28:49 | 12,350,144 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography - The Missing Manual (2006).chm
[2009/05/08 04:28:39 | 00,605,800 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography - Expert Techniques, 2nd Edition (2006).chm
[2009/05/08 04:28:38 | 37,703,743 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Art Photography For Dummies (2006).pdf
[2009/05/08 04:17:38 | 17,383,092 | —- | M] () – C:\Documents and Settings\Sally\My Documents\How To Do Everything With Your Digital Camera, 2nd Edition (2002).pdf
[2009/05/08 04:17:27 | 02,200,304 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Pocket Guide (2002).pdf
[2009/05/08 04:17:24 | 12,289,9547 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Just The Steps For Dummies (2005).pdf
[2009/05/08 04:15:54 | 12,331,185 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography Hacks - 100 Industrial-Strength Tips & Tools (2004).chm
[2009/05/08 04:15:38 | 25,766,034 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Digital Photography All-In-One Desk Reference For Dummies, 2nd Edition (2005).pdf
[2009/05/07 14:00:41 | 00,009,986 | —- | M] () – C:\Documents and Settings\Sally\Desktop\PACO002733203121120081IDC[1].pdf
[2009/05/06 23:29:35 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Sally\Desktop\HJTInstall.exe
[2009/05/06 23:29:15 | 00,000,812 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2009/05/06 22:27:54 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/05/06 22:27:54 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/05/06 22:23:01 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/28 09:08:35 | 00,000,488 | —- | M] () – C:\WINDOWS\ODBC.INI
[2009/04/20 03:17:15 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/15 08:38:07 | 00,001,840 | —- | M] () – C:\Documents and Settings\Sally\Desktop\ExtFiling.html
[2009/04/06 08:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/06 03:28:18 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/04/06 03:28:18 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/04/03 16:26:57 | 00,082,664 | —- | M] () – C:\Documents and Settings\Sally\Desktop\L3April09.jpg
[2009/03/30 16:39:54 | 00,035,092 | —- | M] () – C:\Documents and Settings\Sally\Desktop\lolcats3.htm
[2009/03/30 16:38:45 | 00,041,458 | —- | M] () – C:\Documents and Settings\Sally\Desktop\lolcats2.html
[2009/03/30 16:38:07 | 00,062,089 | —- | M] () – C:\Documents and Settings\Sally\Desktop\lolcats.html
[2009/03/27 01:09:32 | 01,193,414 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/22 01:49:16 | 00,083,456 | —- | M] () – C:\Documents and Settings\Sally\My Documents\L3 April 17 09.xls
[2009/03/21 08:18:57 | 00,986,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\kernel32.dll
[2009/03/21 08:18:57 | 00,986,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kernel32.dll
[2009/03/20 13:43:33 | 00,085,504 | —- | M] () – C:\Documents and Settings\Sally\My Documents\L3 Mar 20 09 (version 1).xls
[2009/03/11 03:13:38 | 00,382,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 00:11:24 | 00,083,456 | —- | M] () – C:\Documents and Settings\Sally\My Documents\L3 Mar 20 09.xls
[2009/03/09 13:56:57 | 00,081,408 | —- | M] () – C:\Documents and Settings\Sally\My Documents\L3 Feb 20 09.xls
[2009/03/06 08:00:22 | 00,284,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pdh.dll
[2009/03/06 08:00:22 | 00,284,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/03/03 03:17:28 | 01,564,672 | -HS- | M] () – C:\Documents and Settings\Sally\My Documents\Thumbs.db
[2009/03/02 18:18:25 | 00,826,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/03/02 18:18:25 | 00,826,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/02/28 15:36:58 | 00,104,982 | —- | M] () – C:\Documents and Settings\Sally\Desktop\making_relationships_suck.pdf
[2009/02/28 12:11:59 | 00,100,634 | —- | M] () – C:\Documents and Settings\Sally\My Documents\n695802179_1415769_6028243.jpg
[2009/02/27 22:54:41 | 00,636,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/02/20 12:09:38 | 01,160,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/02/20 12:09:38 | 01,160,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/02/20 12:09:38 | 00,671,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/02/20 12:09:38 | 00,671,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/02/20 12:09:38 | 00,477,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/02/20 12:09:38 | 00,477,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/02/20 12:09:38 | 00,233,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/02/20 12:09:38 | 00,233,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/02/20 12:09:38 | 00,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/02/20 12:09:38 | 00,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/02/20 12:09:38 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/02/20 12:09:38 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/02/20 12:09:38 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/02/20 12:09:38 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/02/20 12:09:38 | 00,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2009/02/20 12:09:38 | 00,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieencode.dll
[2009/02/20 12:09:38 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/02/20 12:09:38 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/02/20 12:09:37 | 03,595,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/02/20 12:09:37 | 03,595,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/02/20 12:09:37 | 01,830,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/02/20 12:09:37 | 01,830,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/02/20 12:09:37 | 00,459,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/02/20 12:09:37 | 00,459,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/02/20 12:09:37 | 00,268,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/02/20 12:09:37 | 00,268,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/02/20 12:09:37 | 00,052,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/02/20 12:09:37 | 00,052,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/02/20 12:09:37 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/02/20 12:09:37 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/02/20 12:09:37 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/02/20 12:09:37 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/02/20 12:09:36 | 06,066,176 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/02/20 12:09:36 | 06,066,176 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/02/20 12:09:36 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/02/20 12:09:36 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/02/20 12:09:36 | 00,383,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/02/20 12:09:36 | 00,383,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/02/20 12:09:36 | 00,230,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/02/20 12:09:36 | 00,230,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/02/20 12:09:36 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/02/20 12:09:36 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/02/20 12:09:36 | 00,153,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/02/20 12:09:36 | 00,153,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/02/20 12:09:36 | 00,133,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\extmgr.dll
[2009/02/20 12:09:36 | 00,133,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\extmgr.dll
[2009/02/20 12:09:36 | 00,063,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/02/20 12:09:36 | 00,063,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/02/20 12:09:35 | 00,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/02/20 12:09:35 | 00,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/02/20 12:09:35 | 00,124,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/02/20 12:09:35 | 00,124,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/02/20 04:21:18 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/02/20 04:20:49 | 00,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/02/20 04:20:49 | 00,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/02/20 04:20:49 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/02/20 04:20:49 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/02/19 23:14:12 | 00,161,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/02/19 23:14:12 | 00,161,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/02/18 12:12:41 | 00,004,636 | —- | M] () – C:\Documents and Settings\Sally\My Documents\evilponderings.mht
[2009/02/11 12:53:09 | 00,044,544 | —- | M] () – C:\Documents and Settings\Sally\My Documents\Sally Wright Resume Feb2009.doc
[2009/02/10 18:31:54 | 00,453,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/02/09 17:15:45 | 00,105,157 | —- | M] () – C:\Documents and Settings\Sally\My Documents\dear-miriam.jpg
========== LOP Check ==========
[2009/05/10 14:29:36 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/02/11 13:08:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/11/14 15:01:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2006/12/12 20:00:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/20 22:29:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2006/09/01 02:52:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/04/02 01:44:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/09/09 14:44:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2006/11/29 16:19:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/09/09 09:14:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2006/09/01 01:16:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2008/04/15 14:25:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/06/06 00:53:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2006/12/06 16:59:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Maxtor
[2008/11/29 22:04:27 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/05/04 01:16:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2006/12/07 22:42:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2006/09/01 02:22:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2007/04/02 04:40:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2006/10/23 17:50:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/09/01 01:16:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2006/09/01 01:16:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2008/06/06 00:57:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/06/18 15:47:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/12/10 04:11:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2007/02/15 15:23:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/09/09 14:46:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/01/14 13:00:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/11/29 19:54:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/05/10 14:29:36 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Sally\Application Data
[2008/01/22 08:36:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Adobe
[2007/01/17 17:40:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\AdobeUM
[2007/01/27 10:21:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\AOL
[2006/12/12 19:45:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Apple Computer
[2006/10/26 22:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\CyberLink
[2008/12/05 19:11:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Flickr
[2007/01/01 17:13:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Google
[2007/03/18 07:04:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\GTek
[2006/12/15 01:33:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Help
[2007/09/18 07:37:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\HP
[2006/09/01 01:16:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Identities
[2007/09/30 15:52:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Image Zone Express
[2008/04/15 14:36:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Intuit
[2006/11/15 00:30:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Leadertech
[2006/09/01 02:50:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Macromedia
[2006/11/13 17:07:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Media Player Classic
[2009/02/23 15:19:27 | 00,000,000 | –SD | M] – C:\Documents and Settings\Sally\Application Data\Microsoft
[2009/03/28 20:31:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Move Networks
[2008/11/26 01:05:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Mozilla
[2008/06/06 00:11:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\MSNInstaller
[2006/12/07 22:45:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\muvee Technologies
[2007/09/12 09:46:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Printer Info Cache
[2007/03/10 09:32:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Real
[2006/10/24 13:53:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Shareaza
[2007/10/16 18:45:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Smith Micro
[2006/11/15 00:41:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Sonic
[2007/02/14 16:24:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\SonicWALL
[2006/11/04 10:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Sun
[2009/01/18 19:54:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\U3
[2007/08/09 00:11:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Unreal Streaming
[2009/03/04 21:11:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\uTorrent
[2007/02/15 15:23:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\Viewpoint
[2007/12/27 11:43:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\vlc
[2008/11/29 19:56:07 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Sally\Application Data\yahoo!
[2006/10/23 17:50:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Sally\Application Data\You've Got Pictures Screensaver
[2006/03/15 22:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/10 15:05:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >