OTL Extras logfile created on: 1/11/2010 11:58:50 PM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Kila_Hau\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.15 Gb Total Space | 66.44 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KILAHAU
Current User Name: Kila_Hau
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = JSFile] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"58504:TCP" = 58504:TCP:*:Enabled:Pando Media Booster
"58504:UDP" = 58504:UDP:*:Enabled:Pando Media Booster
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\MozyHome\mozybackup.exe" = C:\Program Files\MozyHome\mozybackup.exe:*:Enabled:mozybackup – ()
"C:\Program Files\Cartoon Network\Ben 10 Bounty Hunters\RT_Multiplayer.exe" = C:\Program Files\Cartoon Network\Ben 10 Bounty Hunters\RT_Multiplayer.exe:*:Enabled:RT_Multi Application – File not found
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\NBC Direct\DirectPlayerCore.exe" = C:\Program Files\NBC Direct\DirectPlayerCore.exe:*:Enabled:NBC Direct – (NBC Universal)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\Aptana\Aptana Studio 1.2\jre\bin\javaw.exe" = C:\Program Files\Aptana\Aptana Studio 1.2\jre\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0996C331-6DCB-4E38-A3EC-0A77ABAE1361}" = Help_CTR
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel® Network Connections 13.0.42.0
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 17
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2A97D5B3-A989-47E1-B207-1CA9E3635655}" = aioprnt
"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BED0238-3A25-41AE-BC23-316914B5B048}" = aioocr
"{3EB90211-5E1E-42A6-9C27-E42C4771F7DC}" = MozyHome Remote Backup
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{73F1681F-ADE1-461F-9F18-B7640507D395}" = ksdip
"{753D852A-D86D-42C9-9978-40AE66FB8985}" = Driver Installer
"{7599B516-83D2-4B41-8DC0-25FA4ADC112F}" = HOT ALBUM MYBOX
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{791E3D44-33D3-4446-82AD-5CD4B0169083}" = aiofw
"{79E41D91-BA1C-44B9-9358-48E598263ECF}" = center
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{843081BD-351F-46FC-8A17-517A0D9117A3}" = helptut
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A65F7CF8-6F76-40CE-B44D-D5A89D9881C7}" = MSN Toolbar Platform
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B2B30EC0-FB6A-43BB-9B38-0C3B32D75B40}_is1" = Sony Download Taxi 1.5.0.0
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{C0251585-1BE8-4278-B3CB-964B6E01C59D}" = aioscnnr
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = KODAK All-in-One Printer Software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC626A21-EDF1-40C7-8F2F-D2BA7535529F}" = helpug
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.00
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1BA3CD5-89DC-4273-8603-A75F33E9B335}" = Nokia Connectivity Adapter Cable DKU-5
"{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F}" = NBC Direct
"{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"{F65FE148-FCF5-42F7-8803-FA0B7DA8B8A4}" = ubCore
"{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}" = Windows Media Connect
"{F8A3C1B6-D2E0-4CE1-80A2-555D6F71C639}" = Microsoft Search Enhancement Pack
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AOL Search Enhancement" = Search Enhancement by AOL Search
"avast!" = avast! Antivirus
"ERUNT_is1" = ERUNT 1.1j
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{7599B516-83D2-4B41-8DC0-25FA4ADC112F}" = HOT ALBUM MYBOX
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InstallShield_{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"InstallShield_{F65FE148-FCF5-42F7-8803-FA0B7DA8B8A4}" = ubCore
"IPP Port Monitor" = IPP Port Monitor
"Linksys Bi-Admin" = Linksys Bi-Admin
"MagicDisc 2.7.97" = MagicDisc 2.7.97
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MouseSuite98" = Sony USB Mouse
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Connect" = Windows Media Connect
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"idm_flash" = IDM Flash 4.4.0.468
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"NBC Direct" = NBC Direct
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 11/6/2009 1:12:42 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\MICROSOFT
FEEDS~\MICROSOFT AT WORK~.FEED-MS failed, 00000005.
Error - 11/6/2009 1:12:43 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\MICROSOFT
FEEDS~\MICROSOFT AT HOME~.FEED-MS failed, 00000005.
Error - 11/6/2009 1:12:43 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\BOOKMARKS
TOOLBAR FOLDER~\LATEST HEADLINES~.FEED-MS failed, 00000005.
[ Application Events ]
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/18/2009 1:34:17 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.
Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)
Error - 11/18/2009 1:34:18 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.
Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)
Error - 12/9/2009 8:50:01 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
Error - 12/9/2009 8:51:32 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
Error - 1/3/2010 1:38:46 AM | Computer Name = KILAHAU | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.
Error - 1/4/2010 6:57:23 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
Error - 1/8/2010 1:45:57 AM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
[ Application Events ]
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/18/2009 1:34:17 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.
Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)
Error - 11/18/2009 1:34:18 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.
Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)
Error - 12/9/2009 8:50:01 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
Error - 12/9/2009 8:51:32 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
Error - 1/3/2010 1:38:46 AM | Computer Name = KILAHAU | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.
Error - 1/4/2010 6:57:23 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
Error - 1/8/2010 1:45:57 AM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.
[ OSession Events ]
Error - 10/17/2008 1:26:45 PM | Computer Name = KILA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 98023
seconds with 2880 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
Error - 1/12/2010 1:52:27 AM | Computer Name = KILAHAU | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3
Error - 1/12/2010 1:54:34 AM | Computer Name = KILAHAU | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
GREG that believes that it is the master browser for the domain on transport NetBT_Tcpip_{11317D5A-28C1-4478-A0B4.
The
master browser is stopping or an election is being forced.
< End of report >
OTL logfile created on: 1/11/2010 11:58:50 PM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Kila_Hau\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.15 Gb Total Space | 66.44 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KILAHAU
Current User Name: Kila_Hau
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\NBC Direct\DirectPlayerCore.exe (NBC Universal)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\MozyHome\mozybackup.exe ()
PRC - C:\Program Files\Kodak\Printer\Center\KodakSvc.exe (Eastman Kodak Company)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe (PLANNING Co., Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (mozybackup) – C:\Program Files\MozyHome\mozybackup.exe ()
SRV - (KodakSvc) – C:\Program Files\Kodak\printer\center\KodakSvc.exe (Eastman Kodak Company)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (WmcCds) Windows Media Connect (WMC) – c:\Program Files\Windows Media Connect\mswmccds.exe (Microsoft Corporation)
SRV - (WmcCdsLs) Windows Media Connect (WMC) – C:\Program Files\Windows Media Connect\mswmcls.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (PzWDM) – C:\WINDOWS\system32\Drivers\PzWDM.sys (Prassi Technology)
DRV - (LMIRfsClientNP) – C:\WINDOWS\system32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (mozyFilter) – C:\WINDOWS\system32\drivers\mozy.sys (Mozy, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (lmimirr) – C:\WINDOWS\system32\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (RimVSerPort) – C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (tifmsony) – C:\WINDOWS\system32\drivers\tifmsony.sys (Texas Instruments)
DRV - (ubohci) – C:\WINDOWS\system32\drivers\ubohci.sys (Unibrain S.A.)
DRV - (ubumapi) – C:\WINDOWS\system32\drivers\UBUMAPI.sys (Unibrain S.A.)
DRV - (ubsbm) – C:\WINDOWS\system32\drivers\UBSBM.sys (Unibrain S.A.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en&source;=iglk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Crawler Search"
FF - prefs.js..browser.search.order.1: "Crawler Search"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..keyword.URL: "
http://www.crawler.com/search/dispatcher.aspx?tp=aus&tbid;=60049&qkw;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/01/01 11:48:18 | 00,000,000 | —D | M]
[2008/08/10 18:14:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Extensions
[2008/11/18 22:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions
[2008/08/10 19:27:28 | 00,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2008/10/20 11:12:03 | 00,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/09/14 18:32:59 | 00,000,000 | —D | M] (deskCut) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA}
[2008/08/10 19:46:24 | 00,000,000 | —D | M] (BugMeNot) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2008/08/10 20:06:31 | 00,000,000 | —D | M] (DictionarySearch) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2008/08/10 19:33:06 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/08/10 18:49:04 | 00,000,000 | —D | M] () – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{DCBD1271-D228-4082-9FBC-36D9B7660B03}
[2008/10/02 20:09:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\[removed]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - No CLSID value found.
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DC5F9604-C6E2-47D0-8E0F-E60FCCB334C7} - No CLSID value found.
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe File not found
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MBBalloon] C:\Program Files\HOTALBUMMyBOX\MBBalloon.exe (PLANNING Co., Ltd.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] File not found
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [PartSeal] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
O4 - HKLM..\Run: [Wireless printer] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKCU..\Run: [Cute Password Manager] File not found
O4 - HKCU..\Run: [DirectPlayerCore] C:\Program Files\NBC Direct\DirectPlayerCore.exe (NBC Universal)
O4 - HKCU..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKCU..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident\4.0; File not found
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe (PLANNING Co., Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB (VaioInfo.CMClass)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566}
https://216.84.63.34:5443/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1209522144312 (MUWebControl Class)
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274}
http://www.shockwave.com/content/snailmail…gwebinstall.cab (Sandlot Loader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD}
http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB (TSEasyInstallX Control)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
http://onlinedesigner.hgtv.com/images/app/view22rte.cab (View22RTE Class)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/05 12:32:55 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/01/11 23:40:44 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/11 23:35:46 | 00,544,256 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe
[2010/01/11 18:54:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/01/10 14:24:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\Application Data\Malwarebytes
[2010/01/10 14:24:29 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/10 14:24:28 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/10 14:24:27 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/10 14:24:27 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/10 14:23:32 | 05,115,840 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Kila_Hau\Desktop\mbam-setup.exe
[2010/01/10 14:22:23 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/01/10 14:19:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/01/10 14:18:41 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Kila_Hau\Desktop\erunt_setup.exe
[2010/01/10 14:17:06 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Kila_Hau\Desktop\SysRestorePoint.exe
[2010/01/10 13:20:32 | 00,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/01/07 12:28:49 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Kila_Hau\Desktop\.picasaoriginals
[2010/01/06 13:00:38 | 00,000,000 | —D | C] – C:\Program Files\IPP Port Monitor
[2010/01/06 13:00:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\WINDOWS
[2010/01/06 12:45:04 | 00,000,000 | —D | C] – C:\Program Files\Linksys
[2010/01/06 11:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\Desktop\linksys Wireless Printer
[2010/01/01 11:48:11 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/01/01 11:47:59 | 00,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/01/01 11:47:50 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/01 11:47:38 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/01 11:46:56 | 00,000,000 | —D | C] – C:\Program Files\MSN Toolbar Installer
[2010/01/01 11:46:08 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/01 11:46:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/01 11:46:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/12/14 13:15:14 | 02,146,304 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2009/08/01 19:55:15 | 00,308,160 | —- | C] (ALWIL Software) – C:\Program Files\avast_home_setup.exe
[2009/07/23 02:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/26 18:09:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2009/06/20 19:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Bytemobile
[2009/05/21 21:32:34 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/03/15 10:30:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Eastman Kodak Company
[2009/03/14 21:03:52 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Eastman Kodak Company
[2009/02/21 23:06:43 | 45,570,152 | —- | C] (Trend Micro Inc.) – C:\Program Files\TIS_Download_SP_32bit.exe
[2009/01/15 14:14:20 | 66,644,872 | —- | C] (Trend Micro Inc.) – C:\Program Files\TrendMicro_TIS_17.00_en-US_32-bit.exe
[2008/12/06 20:36:08 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2008/10/17 12:26:10 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2008/10/17 12:26:09 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2008/08/13 05:48:55 | 04,891,216 | —- | C] (Microsoft Corporation) – C:\Program Files\Silverlight.2.0.exe
[2008/08/12 22:47:30 | 05,520,400 | —- | C] (Microsoft Corporation) – C:\Program Files\WindowsSearch-KB940157-XP-x86-enu.exe
[2008/07/27 07:18:49 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[1 C:\Documents and Settings\Kila_Hau\Desktop\*.tmp files -> C:\Documents and Settings\Kila_Hau\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/01/11 23:52:01 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/11 23:51:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/11 23:50:50 | 05,242,880 | -H– | M] () – C:\Documents and Settings\Kila_Hau\NTUSER.DAT
[2010/01/11 23:50:50 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Kila_Hau\ntuser.ini
[2010/01/11 23:35:48 | 00,544,256 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe
[2010/01/11 23:35:07 | 00,000,000 | —- | M] () – C:\Documents and Settings\Kila_Hau\settings.dat
[2010/01/11 23:34:44 | 00,094,720 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\pw and checks.xlsx
[2010/01/11 23:34:32 | 00,464,491 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\RootRepeal.zip
[2010/01/11 23:29:27 | 00,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A4258327-FEA4-40DE-88D7-9AF76047C84C}.job
[2010/01/11 10:08:04 | 00,000,362 | —- | M] () – C:\WINDOWS\tasks\Kodak AiO Scheduled Maintenance.job
[2010/01/11 02:30:27 | 00,003,980 | —- | M] () – C:\WINDOWS\mozy.blk
[2010/01/11 02:30:27 | 00,002,460 | —- | M] () – C:\WINDOWS\mozy.flt
[2010/01/11 00:33:55 | 00,015,960 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\greg finance.xlsx
[2010/01/11 00:19:52 | 00,111,795 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Greg LoanAmortizationSchedule.zip
[2010/01/11 00:12:11 | 00,119,873 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\loan-amortization-schedule_L.xlsx
[2010/01/11 00:09:36 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$loan-amortization-schedule_L.xlsx
[2010/01/10 17:13:24 | 00,359,929 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\dds.scr
[2010/01/10 17:12:56 | 00,001,458 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\ark.text
[2010/01/10 16:20:30 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$greg finance.xlsx
[2010/01/10 14:55:28 | 00,284,915 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\gmer.zip
[2010/01/10 14:24:32 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 14:23:42 | 05,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Kila_Hau\Desktop\mbam-setup.exe
[2010/01/10 14:22:24 | 00,000,611 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\NTREGOPT.lnk
[2010/01/10 14:22:24 | 00,000,592 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\ERUNT.lnk
[2010/01/10 14:18:43 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Kila_Hau\Desktop\erunt_setup.exe
[2010/01/10 14:17:06 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Kila_Hau\Desktop\SysRestorePoint.exe
[2010/01/10 13:40:20 | 00,014,206 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\hijackthis1.10
[2010/01/10 13:20:32 | 00,001,988 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\HiJackThis.lnk
[2010/01/09 16:02:30 | 00,347,226 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Fall09 LR activities sign up.pdf
[2010/01/09 15:40:00 | 01,282,344 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Junior%20Egyptologist%20Final.pdf
[2010/01/09 10:01:00 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\Norton PC Checkup Weekend Scanner.job
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 14:16:41 | 00,237,441 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\att.pdf
[2010/01/07 14:16:31 | 00,237,441 | —- | M] () – C:\Documents and Settings\Kila_Hau\My Documents\ATT Alice Ct 12.2009.pdf
[2010/01/06 19:05:00 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\Norton PC Checkup WeekDay Scanner.job
[2010/01/06 12:47:33 | 00,000,867 | —- | M] () – C:\WINDOWS\Common.ini
[2010/01/04 10:44:52 | 00,019,410 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\TO DO Jan 2010.xlsx
[2010/01/03 16:29:16 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$TO DO Jan 2010.xlsx
[2010/01/02 19:58:10 | 00,358,603 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Lighting.docx
[2010/01/01 13:56:17 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$pression info.docx
[2010/01/01 11:43:46 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/01/01 11:40:30 | 00,000,216 | RHS- | M] () – C:\boot.ini
[2010/01/01 11:40:29 | 00,000,461 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/01 11:40:12 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/27 10:01:08 | 00,000,442 | —- | M] () – C:\WINDOWS\tasks\EasyShare Registration Task.job
[2009/12/25 22:32:09 | 00,024,127 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\note to bh.docx
[2009/12/22 16:38:34 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$te to bh.docx
[2009/12/22 15:52:27 | 00,404,591 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\My Shape Return 12.09.docx
[2009/12/21 11:59:01 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$ Shape Return 12.09.docx
[2009/12/14 13:15:14 | 02,146,304 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[1 C:\Documents and Settings\Kila_Hau\Desktop\*.tmp files -> C:\Documents and Settings\Kila_Hau\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/01/11 23:35:07 | 00,000,000 | —- | C] () – C:\Documents and Settings\Kila_Hau\settings.dat
[2010/01/11 23:34:30 | 00,464,491 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\RootRepeal.zip
[2010/01/11 00:19:52 | 00,111,795 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Greg LoanAmortizationSchedule.zip
[2010/01/11 00:09:36 | 00,119,873 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\loan-amortization-schedule_L.xlsx
[2010/01/11 00:09:36 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$loan-amortization-schedule_L.xlsx
[2010/01/10 22:50:57 | 00,364,847 | —- | C] () – C:\Documents and Settings\Kila_Hau\My Documents\UltimateBuyHold.pdf
[2010/01/10 17:13:23 | 00,359,929 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\dds.scr
[2010/01/10 17:12:56 | 00,001,458 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\ark.text
[2010/01/10 16:20:30 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$greg finance.xlsx
[2010/01/10 16:20:29 | 00,015,960 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\greg finance.xlsx
[2010/01/10 14:55:25 | 00,284,915 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\gmer.zip
[2010/01/10 14:24:32 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 14:22:24 | 00,000,611 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\NTREGOPT.lnk
[2010/01/10 14:22:24 | 00,000,592 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\ERUNT.lnk
[2010/01/10 13:40:20 | 00,014,206 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\hijackthis1.10
[2010/01/10 13:20:32 | 00,001,988 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\HiJackThis.lnk
[2010/01/09 16:02:30 | 00,347,226 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Fall09 LR activities sign up.pdf
[2010/01/09 15:40:00 | 01,282,344 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Junior%20Egyptologist%20Final.pdf
[2010/01/07 14:16:41 | 00,237,441 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\att.pdf
[2010/01/07 14:16:30 | 00,237,441 | —- | C] () – C:\Documents and Settings\Kila_Hau\My Documents\ATT Alice Ct 12.2009.pdf
[2010/01/06 13:00:38 | 00,080,896 | —- | C] () – C:\WINDOWS\System32\ippnu.dll
[2010/01/06 12:45:05 | 00,000,867 | —- | C] () – C:\WINDOWS\Common.ini
[2010/01/03 16:29:16 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$TO DO Jan 2010.xlsx
[2010/01/03 16:29:15 | 00,019,410 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\TO DO Jan 2010.xlsx
[2010/01/02 19:58:10 | 00,358,603 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Lighting.docx
[2010/01/01 13:56:17 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$pression info.docx
[2009/12/22 16:38:34 | 00,024,127 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\note to bh.docx
[2009/12/22 16:38:34 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$te to bh.docx
[2009/12/21 11:59:01 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$ Shape Return 12.09.docx
[2009/12/21 11:59:00 | 00,404,591 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\My Shape Return 12.09.docx
[2009/11/01 10:07:54 | 00,012,800 | —- | C] () – C:\WINDOWS\System32\EKDeviceServices.dll
[2009/06/20 19:44:08 | 00,025,736 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/02/14 17:00:44 | 00,000,759 | —- | C] () – C:\Program Files\Picasa 3.lnk
[2008/12/13 14:57:00 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/11/05 20:04:57 | 00,008,192 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/13 08:19:06 | 00,037,532 | —- | C] () – C:\Documents and Settings\Kila_Hau\Application Data\Comma Separated Values (Windows).ADR
[2008/09/08 10:38:09 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/08/17 15:22:04 | 00,028,160 | —- | C] () – C:\WINDOWS\System32\sspdfpmd.dll
[2008/08/04 14:07:33 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2008/04/15 18:49:11 | 00,000,128 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\fusioncache.dat
[2008/04/13 22:56:11 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2008/04/13 22:54:44 | 00,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2008/04/13 22:54:12 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2008/04/13 22:54:12 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2008/04/13 22:54:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2008/04/13 22:54:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2008/04/13 22:54:12 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2008/04/13 22:54:12 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2008/04/13 22:53:18 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/04/13 22:48:01 | 00,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2008/03/19 11:35:05 | 00,000,233 | -H– | C] () – C:\WINDOWS\gvac.sys
[2008/02/05 12:28:20 | 00,000,051 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\setup.txt
[2007/09/27 09:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/01/12 16:09:14 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\DXFLib.dll
[2006/01/12 16:08:06 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\opcode.dll
[2006/01/06 05:58:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/01/06 05:24:32 | 00,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/01/06 05:17:52 | 00,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/01/05 12:38:40 | 00,000,800 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/01/05 11:16:49 | 00,000,762 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/11/01 19:53:38 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/06/12 13:21:12 | 00,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll
========== LOP Check ==========
[2009/07/06 10:54:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2009/03/14 21:25:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eastman Kodak Company
[2008/08/08 20:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2009/03/14 21:30:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2008/08/08 20:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Launcher
[2009/01/05 18:29:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/04/16 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NBC Direct
[2008/05/03 00:06:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers Headquarters
[2008/05/23 12:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/10/04 16:43:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2008/05/23 12:09:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/10/17 12:49:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/18 08:38:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/15 14:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2009/02/27 18:57:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2009/05/25 13:09:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Aptana
[2009/06/26 18:11:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\AT&T;
[2009/01/12 20:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Crayon Physics Deluxe
[2009/06/20 19:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\DBUpdater
[2009/04/16 19:48:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\IDM
[2008/07/13 13:32:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\InterVideo
[2008/07/20 11:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Leadertech
[2008/10/29 14:07:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\MechCAD
[2008/08/17 14:42:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\My CuteForm RunTime
[2010/01/11 13:31:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\NBC Direct
[2008/05/23 12:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\PlayFirst
[2009/06/20 19:37:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Sierra Wireless
[2008/09/16 11:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Uniblue
[2008/08/12 22:53:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Windows Desktop Search
[2008/08/19 18:13:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Windows Search
[2009/03/05 12:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\WinPatrol
[2009/12/27 10:01:08 | 00,000,442 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/01/11 23:29:27 | 00,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{A4258327-FEA4-40DE-88D7-9AF76047C84C}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1EA8A42
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A93060EC
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DB0B938
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:028E4554
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC4C6FB4
< End of report >