It appears that it would be easier to read this way:
OTS logfile created on: 11/25/2009 8:13:50 PM - Run 1
OTS by OldTimer - Version 3.1.7.0 Folder = C:\Documents and Settings\Desiree Meenan\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.48 Mb Total Physical Memory | 264.13 Mb Available Physical Memory | 59.02% Memory free
1.03 Gb Paging File | 0.78 Gb Available in Paging File | 75.58% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 101.29 Gb Free Space | 90.61% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PATTYM
Current User Name: Desiree Meenan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\OTS.exe -> [2009/11/25 20:13:01 | 00,526,848 | —- | M] (OldTimer Tools)
ashdisp.exe -> C:\Program Files\Alwil Software\Avast4\ashDisp.exe -> [2009/09/15 03:56:48 | 00,081,000 | —- | M] (ALWIL Software)
ashserv.exe -> C:\Program Files\Alwil Software\Avast4\ashServ.exe -> [2009/09/15 03:56:43 | 00,138,680 | —- | M] (ALWIL Software)
ashmaisv.exe -> C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -> [2009/09/15 03:56:28 | 00,254,040 | —- | M] (ALWIL Software)
ashwebsv.exe -> C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -> [2009/09/15 03:54:13 | 00,352,920 | —- | M] (ALWIL Software)
aswupdsv.exe -> C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -> [2009/09/15 03:49:40 | 00,018,752 | —- | M] (ALWIL Software)
wmiprvse.exe -> C:\WINDOWS\system32\wbem\wmiprvse.exe -> [2009/02/06 02:10:02 | 00,227,840 | —- | M] (Microsoft Corporation)
explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 16:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
lic98rmt.exe -> C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe -> [2005/07/11 10:16:00 | 00,126,976 | —- | M] (Computer Associates International Inc.)
logwatnt.exe -> C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe -> [2005/07/11 10:16:00 | 00,053,248 | —- | M] (Computer Associates)
airplus.exe -> C:\Program Files\D-Link AirPlus G\AIRPLUS.exe -> [2004/01/06 20:19:38 | 00,294,912 | —- | M] (D-Link)
qttask.exe -> C:\Program Files\QuickTime\qttask.exe -> [2003/11/20 03:29:37 | 00,077,824 | —- | M] (Apple Computer, Inc.)
acsd.exe -> C:\Program Files\Common Files\AOL\ACS\acsd.exe -> [2003/08/06 16:58:26 | 01,376,360 | —- | M] (America Online, Inc.)
zhotkey.exe -> C:\WINDOWS\zHotkey.exe -> [2003/06/03 11:01:32 | 00,496,640 | —- | M] (Chicony)
slserv.exe -> C:\WINDOWS\system32\slserv.exe -> [2003/01/17 01:02:00 | 00,045,056 | —- | M] ( )
wanmpsvc.exe -> C:\WINDOWS\wanmpsvc.exe -> [2003/01/10 17:13:04 | 00,065,536 | —- | M] (America Online, Inc.)
gwremind.exe -> C:\Program Files\Greetings Workshop\GWREMIND.EXE -> [1997/09/03 23:00:00 | 00,050,688 | —- | M] (Microsoft Corporation)
[Modules - Safe List]
ots.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\OTS.exe -> [2009/11/25 20:13:01 | 00,526,848 | —- | M] (OldTimer Tools)
comctl32.dll -> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll -> [2008/04/13 16:12:51 | 01,054,208 | —- | M] (Microsoft Corporation)
framedyn.dll -> C:\WINDOWS\system32\wbem\framedyn.dll -> [2008/04/13 16:11:53 | 00,185,344 | —- | M] (Microsoft Corporation)
serwvdrv.dll -> C:\WINDOWS\system32\serwvdrv.dll -> [2003/03/31 04:00:00 | 00,014,848 | —- | M] (Microsoft Corporation)
umdmxfrm.dll -> C:\WINDOWS\system32\umdmxfrm.dll -> [2003/03/31 04:00:00 | 00,013,312 | —- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(avast! Antivirus) avast! Antivirus [Auto | Running] -> C:\Program Files\Alwil Software\Avast4\ashServ.exe -> [2009/09/15 03:56:43 | 00,138,680 | —- | M] (ALWIL Software)
(avast! Mail Scanner) avast! Mail Scanner [On_Demand | Running] -> C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -> [2009/09/15 03:56:28 | 00,254,040 | —- | M] (ALWIL Software)
(avast! Web Scanner) avast! Web Scanner [On_Demand | Running] -> C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -> [2009/09/15 03:54:13 | 00,352,920 | —- | M] (ALWIL Software)
(aswUpdSv) avast! iAVS4 Control Service [Auto | Running] -> C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -> [2009/09/15 03:49:40 | 00,018,752 | —- | M] (ALWIL Software)
(helpsvc) Help and Support [Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 16:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [On_Demand | Stopped] -> C:\Program Files\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
(CA_LIC_CLNT) CA License Client [Auto | Running] -> C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe -> [2005/07/11 10:16:00 | 00,126,976 | —- | M] (Computer Associates International Inc.)
(LogWatch) Event Log Watch [Auto | Running] -> C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe -> [2005/07/11 10:16:00 | 00,053,248 | —- | M] (Computer Associates)
(Pml Driver HPZ12) Pml Driver HPZ12 [On_Demand | Stopped] -> C:\WINDOWS\system32\HPZipm12.exe -> [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP)
(aspnet_state) ASP.NET State Service [On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -> [2004/07/15 00:49:26 | 00,032,768 | —- | M] (Microsoft Corporation)
(awhost32) pcAnywhere Host Service [On_Demand | Stopped] -> C:\Program Files\Symantec\pcAnywhere\awhost32.exe -> [2003/10/31 11:01:00 | 00,106,496 | —- | M] (Symantec Corporation)
(AOL ACS) AOL Connectivity Service [Auto | Running] -> C:\Program Files\Common Files\AOL\ACS\acsd.exe -> [2003/08/06 16:58:26 | 01,376,360 | —- | M] (America Online, Inc.)
(SLService) SmartLinkService [Auto | Running] -> C:\WINDOWS\System32\slserv.exe -> [2003/01/17 01:02:00 | 00,045,056 | —- | M] ( )
(WANMiniportService) WAN Miniport (ATW) Service [Auto | Running] -> C:\WINDOWS\wanmpsvc.exe -> [2003/01/10 17:13:04 | 00,065,536 | —- | M] (America Online, Inc.)
[Driver Services - Safe List]
(aswMon2) avast! Standard Shield Support [File_System | Auto | Running] -> C:\WINDOWS\system32\drivers\aswmon2.sys -> [2009/09/15 03:56:14 | 00,094,160 | —- | M] (ALWIL Software)
(aswSP) avast! Self Protection [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\aswSP.sys -> [2009/09/15 03:55:30 | 00,114,768 | —- | M] (ALWIL Software)
(aswFsBlk) aswFsBlk [File_System | Auto | Running] -> C:\WINDOWS\system32\drivers\aswFsBlk.sys -> [2009/09/15 03:55:19 | 00,020,560 | —- | M] (ALWIL Software)
(aswTdi) avast! Network Shield Support [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\aswTdi.sys -> [2009/09/15 03:54:30 | 00,052,368 | —- | M] (ALWIL Software)
(aswRdr) aswRdr [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\aswRdr.sys -> [2009/09/15 03:54:21 | 00,023,152 | —- | M] (ALWIL Software)
(Aavmker4) avast! Asynchronous Virus Monitor [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\aavmker4.sys -> [2009/09/15 03:53:24 | 00,027,408 | —- | M] (ALWIL Software)
(mf) mf [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\mf.sys -> [2008/04/13 10:36:41 | 00,063,744 | —- | M] (Microsoft Corporation)
(MCSTRM) MCSTRM [Kernel | Auto | Running] -> C:\WINDOWS\system32\drivers\mcstrm.sys -> [2007/11/28 20:35:26 | 00,008,413 | —- | M] (RealNetworks, Inc.)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\secdrv.sys -> [2007/11/13 02:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SymEvent) SymEvent [Kernel | On_Demand | Stopped] -> C:\Program Files\Symantec\SYMEVENT.SYS -> [2005/05/13 18:50:10 | 00,123,488 | —- | M] (Symantec Corporation)
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\HPZius12.sys -> [2004/10/04 15:26:08 | 00,021,744 | R— | M] (HP)
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\HPZipr12.sys -> [2004/10/04 15:26:04 | 00,016,496 | R— | M] (HP)
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\HPZid412.sys -> [2004/10/04 15:26:03 | 00,051,120 | R— | M] (HP)
(RecAgent) RecAgent [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\recagent.sys -> [2004/08/03 22:41:40 | 00,013,776 | —- | M] (Smart Link)
(W8100PCI) D-Link AirPlus G Wireless Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\MRV8K51.sys -> [2004/01/08 19:46:18 | 00,297,984 | R— | M] (Marvell Semiconductor, Inc)
(AW_HOST) AW_HOST [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\AW_HOST5.sys -> [2003/10/24 09:53:08 | 00,016,984 | —- | M] (Symantec Corporation)
(viagfx) viagfx [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\vtmini.sys -> [2003/10/16 15:19:40 | 00,117,760 | —- | M] (Copyright (C) VIA/S3 Graphics, Inc.)
(FETNDISB) VIA Rhine Family Fast Ethernet Adapter Driver Service [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\fetnd5b.sys -> [2003/09/04 10:37:04 | 00,041,984 | —- | M] (VIA Technologies, Inc. )
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ALCXWDM.SYS -> [2003/08/21 16:31:52 | 00,462,940 | —- | M] (Realtek Semiconductor Corp.)
(ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ALCXSENS.SYS -> [2003/08/14 23:16:38 | 00,404,736 | —- | M] (Sensaura Ltd)
(m4301a) Linksys Wireless-B USB Network Adapter v4.0 Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\m4301A.sys -> [2003/08/04 23:07:00 | 00,083,552 | R— | M] (ALinx Corporation)
(viaagp1) VIA AGP Filter [Kernel | Boot | Running] -> C:\WINDOWS\System32\DRIVERS\viaagp1.sys -> [2003/07/02 04:42:00 | 00,027,904 | —- | M] (VIA Technologies, Inc.)
(FVNETusb) Linksys Wireless-B USB Network Adapter v2.8 Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\vnet558x.sys -> [2003/06/12 01:56:44 | 00,098,304 | R— | M] (ATMEL)
(Gernuwa) Gernuwa [Kernel | Boot | Running] -> C:\WINDOWS\system32\drivers\GERNUWA.sys -> [2003/04/21 13:00:32 | 00,013,898 | R— | M] (Symantec Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ptilink.sys -> [2003/03/31 04:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ROOTMODEM) Microsoft Legacy Modem Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\rootmdm.sys -> [2003/03/31 04:00:00 | 00,005,888 | —- | M] (Microsoft Corporation)
(BrSerWDM) Brother WDM Serial driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BrSerWdm.sys -> [2003/03/13 16:04:20 | 00,061,952 | —- | M] (Brother Industries Ltd.)
(Mtlstrm) Mtlstrm [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\mtlstrm.sys -> [2003/02/16 16:33:00 | 01,293,192 | —- | M] ( )
(SlNtHal) SlNtHal [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\slnthal.sys -> [2003/02/16 15:12:00 | 00,085,520 | —- | M] ( )
(Slntamr) SmartLink AMR_PCI Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\slntamr.sys -> [2003/02/16 15:11:00 | 00,516,616 | —- | M] ( )
(Mtlmnt5) Mtlmnt5 [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\mtlmnt5.sys -> [2003/02/16 15:08:00 | 00,210,128 | —- | M] ( )
(NtMtlFax) NtMtlFax [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ntmtlfax.sys -> [2003/02/05 16:25:00 | 00,162,136 | —- | M] ( )
(SlWdmSup) SlWdmSup [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\slwdmsup.sys -> [2003/01/17 00:19:00 | 00,039,348 | —- | M] (Vireo Software)
(wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\wanatw4.sys -> [2003/01/10 17:13:04 | 00,033,588 | —- | M] (America Online, Inc.)
(StillCam) Still Serial Digital Camera Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\serscan.sys -> [2001/08/17 13:53:32 | 00,006,784 | —- | M] (Microsoft Corporation)
(brparimg) Brother Multi Function Parallel Image driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BrParImg.sys -> [2001/08/17 13:12:24 | 00,003,168 | —- | M] (Brother Industries Ltd.)
(BrUsbScn) Brother MFC USB Scanner driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BrUsbScn.sys -> [2001/08/17 13:12:22 | 00,010,368 | —- | M] (Brother Industries Ltd.)
(BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BrUsbMdm.sys -> [2001/08/17 13:12:20 | 00,011,008 | —- | M] (Brother Industries Ltd.)
(BrParWdm) Brother WDM Parallel Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BrParwdm.sys -> [2001/08/17 13:12:18 | 00,039,552 | —- | M] (Brother Industries Ltd.)
(brfilt) Brother MFC Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BrFilt.sys -> [2001/08/17 13:12:12 | 00,002,944 | —- | M] (Brother Industries Ltd.)
(MODEMCSA) Unimodem Streaming Filter Device [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\MODEMCSA.sys -> [2001/08/17 05:57:38 | 00,016,128 | —- | M] (Microsoft Corporation)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"CustomSearch" -> http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html ->
HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.google.com/ie ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultName" -> Google ->
HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultURL" -> http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.yahoo.com/?fr=fptb-msgr ->
HKEY_CURRENT_USER\: SearchURL\\"" -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> [2008/07/28 02:47:40 | 00,882,416 | —- | M] (Yahoo! Inc.)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
HKEY_CURRENT_USER\: "ProxyOverride" -> 127.0.0.1 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\CompuServe 7.0\Extensions -> ->
HKLM\software\mozilla\CompuServe 7.0\Extensions\\ -> ->
HKLM\software\mozilla\CompuServe 7.0\Extensions\\Components -> C:\Program Files\Common Files\csshare\plugins0942 [C:\PROGRAM FILES\COMMON FILES\CSSHARE\PLUGINS0942] -> [2009/11/18 07:29:57 | 00,000,000 | —D | M]
HKLM\software\mozilla\CompuServe 7.0\Extensions\\Plugins -> C:\Program Files\Common Files\csshare\plugins0942 [C:\PROGRAM FILES\COMMON FILES\CSSHARE\PLUGINS0942] -> [2009/11/18 07:29:57 | 00,000,000 | —D | M]
HKLM\software\mozilla\Firefox\Extensions -> ->
< FireFox Extensions [User Folders] > ->
< HOSTS File > (27 bytes and 1 lines) -> C:\WINDOWS\system32\drivers\etc\hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [&Yahoo! Toolbar Helper] -> [2008/07/28 02:47:40 | 00,882,416 | —- | M] (Yahoo! Inc.)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> [2006/01/12 19:38:22 | 00,063,128 | —- | M] (Adobe Systems Incorporated)
{18597442-c73f-43b3-bf40-76ed057ede97} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{35E78239-811E-4c3f-B37D-F339AC16C2C0} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} [HKLM] -> C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [SingleInstance Class] -> [2008/07/28 02:47:42 | 00,160,496 | —- | M] (Yahoo! Inc)
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> [2008/07/28 02:47:40 | 00,882,416 | —- | M] (Yahoo! Inc.)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> [2008/07/28 02:47:40 | 00,882,416 | —- | M] (Yahoo! Inc.)
WebBrowser\\"{FE6BC4EF-5676-484B-88AE-883323913256}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"avast!" -> C:\Program Files\Alwil Software\Avast4\ashDisp.exe [C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe] -> [2009/09/15 03:56:48 | 00,081,000 | —- | M] (ALWIL Software)
"CHotkey" -> C:\WINDOWS\zHotkey.exe [zHotkey.exe] -> [2003/06/03 11:01:32 | 00,496,640 | —- | M] (Chicony)
"QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2003/11/20 03:29:37 | 00,077,824 | —- | M] (Apple Computer, Inc.)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Messenger (Yahoo!)" -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe ["C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet] -> [2009/03/18 17:50:30 | 04,363,504 | —- | M] (Yahoo! Inc.)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> [2005/09/23 21:05:26 | 00,029,696 | —- | M] (Adobe Systems Incorporated)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link AirPlus G Configuration Utility.lnk -> C:\Program Files\D-Link AirPlus G\AIRPLUS.exe -> [2004/01/06 20:19:38 | 00,294,912 | —- | M] (D-Link)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE -> [1999/02/17 12:05:56 | 00,065,588 | —- | M] (Microsoft Corporation)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe -> [2005/02/15 15:26:20 | 00,724,992 | —- | M] (Intuit, Inc.)
< Desiree Meenan Startup Folder > -> C:\Documents and Settings\Desiree Meenan\Start Menu\Programs\Startup ->
C:\Documents and Settings\Desiree Meenan\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk -> C:\Program Files\Greetings Workshop\GWREMIND.EXE -> [1997/09/03 23:00:00 | 00,050,688 | —- | M] (Microsoft Corporation)
-> C:\Documents and Settings\Desiree Meenan\Start Menu\Programs\Startup\PowerReg Scheduler.exe -> [2007/06/17 22:33:46 | 00,189,952 | —- | M] ()
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" -> [1] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"DisableRegistryTools" -> [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
&Search -> [?p=ZJxdm025SHUS] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 10:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{2499216C-4BA5-11D5-BD9C-000103C116D5}" [HKLM] -> [Reg Error: Key error.] -> File not found
CmdMapping\\"{4528BBE0-4E08-11D5-AD55-00010333D0AD}" [HKLM] -> [Reg Error: Key error.] -> File not found
CmdMapping\\"{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}" [HKLM] -> [Reg Error: Value error.] -> File not found
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. ->
online_musicmatch.com [https] -> Trusted sites ->
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
.[msn] -> My Computer ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{1239CC52-59EF-4DFA-8C61-90FFA846DF7E} [HKLM] -> http://www.musicnotes.com/download/mnviewer.cab [Musicnotes Viewer] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Shockwave ActiveX Control] ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204 [Windows Genuine Advantage Validation Tool] ->
{3DCEC959-378A-4922-AD7E-FD5C925D927F} [HKLM] -> http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab [Disney Online Games ActiveX Control] ->
{7530BFB8-7293-4D34-9923-61A11451AFC5} [HKLM] -> http://download.eset.com/special/eos/OnlineScanner.cab [Reg Error: Key error.] ->
{A4639D2F-774E-11D3-A490-00C04F6843FB} [HKLM] -> http://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab [IEAnimBehaviorFactory Class] ->
{CA11EB7C-1C85-4577-8A49-9E28EFB30184} [HKLM] -> http://www.umediaserver.net/bin/UMediaControl4.cab [UMediaPlayer Class] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab [Reg Error: Key error.] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.0.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{0A33B48B-3810-495E-B45D-EFDFA6C270B8}\\NameServer -> 24.205.192.61 (Linksys Wireless-B USB Network Adapter v2.8) ->
{0D4950E0-2622-4F3A-97C7-70D0110EA63E}\\DhcpNameServer -> 192.168.0.1 (D-Link AirPlus G DWL-G510 Wireless PCI Card) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 16:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
PCANotify -> C:\WINDOWS\System32\PCANotify.dll -> [2003/10/31 11:01:00 | 00,008,704 | —- | M] (Symantec Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 10:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 16:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.0] -> File not found
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 10:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 16:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\CA\eTrust Antivirus\InoNmSrv.exe" -> C:\Program Files\CA\eTrust Antivirus\InoNmSrv.exe [C:\Program Files\CA\eTrust Antivirus\InoNmSrv.exe:*:Enabled:eTrust Antivirus - Admin Server] -> [2004/09/16 10:42:54 | 00,356,624 | —- | M] (Computer Associates International, Inc.)
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
"C:\Program Files\Symantec\pcAnywhere\awhost32.exe" -> C:\Program Files\Symantec\pcAnywhere\awhost32.exe [C:\Program Files\Symantec\pcAnywhere\awhost32.exe:*:Enabled:pcAnywhere Host Service] -> [2003/10/31 11:01:00 | 00,106,496 | —- | M] (Symantec Corporation)
"C:\Program Files\Symantec\pcAnywhere\awrem32.exe" -> C:\Program Files\Symantec\pcAnywhere\awrem32.exe [C:\Program Files\Symantec\pcAnywhere\awrem32.exe:*:Enabled:pcAnywhere Remote Service] -> [2003/05/29 11:00:00 | 00,114,688 | —- | M] (Symantec Corporation)
"C:\Program Files\Symantec\pcAnywhere\Winaw32.exe" -> C:\Program Files\Symantec\pcAnywhere\Winaw32.exe [C:\Program Files\Symantec\pcAnywhere\Winaw32.exe:*:Enabled:pcAnywhere Main Executable] -> [2003/10/31 11:01:00 | 00,704,512 | —- | M] (Symantec Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger] -> [2009/03/18 17:50:30 | 04,363,504 | —- | M] (Yahoo! Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [System32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2003/11/20 03:00:28 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\OTS.exe -> [2009/11/25 20:12:58 | 00,526,848 | —- | C] (OldTimer Tools)
aswRdr.sys -> C:\WINDOWS\System32\drivers\aswRdr.sys -> [2009/11/22 10:34:11 | 00,023,152 | —- | C] (ALWIL Software)
aswTdi.sys -> C:\WINDOWS\System32\drivers\aswTdi.sys -> [2009/11/22 10:34:10 | 00,052,368 | —- | C] (ALWIL Software)
aavmker4.sys -> C:\WINDOWS\System32\drivers\aavmker4.sys -> [2009/11/22 10:34:10 | 00,027,408 | —- | C] (ALWIL Software)
AvastSS.scr -> C:\WINDOWS\System32\AvastSS.scr -> [2009/11/22 10:34:08 | 00,097,480 | —- | C] (ALWIL Software)
aswSP.sys -> C:\WINDOWS\System32\drivers\aswSP.sys -> [2009/11/22 10:34:07 | 00,114,768 | —- | C] (ALWIL Software)
aswmon2.sys -> C:\WINDOWS\System32\drivers\aswmon2.sys -> [2009/11/22 10:34:07 | 00,094,160 | —- | C] (ALWIL Software)
aswmon.sys -> C:\WINDOWS\System32\drivers\aswmon.sys -> [2009/11/22 10:34:07 | 00,093,424 | —- | C] (ALWIL Software)
aswFsBlk.sys -> C:\WINDOWS\System32\drivers\aswFsBlk.sys -> [2009/11/22 10:34:07 | 00,020,560 | —- | C] (ALWIL Software)
aswBoot.exe -> C:\WINDOWS\System32\aswBoot.exe -> [2009/11/22 10:33:48 | 01,279,968 | —- | C] (ALWIL Software)
MFC71.dll -> C:\WINDOWS\System32\MFC71.dll -> [2009/11/22 10:33:48 | 01,060,864 | —- | C] (Microsoft Corporation)
Alwil Software -> C:\Program Files\Alwil Software -> [2009/11/22 10:33:46 | 00,000,000 | —D | C]
avast_home_setup.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\avast_home_setup.exe -> [2009/11/22 10:28:32 | 00,308,160 | —- | C] (ALWIL Software)
Malwarebytes -> C:\Documents and Settings\Desiree Meenan\Application Data\Malwarebytes -> [2009/11/20 21:29:39 | 00,000,000 | —D | C]
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/11/20 21:29:33 | 00,038,224 | —- | C] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/11/20 21:29:32 | 00,019,160 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2009/11/20 21:29:32 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/11/20 21:29:31 | 00,000,000 | —D | C]
mbam-setup.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\mbam-setup.exe -> [2009/11/20 21:26:54 | 04,045,528 | —- | C] (Malwarebytes Corporation )
cmdcons -> C:\cmdcons -> [2009/11/20 18:56:30 | 00,000,000 | RHSD | C]
SWXCACLS.exe -> C:\WINDOWS\SWXCACLS.exe -> [2009/11/20 18:55:14 | 00,212,480 | —- | C] (SteelWerX)
SWREG.exe -> C:\WINDOWS\SWREG.exe -> [2009/11/20 18:55:14 | 00,161,792 | —- | C] (SteelWerX)
SWSC.exe -> C:\WINDOWS\SWSC.exe -> [2009/11/20 18:55:14 | 00,136,704 | —- | C] (SteelWerX)
NIRCMD.exe -> C:\WINDOWS\NIRCMD.exe -> [2009/11/20 18:55:14 | 00,031,232 | —- | C] (NirSoft)
Qoobox -> C:\Qoobox -> [2009/11/20 18:54:36 | 00,000,000 | —D | C]
RootRepeal.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\RootRepeal.exe -> [2009/11/20 17:11:11 | 00,472,064 | —- | C] ( )
ERDNT -> C:\WINDOWS\ERDNT -> [2009/11/20 17:04:38 | 00,000,000 | —D | C]
ERUNT -> C:\Program Files\ERUNT -> [2009/11/20 17:03:52 | 00,000,000 | —D | C]
Adobe -> C:\WINDOWS\System32\Adobe -> [2009/11/18 07:29:35 | 00,000,000 | —D | C]
Trend Micro -> C:\Program Files\Trend Micro -> [2009/11/18 07:26:41 | 00,000,000 | —D | C]
Spybot - Search & Destroy -> C:\Program Files\Spybot - Search & Destroy -> [2009/11/01 17:36:17 | 00,000,000 | —D | C]
Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [2009/11/01 17:36:17 | 00,000,000 | —D | C]
pss -> C:\WINDOWS\pss -> [2009/11/01 17:23:26 | 00,000,000 | —D | C]
slntamr.sys -> C:\WINDOWS\System32\drivers\slntamr.sys -> [2003/11/20 01:49:11 | 00,516,616 | —- | C] ( )
slnthal.sys -> C:\WINDOWS\System32\drivers\slnthal.sys -> [2003/11/20 01:49:11 | 00,085,520 | —- | C] ( )
mtlstrm.sys -> C:\WINDOWS\System32\drivers\mtlstrm.sys -> [2003/11/20 01:49:10 | 01,293,192 | —- | C] ( )
mtlmnt5.sys -> C:\WINDOWS\System32\drivers\mtlmnt5.sys -> [2003/11/20 01:49:10 | 00,210,128 | —- | C] ( )
ntmtlfax.sys -> C:\WINDOWS\System32\drivers\ntmtlfax.sys -> [2003/11/20 01:49:10 | 00,162,136 | —- | C] ( )
winddx.sys -> C:\WINDOWS\System32\drivers\winddx.sys -> [2003/11/19 18:54:50 | 00,014,976 | —- | C] ( )
2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
[Files/Folders - Modified Within 30 Days]
OTS.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\OTS.exe -> [2009/11/25 20:13:01 | 00,526,848 | —- | M] (OldTimer Tools)
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/11/25 03:18:33 | 00,001,158 | —- | M] ()
QTFont.qfn -> C:\WINDOWS\QTFont.qfn -> [2009/11/25 03:18:32 | 00,054,156 | -H– | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/11/25 03:18:14 | 00,000,006 | -H– | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/11/25 03:18:00 | 46,929,1008 | -HS- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/11/25 03:18:00 | 00,002,048 | –S- | M] ()
NTUSER.DAT -> C:\Documents and Settings\Desiree Meenan\NTUSER.DAT -> [2009/11/25 03:17:06 | 04,456,448 | -H– | M] ()
ntuser.ini -> C:\Documents and Settings\Desiree Meenan\ntuser.ini -> [2009/11/25 03:17:06 | 00,000,278 | -HS- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/11/25 03:01:50 | 00,001,393 | —- | M] ()
Duross Construction 1097526202.job -> C:\WINDOWS\tasks\Duross Construction 1097526202.job -> [2009/11/23 16:00:00 | 00,000,548 | -H– | M] ()
Microsoft Word.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\Microsoft Word.lnk -> [2009/11/22 20:45:24 | 00,002,473 | —- | M] ()
QTFont.for -> C:\WINDOWS\QTFont.for -> [2009/11/22 15:30:37 | 00,001,409 | —- | M] ()
avast! Antivirus.lnk -> C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk -> [2009/11/22 10:34:11 | 00,001,743 | —- | M] ()
CONFIG.NT -> C:\WINDOWS\System32\CONFIG.NT -> [2009/11/22 10:34:07 | 00,002,626 | —- | M] ()
avast_home_setup.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\avast_home_setup.exe -> [2009/11/22 10:28:33 | 00,308,160 | —- | M] (ALWIL Software)
Tips for being cooler.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\Tips for being cooler.doc -> [2009/11/21 17:59:20 | 00,020,480 | —- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/11/20 21:29:36 | 00,000,730 | —- | M] ()
mbam-setup.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\mbam-setup.exe -> [2009/11/20 21:26:54 | 04,045,528 | —- | M] (Malwarebytes Corporation )
system.ini -> C:\WINDOWS\system.ini -> [2009/11/20 19:05:10 | 00,000,271 | —- | M] ()
hosts -> C:\WINDOWS\System32\drivers\etc\hosts -> [2009/11/20 19:05:03 | 00,000,027 | —- | M] ()
boot.ini -> C:\boot.ini -> [2009/11/20 18:56:37 | 00,000,281 | RHS- | M] ()
ComboFix.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\ComboFix.exe -> [2009/11/20 18:54:11 | 03,570,958 | R— | M] ()
settings.dat -> C:\Documents and Settings\Desiree Meenan\Desktop\settings.dat -> [2009/11/20 17:11:25 | 00,000,000 | —- | M] ()
RootRepeal.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\RootRepeal.exe -> [2009/11/20 17:11:14 | 00,472,064 | —- | M] ( )
dds.scr -> C:\Documents and Settings\Desiree Meenan\Desktop\dds.scr -> [2009/11/20 17:05:36 | 00,359,929 | —- | M] ()
NTREGOPT.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\NTREGOPT.lnk -> [2009/11/20 17:03:53 | 00,000,645 | —- | M] ()
ERUNT.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\ERUNT.lnk -> [2009/11/20 17:03:53 | 00,000,626 | —- | M] ()
My eBay.url -> C:\Documents and Settings\Desiree Meenan\Desktop\My eBay.url -> [2009/11/18 17:06:07 | 00,000,826 | —- | M] ()
IconCache.db -> C:\Documents and Settings\Desiree Meenan\Local Settings\Application Data\IconCache.db -> [2009/11/18 16:51:48 | 03,081,934 | -H– | M] ()
Yahoo!.url -> C:\Documents and Settings\Desiree Meenan\Desktop\Yahoo!.url -> [2009/11/18 15:41:21 | 00,000,240 | —- | M] ()
HijackThis.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\HijackThis.lnk -> [2009/11/18 07:26:42 | 00,001,768 | —- | M] ()
PEV.exe -> C:\WINDOWS\PEV.exe -> [2009/11/14 01:47:57 | 00,260,608 | —- | M] ()
yahoo answers.url -> C:\Documents and Settings\Desiree Meenan\Desktop\yahoo answers.url -> [2009/11/11 20:46:37 | 00,000,479 | —- | M] ()
YouTube.url -> C:\Documents and Settings\Desiree Meenan\Desktop\YouTube.url -> [2009/11/11 19:45:07 | 00,001,062 | —- | M] ()
FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2009/11/11 03:19:04 | 00,239,144 | —- | M] ()
revolutionary war poster.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\revolutionary war poster.doc -> [2009/11/05 17:32:14 | 00,110,080 | —- | M] ()
MRT.exe -> C:\WINDOWS\System32\MRT.exe -> [2009/11/05 09:36:21 | 26,768,832 | —- | M] (Microsoft Corporation)
SCARY STORY ROUGH DRAFT.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\SCARY STORY ROUGH DRAFT.doc -> [2009/11/01 22:04:54 | 00,064,000 | —- | M] ()
wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/11/01 18:22:59 | 00,000,405 | —- | M] ()
hosts.20091101-182251.backup -> C:\WINDOWS\System32\drivers\etc\hosts.20091101-182251.backup -> [2009/11/01 18:22:51 | 00,001,231 | R— | M] ()
Spybot - Search & Destroy.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\Spybot - Search & Destroy.lnk -> [2009/11/01 17:36:22 | 00,000,967 | —- | M] ()
win.ini -> C:\WINDOWS\win.ini -> [2009/11/01 17:25:13 | 00,001,004 | —- | M] ()
Boot.bak -> C:\Boot.bak -> [2009/11/01 17:25:13 | 00,000,211 | —- | M] ()
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2009/11/01 17:09:20 | 00,443,286 | —- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2009/11/01 17:09:20 | 00,382,966 | —- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2009/11/01 17:09:20 | 00,053,978 | —- | M] ()
GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\Desiree Meenan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/10/28 15:09:10 | 00,061,840 | —- | M] ()
tzchange.exe -> C:\WINDOWS\System32\tzchange.exe -> [2009/10/28 07:07:15 | 00,046,080 | —- | M] (Microsoft Corporation)
ABC book.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\ABC book.doc -> [2009/10/28 04:47:42 | 00,147,456 | —- | M] ()
80 C:\Documents and Settings\Desiree Meenan\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Desiree Meenan\Local Settings\Temp\*.tmp ->
2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
[Files - No Company Name]
QTFont.qfn -> C:\WINDOWS\QTFont.qfn -> [2009/11/22 15:30:37 | 00,054,156 | -H– | C] ()
QTFont.for -> C:\WINDOWS\QTFont.for -> [2009/11/22 15:30:37 | 00,001,409 | —- | C] ()
avast! Antivirus.lnk -> C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk -> [2009/11/22 10:34:11 | 00,001,743 | —- | C] ()
actskin4.ocx -> C:\WINDOWS\System32\actskin4.ocx -> [2009/11/22 10:33:48 | 00,380,928 | —- | C] ()
Tips for being cooler.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\Tips for being cooler.doc -> [2009/11/21 17:59:19 | 00,020,480 | —- | C] ()
Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/11/20 21:29:36 | 00,000,730 | —- | C] ()
Boot.bak -> C:\Boot.bak -> [2009/11/20 18:56:37 | 00,000,211 | —- | C] ()
cmldr -> C:\cmldr -> [2009/11/20 18:56:33 | 00,260,272 | —- | C] ()
PEV.exe -> C:\WINDOWS\PEV.exe -> [2009/11/20 18:55:14 | 00,260,608 | —- | C] ()
sed.exe -> C:\WINDOWS\sed.exe -> [2009/11/20 18:55:14 | 00,098,816 | —- | C] ()
grep.exe -> C:\WINDOWS\grep.exe -> [2009/11/20 18:55:14 | 00,080,412 | —- | C] ()
MBR.exe -> C:\WINDOWS\MBR.exe -> [2009/11/20 18:55:14 | 00,077,312 | —- | C] ()
zip.exe -> C:\WINDOWS\zip.exe -> [2009/11/20 18:55:14 | 00,068,096 | —- | C] ()
ComboFix.exe -> C:\Documents and Settings\Desiree Meenan\Desktop\ComboFix.exe -> [2009/11/20 18:54:11 | 03,570,958 | R— | C] ()
settings.dat -> C:\Documents and Settings\Desiree Meenan\Desktop\settings.dat -> [2009/11/20 17:11:25 | 00,000,000 | —- | C] ()
dds.scr -> C:\Documents and Settings\Desiree Meenan\Desktop\dds.scr -> [2009/11/20 17:05:33 | 00,359,929 | —- | C] ()
NTREGOPT.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\NTREGOPT.lnk -> [2009/11/20 17:03:53 | 00,000,645 | —- | C] ()
ERUNT.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\ERUNT.lnk -> [2009/11/20 17:03:53 | 00,000,626 | —- | C] ()
HijackThis.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\HijackThis.lnk -> [2009/11/18 07:26:42 | 00,001,768 | —- | C] ()
revolutionary war poster.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\revolutionary war poster.doc -> [2009/11/05 17:32:13 | 00,110,080 | —- | C] ()
wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/11/01 18:22:58 | 00,000,405 | —- | C] ()
Spybot - Search & Destroy.lnk -> C:\Documents and Settings\Desiree Meenan\Desktop\Spybot - Search & Destroy.lnk -> [2009/11/01 17:36:22 | 00,000,967 | —- | C] ()
SCARY STORY ROUGH DRAFT.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\SCARY STORY ROUGH DRAFT.doc -> [2009/10/28 16:15:49 | 00,064,000 | —- | C] ()
ABC book.doc -> C:\Documents and Settings\Desiree Meenan\My Documents\ABC book.doc -> [2009/10/27 17:38:02 | 00,147,456 | —- | C] ()
iyvu9_32.dll -> C:\WINDOWS\System32\iyvu9_32.dll -> [2008/03/14 11:47:45 | 00,056,832 | —- | C] ()
QTW.INI -> C:\WINDOWS\QTW.INI -> [2007/07/18 12:11:38 | 00,000,305 | —- | C] ()
TLCAPPS.INI -> C:\WINDOWS\TLCAPPS.INI -> [2007/06/02 18:59:13 | 00,000,229 | —- | C] ()
SETUP32.INI -> C:\WINDOWS\SETUP32.INI -> [2007/06/02 18:58:54 | 00,000,000 | —- | C] ()
cdplayer.ini -> C:\WINDOWS\cdplayer.ini -> [2006/07/28 09:23:23 | 00,000,879 | —- | C] ()
HPGdiPlus.ini -> C:\WINDOWS\HPGdiPlus.ini -> [2006/06/26 06:15:48 | 00,000,206 | —- | C] ()
liveup.ini -> C:\WINDOWS\liveup.ini -> [2006/03/17 13:21:42 | 00,000,044 | —- | C] ()
hptcpmon.ini -> C:\WINDOWS\System32\hptcpmon.ini -> [2006/01/19 08:34:26 | 00,003,399 | R— | C] ()
AddPort.ini -> C:\WINDOWS\System32\AddPort.ini -> [2006/01/19 08:34:26 | 00,000,136 | —- | C] ()
hpntwksetup.ini -> C:\WINDOWS\hpntwksetup.ini -> [2006/01/19 08:34:13 | 00,000,700 | —- | C] ()
Install.ini -> C:\WINDOWS\Install.ini -> [2005/09/14 10:53:06 | 00,000,028 | —- | C] ()
BrmfBidi.ini -> C:\WINDOWS\BrmfBidi.ini -> [2005/02/01 08:10:08 | 00,002,183 | —- | C] ()
YCRWin32.dll -> C:\WINDOWS\System32\YCRWin32.dll -> [2004/12/27 11:39:56 | 00,065,536 | —- | C] ()
hpqEmlSz.INI -> C:\WINDOWS\hpqEmlSz.INI -> [2004/11/08 10:19:57 | 00,000,000 | —- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2004/10/14 07:44:25 | 00,000,376 | —- | C] ()
A6W.INI -> C:\WINDOWS\A6W.INI -> [2004/09/30 09:37:08 | 00,000,035 | —- | C] ()
WORDPAD.INI -> C:\WINDOWS\WORDPAD.INI -> [2004/09/27 07:32:20 | 00,000,754 | —- | C] ()
tx32.dll -> C:\WINDOWS\System32\tx32.dll -> [2004/09/07 08:20:04 | 00,375,296 | —- | C] ()
Ic32.ini -> C:\WINDOWS\System32\Ic32.ini -> [2004/09/07 08:20:04 | 00,000,202 | —- | C] ()
ntio412.sys -> C:\WINDOWS\System32\ntio412.sys -> [2004/05/17 14:43:09 | 00,035,424 | —- | C] ()
ntio404.sys -> C:\WINDOWS\System32\ntio404.sys -> [2004/05/17 14:43:07 | 00,034,560 | —- | C] ()
ntio804.sys -> C:\WINDOWS\System32\ntio804.sys -> [2004/05/17 14:43:06 | 00,034,560 | —- | C] ()
ntio411.sys -> C:\WINDOWS\System32\ntio411.sys -> [2004/05/17 14:43:04 | 00,035,648 | —- | C] ()
ntio.sys -> C:\WINDOWS\System32\ntio.sys -> [2004/05/17 14:43:02 | 00,033,840 | —- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2003/11/20 04:00:12 | 00,000,061 | —- | C] ()
psisdecd.dll -> C:\WINDOWS\System32\psisdecd.dll -> [2003/11/20 03:37:40 | 00,363,520 | —- | C] ()
winamp.ini -> C:\WINDOWS\winamp.ini -> [2003/11/20 03:27:40 | 00,000,132 | —- | C] ()
net2fone.ini -> C:\WINDOWS\net2fone.ini -> [2003/11/20 03:27:07 | 00,000,310 | —- | C] ()
PIC.dll -> C:\WINDOWS\PIC.dll -> [2003/11/20 03:09:53 | 00,532,544 | —- | C] ()
HKNTDLL.dll -> C:\WINDOWS\HKNTDLL.dll -> [2003/11/20 03:09:53 | 00,024,576 | —- | C] ()
avrack.ini -> C:\WINDOWS\avrack.ini -> [2003/11/20 03:08:07 | 00,000,164 | —- | C] ()
control.ini -> C:\WINDOWS\control.ini -> [2003/11/20 03:00:28 | 00,000,000 | —- | C] ()
vbaddin.ini -> C:\WINDOWS\vbaddin.ini -> [2003/11/20 02:58:05 | 00,000,059 | —- | C] ()
vb.ini -> C:\WINDOWS\vb.ini -> [2003/11/20 02:58:05 | 00,000,036 | —- | C] ()
tslabels.ini -> C:\WINDOWS\System32\tslabels.ini -> [2003/11/20 02:57:18 | 00,013,223 | —- | C] ()
msdtcprf.ini -> C:\WINDOWS\System32\msdtcprf.ini -> [2003/11/20 02:57:17 | 00,001,931 | —- | C] ()
slextspk.dll -> C:\WINDOWS\System32\slextspk.dll -> [2003/11/20 01:49:11 | 00,188,416 | —- | C] ()
SLGen.dll -> C:\WINDOWS\System32\SLGen.dll -> [2003/11/20 01:49:11 | 00,159,744 | —- | C] ()
coinst.dll -> C:\WINDOWS\System32\coinst.dll -> [2003/11/20 01:49:10 | 00,049,152 | —- | C] ()
oeminfo.ini -> C:\WINDOWS\System32\oeminfo.ini -> [2003/11/20 01:49:04 | 00,001,094 | —- | C] ()
emver.ini -> C:\WINDOWS\System32\emver.ini -> [2003/11/20 01:49:04 | 00,000,468 | —- | C] ()
win87em.dll -> C:\WINDOWS\System32\win87em.dll -> [2003/11/20 01:48:40 | 00,013,312 | —- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2003/11/20 01:48:40 | 00,001,004 | —- | C] ()
tcpmon.ini -> C:\WINDOWS\System32\tcpmon.ini -> [2003/11/20 01:48:37 | 00,053,478 | —- | C] ()
tsd32.dll -> C:\WINDOWS\System32\tsd32.dll -> [2003/11/20 01:48:37 | 00,015,360 | —- | C] ()
system.ini -> C:\WINDOWS\system.ini -> [2003/11/20 01:48:36 | 00,000,271 | —- | C] ()
sbe.dll -> C:\WINDOWS\System32\sbe.dll -> [2003/11/20 01:48:31 | 00,270,848 | —- | C] ()
rsvp.ini -> C:\WINDOWS\System32\rsvp.ini -> [2003/11/20 01:48:30 | 00,012,082 | —- | C] ()
dxmasf.dll -> C:\WINDOWS\System32\dxmasf.dll -> [2003/11/20 01:48:29 | 00,498,742 | —- | C] ()
rasctrs.ini -> C:\WINDOWS\System32\rasctrs.ini -> [2003/11/20 01:48:29 | 00,003,458 | —- | C] ()
pschdprf.ini -> C:\WINDOWS\System32\pschdprf.ini -> [2003/11/20 01:48:28 | 00,006,877 | —- | C] ()
perfci.ini -> C:\WINDOWS\System32\perfci.ini -> [2003/11/20 01:48:28 | 00,002,891 | —- | C] ()
perfwci.ini -> C:\WINDOWS\System32\perfwci.ini -> [2003/11/20 01:48:28 | 00,002,732 | —- | C] ()
perffilt.ini -> C:\WINDOWS\System32\perffilt.ini -> [2003/11/20 01:48:28 | 00,001,152 | —- | C] ()
prodspec.ini -> C:\WINDOWS\System32\prodspec.ini -> [2003/11/20 01:48:28 | 00,000,343 | —- | C] ()
ntdos411.sys -> C:\WINDOWS\System32\ntdos411.sys -> [2003/11/20 01:48:22 | 00,029,370 | —- | C] ()
ntdos412.sys -> C:\WINDOWS\System32\ntdos412.sys -> [2003/11/20 01:48:22 | 00,029,274 | —- | C] ()
ntdos804.sys -> C:\WINDOWS\System32\ntdos804.sys -> [2003/11/20 01:48:22 | 00,029,146 | —- | C] ()
ntdos404.sys -> C:\WINDOWS\System32\ntdos404.sys -> [2003/11/20 01:48:22 | 00,029,146 | —- | C] ()
ntdos.sys -> C:\WINDOWS\System32\ntdos.sys -> [2003/11/20 01:48:22 | 00,027,866 | —- | C] ()
msencode.dll -> C:\WINDOWS\System32\msencode.dll -> [2003/11/20 01:48:16 | 00,094,282 | —- | C] ()
msdxmlc.dll -> C:\WINDOWS\System32\msdxmlc.dll -> [2003/11/20 01:48:16 | 00,004,126 | —- | C] ()
msdfmap.ini -> C:\WINDOWS\msdfmap.ini -> [2003/11/20 01:48:16 | 00,001,405 | —- | C] ()
key01.sys -> C:\WINDOWS\System32\key01.sys -> [2003/11/20 01:48:09 | 00,042,809 | —- | C] ()
keyboard.sys -> C:\WINDOWS\System32\keyboard.sys -> [2003/11/20 01:48:09 | 00,042,537 | —- | C] ()
ir32_32.dll -> C:\WINDOWS\System32\ir32_32.dll -> [2003/11/20 01:48:08 | 00,199,168 | —- | C] ()
himem.sys -> C:\WINDOWS\System32\himem.sys -> [2003/11/20 01:48:04 | 00,004,768 | —- | C] ()
esentprf.ini -> C:\WINDOWS\System32\esentprf.ini -> [2003/11/20 01:48:01 | 01,015,477 | —- | C] ()
encdec.dll -> C:\WINDOWS\System32\encdec.dll -> [2003/11/20 01:48:00 | 00,186,880 | —- | C] ()
compatui.dll -> C:\WINDOWS\System32\compatui.dll -> [2003/11/20 01:47:46 | 00,252,928 | —- | C] ()
country.sys -> C:\WINDOWS\System32\country.sys -> [2003/11/20 01:47:46 | 00,027,097 | —- | C] ()
msjetoledb40.dll -> C:\WINDOWS\System32\msjetoledb40.dll -> [2003/11/20 01:47:44 | 00,355,112 | —- | C] ()
ansi.sys -> C:\WINDOWS\System32\ansi.sys -> [2003/11/20 01:47:40 | 00,009,029 | —- | C] ()
SLLights.dll -> C:\WINDOWS\System32\SLLights.dll -> [2003/11/19 18:54:50 | 00,466,944 | —- | C] ()
amr_cpl.dll -> C:\WINDOWS\System32\amr_cpl.dll -> [2003/11/19 18:54:50 | 00,151,552 | —- | C] ()
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2003/11/19 18:53:39 | 00,443,286 | —- | C] ()
ODBCINST.INI -> C:\WINDOWS\ODBCINST.INI -> [2003/11/19 18:53:38 | 00,004,161 | —- | C] ()
patchw32.dll -> C:\WINDOWS\patchw32.dll -> [2003/07/14 11:30:28 | 00,197,120 | —- | C] ()
quartz.dll -> C:\WINDOWS\System32\quartz.dll -> [2003/05/30 09:00:02 | 01,291,264 | —- | C] ()
qdvd.dll -> C:\WINDOWS\System32\qdvd.dll -> [2003/05/30 09:00:02 | 00,386,048 | —- | C] ()
devenum.dll -> C:\WINDOWS\System32\devenum.dll -> [2003/05/30 09:00:02 | 00,059,904 | —- | C] ()
qedwipes.dll -> C:\WINDOWS\System32\qedwipes.dll -> [2002/12/12 00:14:32 | 00,733,696 | —- | C] ()
qedit.dll -> C:\WINDOWS\System32\qedit.dll -> [2002/12/12 00:14:32 | 00,562,176 | —- | C] ()
qdv.dll -> C:\WINDOWS\System32\qdv.dll -> [2002/12/12 00:14:32 | 00,279,040 | —- | C] ()
qcap.dll -> C:\WINDOWS\System32\qcap.dll -> [2002/12/12 00:14:32 | 00,192,512 | —- | C] ()
amstream.dll -> C:\WINDOWS\System32\amstream.dll -> [2002/12/12 00:14:32 | 00,070,656 | —- | C] ()
mciqtz32.dll -> C:\WINDOWS\System32\mciqtz32.dll -> [2002/12/12 00:14:32 | 00,035,328 | —- | C] ()
msdmo.dll -> C:\WINDOWS\System32\msdmo.dll -> [2002/12/12 00:14:32 | 00,014,336 | —- | C] ()
paqsp.dll -> C:\WINDOWS\System32\paqsp.dll -> [2001/08/17 14:36:28 | 00,157,696 | —- | C] ()
MSRTEDIT.DLL -> C:\WINDOWS\System32\MSRTEDIT.DLL -> [1999/01/22 10:46:58 | 00,065,536 | —- | C] ()
[Alternate Data Streams]
@Alternate Data Stream - 2628 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:Q30lsldxJoudresxAaaqpcawXc
< End of report >