Alright, well, unfortunately, now the May 3 OTL fix you gave me (which would allow me to log on normally) is no longer working. I've tried it twice from the OTLpe CD-based environment. Again, this method/fix would change some settings and replace two files (userinit.exe and explorer.exe replacement) and it worked three separate times for me over the last week. But now, this fix is no longer working to straighten out the log-on/log-right-off problem. Here's the log (See **2** below) from that failed fix.
I also decided to go back and do another scan using the command list provided a few days ago that begins: /md5start
userinit.exe
explorer.exe
winlogon.exe
/md5stop
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
Here's that log:
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Session manager\\BootExecute:stera deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Session manager\\BootExecute:lsdelete deleted successfully.
File C:\WINDOWS\System32\wsaupdater.exe not found.
========== FILES ==========
File C:\WINDOWS\explorer.exe successfully replaced with C:\WINDOWS\ServicePackFiles\i386\explorer.exe
File C:\WINDOWS\SYSTEM32\USERINIT.EXE successfully replaced with C:\WINDOWS\ServicePackFiles\i386\userinit.exe
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\userinit.exe," /E : value set successfully!
OTLPE by OldTimer - Version 3.1.37.2 log created on 05082010_180655
**2** Begin here:
OTL logfile created on: 5/8/2010 8:24:20 PM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: | Country: | Language: | Date Format:
511.00 Mb Total Physical Memory | 264.00 Mb Available Physical Memory | 52.00% Memory free
459.00 Mb Paging File | 304.00 Mb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 22.41 Gb Free Space | 58.61% Space Free | Partition Type: NTFS
Drive D: | 981.05 Mb Total Space | 921.94 Mb Free Space | 93.97% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet003
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand] – – (TuneUp.Defrag)
SRV - File not found [On_Demand] – – (getPlus® Helper) getPlus®
SRV - File not found [Auto] – – (aawservice)
SRV - [2009/04/27 01:22:08 | 000,020,680 | —- | M] (ESET) [On_Demand] – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe – (EhttpSrv)
SRV - [2009/04/27 01:22:04 | 000,731,840 | —- | M] (ESET) [Auto] – C:\Program Files\ESET\ESET Smart Security\ekrn.exe – (ekrn)
SRV - [2008/07/26 08:25:36 | 000,150,040 | —- | M] (Logitech Inc.) [Auto] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2008/07/26 08:23:42 | 000,186,904 | —- | M] (Logitech Inc.) [Auto] – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer)
SRV - [2008/02/23 15:45:17 | 000,658,432 | —- | M] (Macrovision Europe Ltd.) [On_Demand] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2007/09/11 00:45:04 | 000,124,832 | —- | M] () [Auto] – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor6.0)
SRV - [2007/08/09 03:27:52 | 000,098,304 | —- | M] (HP) [Auto] – C:\WINDOWS\SYSTEM32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/03/07 16:47:46 | 000,076,848 | —- | M] () [On_Demand] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/01/04 17:38:08 | 000,024,576 | —- | M] (Viewpoint Corporation) [Disabled] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/04/27 14:59:24 | 000,266,240 | —- | M] (Microsoft Corporation) [Auto] – C:\Program Files\UPHClean\uphclean.exe – (UPHClean)
SRV - [2003/03/03 14:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (easdrv)
DRV - File not found [Kernel | System] – – (Changer)
DRV - File not found [Kernel | On_Demand] – – (catchme)
DRV - File not found [Kernel | On_Demand] – – (bvrp_pci)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Registry Filter)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Real-Time Scanner)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Connect Filter)
DRV - [2009/04/27 01:22:12 | 000,113,960 | —- | M] (ESET) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\eamon.sys – (eamon)
DRV - [2009/04/27 01:22:08 | 000,033,096 | —- | M] (ESET) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\epfwndis.sys – (Epfwndis)
DRV - [2009/04/27 01:22:04 | 000,131,976 | —- | M] (ESET) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\epfw.sys – (epfw)
DRV - [2009/04/27 01:22:04 | 000,055,768 | —- | M] (ESET) [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\epfwtdi.sys – (epfwtdi)
DRV - [2008/07/26 11:26:56 | 000,023,832 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys – (FilterService)
DRV - [2008/07/26 11:26:44 | 004,658,584 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys – (LVUVC) Logitech QuickCam S5500(UVC)
DRV - [2008/07/26 11:26:22 | 000,041,752 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys – (LVUSBSta)
DRV - [2008/07/26 11:25:48 | 000,627,864 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys – (LVRS)
DRV - [2008/07/26 08:25:02 | 000,025,624 | —- | M] () [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2008/05/02 22:46:00 | 006,554,496 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys – (nv)
DRV - [2008/04/13 14:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 14:40:58 | 000,042,112 | —- | M] () [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\imapi.sys – (Imapi)
DRV - [2008/04/13 14:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 14:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2007/04/23 14:11:54 | 000,224,896 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wg111v3.sys – (RTL8187B)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2005/02/23 14:58:56 | 000,011,776 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys – (Afc)
DRV - [2004/08/04 01:29:49 | 000,019,455 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys – (iAimFP4)
DRV - [2004/08/04 01:29:47 | 000,012,063 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys – (iAimFP3)
DRV - [2004/08/04 01:29:45 | 000,023,615 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys – (iAimTV4)
DRV - [2004/08/04 01:29:43 | 000,033,599 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys – (iAimTV3)
DRV - [2004/08/04 01:29:42 | 000,019,551 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys – (iAimTV1)
DRV - [2004/08/04 01:29:41 | 000,029,311 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys – (iAimTV0)
DRV - [2004/08/04 01:29:37 | 000,012,415 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys – (iAimFP0)
DRV - [2004/08/04 01:29:37 | 000,012,127 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys – (iAimFP1)
DRV - [2004/08/04 01:29:37 | 000,011,775 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys – (iAimFP2)
DRV - [2004/08/04 01:29:36 | 000,161,020 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys – (i81x)
DRV - [2003/08/29 04:59:24 | 001,101,696 | —- | M] (Broadcom Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys – (BCMModem)
DRV - [2003/08/06 02:04:00 | 000,100,373 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys – (tfsnudfa)
DRV - [2003/08/06 02:04:00 | 000,098,068 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys – (tfsnudf)
DRV - [2003/08/06 02:04:00 | 000,083,284 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys – (tfsnifs)
DRV - [2003/08/06 02:04:00 | 000,034,837 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys – (tfsncofs)
DRV - [2003/08/06 02:04:00 | 000,025,685 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys – (tfsnboio)
DRV - [2003/08/06 02:04:00 | 000,014,229 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys – (tfsnopio)
DRV - [2003/08/06 02:04:00 | 000,006,357 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys – (tfsnpool)
DRV - [2003/08/06 02:04:00 | 000,004,117 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys – (tfsndrct)
DRV - [2003/08/06 02:04:00 | 000,002,233 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys – (tfsndres)
DRV - [2003/07/31 04:21:00 | 000,084,576 | —- | M] (Sonic Solutions) [Kernel | Boot] – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys – (drvmcdb)
DRV - [2003/07/14 12:28:40 | 000,005,621 | —- | M] (Sonic Solutions) [File_System | System] – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys – (sscdbhk5)
DRV - [2003/07/14 12:28:22 | 000,023,219 | —- | M] (Sonic Solutions) [File_System | System] – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys – (ssrtln)
DRV - [2003/06/20 03:56:00 | 000,040,448 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys – (drvnddm)
DRV - [2002/11/08 14:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [2002/10/08 12:57:40 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:57:38 | 000,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys – (MODEMCSA)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/17 13:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS – (EL90XBC)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\Andrew_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\Cynthia_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/20 11:35:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 14:00:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/17 22:40:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/03 10:15:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/04/15 19:11:34 | 000,000,000 | —D | M]
[2010/04/08 16:42:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/03 10:15:11 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/06/03 01:27:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
[2009/07/20 11:35:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2010/04/03 10:14:45 | 000,023,000 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/04/03 10:14:45 | 000,138,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009/07/20 11:35:22 | 000,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2010/04/03 10:14:54 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2008/06/11 22:45:28 | 000,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2010/03/15 11:50:31 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/03/15 11:50:31 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/03/15 11:50:31 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/03/15 11:50:31 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/03/15 11:50:31 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/03/15 11:50:31 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/03/15 11:50:31 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2010/05/08 18:08:38 | 000,000,098 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
O1 - Hosts: 127.0.0.1 www.Brenz.pl
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKU\Andrew_ON_C\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKU\Andrew_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\SYSTEM32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\Andrew_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\Cynthia_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\LocalService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\NetworkService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - Startup: Error locating startup folders.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Administrator.KOUCHI_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\Andrew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Andrew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O7 - HKU\Cynthia_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Izabelle.KOUCHI_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\SYSTEM32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\SYSTEM32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\SYSTEM32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9}
http://download.microsoft.com/download/0/5…b?1076002397078 (MSSecurityAdvisor Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1120230108640 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\SYSTEM32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\SYSTEM32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\SYSTEM32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\SYSTEM32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\USERINIT.EXE (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\LOGONUI.EXE (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SYSTEM32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\SYSTEM32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\SYSTEM32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 14:36:02 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/05/06 00:58:13 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Andrew\Desktop\CMD.EXE
[2010/05/05 10:28:15 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/04/25 14:08:10 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
[2010/04/23 20:10:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Izabelle.KOUCHI\Cookies
[2010/04/23 19:24:25 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Cynthia\Cookies
[2010/04/23 19:12:33 | 000,000,000 | –SD | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Microsoft
[2010/04/23 19:12:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\SendTo
[2010/04/23 19:12:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Recent
[2010/04/23 19:12:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data
[2010/04/23 19:12:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Start Menu
[2010/04/23 19:12:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Izabelle.KOUCHI\My Documents
[2010/04/23 19:12:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Favorites
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Templates
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\PrintHood
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\NetHood
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Sun
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Sonic
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Real
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings\Application Data\Microsoft
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Macromedia
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Identities
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Desktop
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings\Application Data\ApplicationHistory
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/23 19:11:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\ESET
[2010/04/23 19:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Macromedia
[2010/04/23 19:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Identities
[2010/04/23 19:11:17 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Microsoft
[2010/04/23 19:11:17 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data
[2010/04/23 19:11:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator.KOUCHI\Favorites
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Sun
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Sonic
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Real
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Desktop
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\ApplicationHistory
[2010/04/23 19:11:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.KOUCHI\SendTo
[2010/04/23 19:11:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Recent
[2010/04/23 19:11:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator.KOUCHI\Start Menu
[2010/04/23 19:11:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator.KOUCHI\My Documents
[2010/04/23 19:11:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\PrintHood
[2010/04/23 19:11:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\NetHood
[2010/04/23 19:11:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings
[2010/04/23 19:11:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\Microsoft
[2010/04/23 19:11:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/23 19:11:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Templates
[2010/04/20 19:48:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/04/18 09:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Mozilla
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Mozilla
[2010/04/17 22:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Malwarebytes
[2010/04/17 22:38:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\GTek
[2010/04/17 18:55:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\NetworkService\Cookies
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Macromedia
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Identities
[2010/04/17 18:47:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\Cynthia\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\SendTo
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Recent
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Application Data
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Start Menu
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Pictures
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Music
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Favorites
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Templates
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\PrintHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\NetHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Local Settings
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sun
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sonic
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Real
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Desktop
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\ApplicationHistory
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Utilities
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Unused Desktop Shortcuts
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\TomAdamczyk
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\The Letter
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\SeacoastOrientalRugEnvlogo
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\sallie
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\R. conley
[2010/04/17 18:45:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\PPS Files
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\patti
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\P. Montrone
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Nilsson
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\m
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Kremans
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\joe
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Izabelle's 8th Bday & jumping Pandy 07 054
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Humor
[2010/04/17 18:45:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Hide These Temp
[2010/04/17 18:45:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\elena
[2010/04/17 18:44:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\My Documents\Advanta_files
[2010/04/17 18:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Share-to-Web Upload Folder
[2010/04/17 18:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ESET
[2010/04/17 18:36:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010/04/17 18:16:56 | 000,000,000 | —D | C] – C:\~ErdUserProfile.$$$
[2010/04/17 17:58:17 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Andrew\Cookies
[2010/04/17 17:58:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/04/17 17:57:47 | 000,000,000 | –SD | C] – C:\Documents and Settings\Andrew\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\SendTo
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Recent
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Application Data
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Start Menu
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Pictures
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Music
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Favorites
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Templates
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\PrintHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\NetHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Local Settings
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sun
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sonic
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Real
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Macromedia
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Identities
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ApplicationHistory
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 17:57:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\LocalService\Cookies
[2010/04/17 17:57:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\LocalService\Local Settings
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data
[2010/04/17 17:57:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | -H-D | C] – C:\Documents and Settings\NetworkService\Local Settings
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data
[2010/04/17 04:35:31 | 000,000,000 | -H-D | C] – C:\ErdUndoCache
[2010/04/15 19:32:45 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2010/04/15 19:15:47 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2010/04/15 17:58:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/12 23:40:08 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/12 22:57:38 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/12 22:36:43 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/12 22:33:20 | 000,033,280 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/12 08:26:57 | 000,000,000 | —D | C] – C:\OEMSettings
[2010/04/12 08:25:41 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2010/04/11 23:24:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 23:24:01 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 23:23:59 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/10 14:18:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/10 14:18:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/10 14:18:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/10 14:18:34 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/10 14:16:49 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/09 07:21:46 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/04/09 06:59:38 | 000,000,000 | —D | C] – C:\Infection
[2005/05/11 23:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
========== Files - Modified Within 30 Days ==========
[2010/05/08 18:12:55 | 000,786,432 | -H– | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/05/08 18:12:55 | 000,786,432 | -H– | M] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/05/08 18:12:53 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/05/08 18:12:33 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/08 18:12:23 | 001,048,576 | -H– | M] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/05/08 18:12:23 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/05/08 18:12:15 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/08 18:12:15 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/05/08 18:12:15 | 000,000,314 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/05/08 18:08:38 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\Hosts
[2010/05/08 18:08:25 | 535,891,968 | -HS- | M] () – C:\hiberfil.sys
[2010/05/08 18:07:12 | 000,262,144 | -H– | M] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.dat
[2010/05/08 15:24:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
[2010/05/08 14:39:31 | 000,786,432 | -H– | M] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/05/07 07:49:19 | 004,840,552 | -H– | M] () – C:\Documents and Settings\Andrew\Local Settings\Application Data\IconCache.db
[2010/05/07 07:46:06 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/05/07 03:30:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/05 10:24:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/23 20:13:11 | 000,262,144 | -H– | M] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.dat
[2010/04/23 19:33:59 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/23 19:12:37 | 000,000,020 | -HS- | M] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.ini
[2010/04/23 19:11:34 | 000,000,020 | -HS- | M] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.ini
[2010/04/17 18:38:47 | 000,000,104 | —- | M] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:07:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/15 19:06:24 | 000,182,038 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/15 18:28:48 | 000,001,964 | —- | M] () – C:\WINDOWS\disney.ini
[2010/04/14 18:31:58 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/14 18:14:01 | 000,000,292 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/12 22:36:56 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/04/09 17:14:00 | 000,000,749 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/04/09 17:14:00 | 000,000,211 | —- | M] () – C:\Boot.bak
========== Files Created - No Company Name ==========
[2010/05/07 07:45:09 | 535,891,968 | -HS- | C] () – C:\hiberfil.sys
[2010/04/23 19:12:37 | 000,008,192 | -H– | C] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.dat.LOG
[2010/04/23 19:12:37 | 000,000,020 | -HS- | C] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.ini
[2010/04/23 19:12:33 | 000,262,144 | -H– | C] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.dat
[2010/04/23 19:11:34 | 000,000,020 | -HS- | C] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.ini
[2010/04/23 19:11:30 | 000,020,480 | -H– | C] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.dat.LOG
[2010/04/23 19:11:15 | 000,262,144 | -H– | C] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.dat
[2010/04/17 18:47:41 | 000,786,432 | -H– | C] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/17 18:47:41 | 000,008,192 | -H– | C] () – C:\Documents and Settings\Cynthia\ntuser.dat.LOG
[2010/04/17 18:47:41 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/17 18:44:34 | 002,392,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Ey Iran.pps
[2010/04/17 18:44:34 | 000,728,850 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ISLAMICOSCARGOESTO.wmv
[2010/04/17 18:44:34 | 000,460,690 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Cash002.zip
[2010/04/17 18:44:34 | 000,455,999 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Heriz ka.pdf
[2010/04/17 18:44:34 | 000,301,056 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ANDREWSLIST.xls
[2010/04/17 18:44:34 | 000,226,340 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Andrewslist.123
[2010/04/17 18:44:34 | 000,068,096 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Invoice.doc
[2010/04/17 18:44:34 | 000,025,600 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Gift Certificate.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Espacio Design 4.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Appraisal letter March 30.doc
[2010/04/17 18:44:34 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ITALIAN.doc
[2010/04/17 18:44:34 | 000,000,794 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Bidjar 11.7 X18.9.lnk
[2010/04/17 18:44:34 | 000,000,761 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Get High Speed Internet!.lnk
[2010/04/17 18:44:33 | 000,486,272 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Speedsters.jpg
[2010/04/17 18:44:33 | 000,438,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Vahid.zip
[2010/04/17 18:44:33 | 000,430,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\123.pps
[2010/04/17 18:44:33 | 000,383,424 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\2008 Tagavi A Form 1040 Individual Tax Return.tax2008
[2010/04/17 18:44:33 | 000,227,684 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\5.5 X 7.9.JPG
[2010/04/17 18:44:33 | 000,154,870 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\AhundovFamilyTree.zip
[2010/04/17 18:44:33 | 000,122,300 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Setade_Koodeta.pdf
[2010/04/17 18:44:33 | 000,092,672 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\rug cleaning certificate.doc
[2010/04/17 18:44:33 | 000,077,062 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\SeacoastOrientalRugEnvlogo.zip
[2010/04/17 18:44:33 | 000,060,587 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\pelosinowruzletter_3.08.pdf
[2010/04/17 18:44:33 | 000,050,176 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\warm up certificate.doc
[2010/04/17 18:44:33 | 000,040,960 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\saddle fitting.doc
[2010/04/17 18:44:33 | 000,034,775 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\LtrtoclientwithdraftlettertoAttyMiller9-6-07.wpd.zip
[2010/04/17 18:44:33 | 000,029,184 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News.doc
[2010/04/17 18:44:33 | 000,026,624 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News #3 2nd edition.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Taylor.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\seacoast media.doc
[2010/04/17 18:44:33 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tonry.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\TUFTED.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted rugs.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted 2.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Sale.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\sale sideways.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Persian.doc
[2010/04/17 18:44:33 | 000,022,090 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Advanta.htm
[2010/04/17 18:44:33 | 000,020,992 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\nicker news3.doc
[2010/04/17 18:44:33 | 000,004,017 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\OrientalRugLogo-Letterhead.htm
[2010/04/17 18:44:33 | 000,000,440 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Shortcut to Vendors.lnk
[2010/04/17 18:38:47 | 000,000,104 | —- | C] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:01:18 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/04/17 17:57:47 | 000,012,288 | -H– | C] () – C:\Documents and Settings\Andrew\ntuser.dat.LOG
[2010/04/17 17:57:47 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/04/17 17:57:46 | 001,048,576 | -H– | C] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/04/17 17:57:40 | 000,786,432 | -H– | C] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/04/17 17:57:40 | 000,008,192 | -H– | C] () – C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2010/04/17 17:57:40 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\LocalService\NTUSER.INI
[2010/04/17 17:57:37 | 000,008,192 | -H– | C] () – C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2010/04/17 17:57:37 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\NetworkService\NTUSER.INI
[2010/04/17 17:57:36 | 000,786,432 | -H– | C] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/04/16 13:34:24 | 000,262,144 | —- | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NtUser.dat.bartbackup1
[2010/04/15 19:15:53 | 000,000,314 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/12 22:36:55 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/04/12 22:36:48 | 000,260,272 | —- | C] () – C:\cmldr
[2010/04/10 14:18:54 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/10 14:18:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/10 14:18:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/10 14:18:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/10 14:18:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/05 15:04:51 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/06/17 10:32:47 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/05/02 22:46:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/02 22:46:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/02 22:46:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/02 22:46:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/02 22:46:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/14 20:15:10 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/08/01 14:13:44 | 000,000,344 | —- | C] () – C:\WINDOWS\QTW.INI
[2007/06/08 12:28:18 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/06/08 12:27:56 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/06/08 12:23:33 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/03/05 14:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/28 15:36:44 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/09/18 14:56:55 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2005/06/30 10:17:00 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/04/13 11:38:24 | 000,004,560 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/18 12:20:46 | 000,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/11/18 12:11:29 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/11/18 12:11:28 | 000,000,365 | —- | C] () – C:\WINDOWS\upst.ini
[2004/10/30 15:14:45 | 000,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2004/08/24 13:39:18 | 000,000,844 | —- | C] () – C:\WINDOWS\hegames.ini
[2004/08/24 13:39:14 | 000,000,080 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2004/08/07 15:31:23 | 000,000,024 | —- | C] () – C:\WINDOWS\RVBOOK.INI
[2004/01/23 11:29:51 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2004/01/23 11:25:39 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2003/12/29 11:42:06 | 000,001,964 | —- | C] () – C:\WINDOWS\disney.ini
[2003/12/05 17:22:04 | 000,000,293 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/11/01 16:42:01 | 000,000,174 | —- | C] () – C:\WINDOWS\System32\mcini.ini
[2003/10/29 17:31:35 | 000,000,024 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/10/23 03:48:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/10/23 03:46:15 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/10/23 03:35:08 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/10/23 03:19:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/23 03:19:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/10/23 03:15:39 | 000,262,144 | —- | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\ntuser.dat
[2003/10/23 03:15:39 | 000,008,192 | -H– | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
[2003/10/23 03:07:02 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:13:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 000,042,112 | —- | C] () – C:\WINDOWS\System32\drivers\imapi.sys
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1980/01/01 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2010/05/08 18:12:15 | 000,000,488 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010/05/08 18:12:15 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=B4EF006490A143E26E473F3C435C5E5A – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: USERINIT.EXE >
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=3833FA6B1774DDCAC290CE0643CFCD1B – C:\_OTL\MovedFiles\04202010_194810\C_\userinit.exe
[2004/08/04 03:56:57 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=F0A69B52B47DAC98323C915EF24521DD – C:\WINDOWS\SYSTEM32\USERINIT.EXE
< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002/08/29 06:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe
< HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit >
< End of report >
And here's the Extras.txt log:
OTL Extras logfile created on: 5/8/2010 8:24:20 PM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: | Country: | Language: | Date Format:
511.00 Mb Total Physical Memory | 264.00 Mb Available Physical Memory | 52.00% Memory free
459.00 Mb Paging File | 304.00 Mb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 22.41 Gb Free Space | 58.61% Space Free | Partition Type: NTFS
Drive D: | 981.05 Mb Total Space | 921.94 Mb Free Space | 93.97% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet003
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\]
.exe [@ = secfile] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"" =
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"" =
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"" =
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Real\RealPlayer\trueplay.exe" = C:\Program Files\Real\RealPlayer\trueplay.exe:*:Disabled:RealOne Player – (RealNetworks, Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – File not found
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – File not found
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – File not found
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – (Skype Technologies)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:\WINDOWS\SYSTEM32\spoolsv.exe" = C:\WINDOWS\SYSTEM32\spoolsv.exe:*:Enabled:spoolsv – (Microsoft Corporation)
"\??\C:\WINDOWS\system32\winlogon.exe" = \??\C:\WINDOWS\system32\winlogon.exe:*:enabled:@shell32.dll,-1 – (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{00F0588F-5F9C-4661-84E0-176790BDF709}" = ESET Smart Security
"{0143CF89-5CF2-4F2D-80D5-BFAE64E1BA00}" = Media Wizard 3.0
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{06230E02-2B7E-11D2-92D0-0040051BD005}" = OLYMPUS CAMEDIA Master 2.5
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{410438A3-B591-4028-B70A-3CC0B33FBCD1}" =
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = Sonic MyDVD
"{60859BF2-5151-473C-8F76-7F3A232CF7E7}" = MM Number Heroes
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{64658686-0CD4-4CF6-983D-0A6BE32007DB}" = Business Complete Care Services Agreement
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70C002F0-5308-42D8-A65A-91436B90255C}" = MakeAMov
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AEAEEAD6-38EC-4321-92A7-599367E21FF2}" = Rosetta Stone V3 DEMO
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}" = Google Talk Plugin
"{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus®
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DD2F0FE7-A3FD-45AE-92A6-DA46166B3158}" = Find Rugs
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF6F70D0-C242-4047-946B-98EA8208481A}" = ArcSoft TotalMedia Backup & Record
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}" = QuickTime
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"102 Dalmatians Activity Center" = 102 Dalmatians Activity Center
"ACDSee" = ACDSee
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0
"AOL Toolbar 5.0" =
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Excel Invoice Manager_is1" = Excel Invoice Manager 2.12.1016
"Full Speed2.1" = Full Speed
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"InstallShield_{70C002F0-5308-42D8-A65A-91436B90255C}" = Make a Movie
"InstallShield_{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"InstallShield_{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"InterActual Player" = InterActual Player
"Knowmad" = Knowmad
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetAlyzer_is1" = NetAlyzer 0.3
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealOne Player
"Revo Uninstaller" = Revo Uninstaller 1.85
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"The ClueFinders Reading Adventures Ages 9-12" = The ClueFinders Reading Adventures Ages 9-12
"TS2AC" = Toy Story 2 Activity Center
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0
< End of report >
And, here is another OTL full scan log below that in anticipation that this would be requested next. And, maybe it's not but I thought I'd try to move ahead.
This is a full OTL scan without any extra commands:
OTL logfile created on: 5/8/2010 2:32:51 PM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: | Country: | Language: | Date Format:
511.00 Mb Total Physical Memory | 254.00 Mb Available Physical Memory | 50.00% Memory free
459.00 Mb Paging File | 305.00 Mb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 22.44 Gb Free Space | 58.69% Space Free | Partition Type: NTFS
Drive D: | 981.05 Mb Total Space | 922.18 Mb Free Space | 94.00% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
Using ControlSet: ControlSet003
========== Win32 Services (SafeList) ==========
SRV - (TuneUp.Defrag) – File not found
SRV - (getPlus® Helper) getPlus® – File not found
SRV - (aawservice) – File not found
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AdobeActiveFileMonitor6.0) – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (easdrv) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – File not found
DRV - (bvrp_pci) – File not found
DRV - (Ad-Watch Registry Filter) – File not found
DRV - (Ad-Watch Real-Time Scanner) – File not found
DRV - (Ad-Watch Connect Filter) – File not found
DRV - (eamon) – C:\WINDOWS\SYSTEM32\DRIVERS\eamon.sys (ESET)
DRV - (Epfwndis) – C:\WINDOWS\SYSTEM32\DRIVERS\epfwndis.sys (ESET)
DRV - (epfw) – C:\WINDOWS\SYSTEM32\DRIVERS\epfw.sys (ESET)
DRV - (epfwtdi) – C:\WINDOWS\SYSTEM32\DRIVERS\epfwtdi.sys (ESET)
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam S5500(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys (Microsoft Corporation)
DRV - (Imapi) – C:\WINDOWS\SYSTEM32\DRIVERS\imapi.sys ()
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (RTL8187B) – C:\WINDOWS\SYSTEM32\DRIVERS\wg111v3.sys (Realtek Semiconductor Corporation )
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Afc) – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys (Arcsoft, Inc.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\Andrew_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\Cynthia_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/20 11:35:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 14:00:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/17 22:40:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/03 10:15:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/04/15 19:11:34 | 000,000,000 | —D | M]
[2010/04/08 16:42:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/03 10:15:11 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/06/03 01:27:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
[2009/07/20 11:35:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2010/04/03 10:14:45 | 000,023,000 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/04/03 10:14:45 | 000,138,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009/07/20 11:35:22 | 000,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2010/04/03 10:14:54 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2008/06/11 22:45:28 | 000,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2010/03/15 11:50:31 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/03/15 11:50:31 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/03/15 11:50:31 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/03/15 11:50:31 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/03/15 11:50:31 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/03/15 11:50:31 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/03/15 11:50:31 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2010/05/08 14:31:16 | 000,000,098 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKU\Andrew_ON_C\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKU\Andrew_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\SYSTEM32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\Andrew_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\Cynthia_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\LocalService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\NetworkService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - Startup: Error locating startup folders.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Administrator.KOUCHI_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\Andrew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Andrew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O7 - HKU\Cynthia_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Izabelle.KOUCHI_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\SYSTEM32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\SYSTEM32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\SYSTEM32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9}
http://download.microsoft.com/download/0/5…b?1076002397078 (MSSecurityAdvisor Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1120230108640 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\SYSTEM32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\SYSTEM32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\SYSTEM32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\SYSTEM32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\USERINIT.EXE (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\LOGONUI.EXE (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SYSTEM32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\SYSTEM32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\SYSTEM32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 14:36:02 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/05/06 00:58:13 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Andrew\Desktop\CMD.EXE
[2010/05/05 10:28:15 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/04/25 14:08:10 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
[2010/04/23 20:10:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Izabelle.KOUCHI\Cookies
[2010/04/23 19:24:25 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Cynthia\Cookies
[2010/04/23 19:12:33 | 000,000,000 | –SD | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Microsoft
[2010/04/23 19:12:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\SendTo
[2010/04/23 19:12:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Recent
[2010/04/23 19:12:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data
[2010/04/23 19:12:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Start Menu
[2010/04/23 19:12:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Izabelle.KOUCHI\My Documents
[2010/04/23 19:12:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Favorites
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Templates
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\PrintHood
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\NetHood
[2010/04/23 19:12:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Sun
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Sonic
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Real
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings\Application Data\Microsoft
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Macromedia
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Application Data\Identities
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Desktop
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings\Application Data\ApplicationHistory
[2010/04/23 19:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Izabelle.KOUCHI\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/23 19:11:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\ESET
[2010/04/23 19:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Macromedia
[2010/04/23 19:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Identities
[2010/04/23 19:11:17 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Microsoft
[2010/04/23 19:11:17 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data
[2010/04/23 19:11:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator.KOUCHI\Favorites
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Sun
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Sonic
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Application Data\Real
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Desktop
[2010/04/23 19:11:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\ApplicationHistory
[2010/04/23 19:11:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.KOUCHI\SendTo
[2010/04/23 19:11:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Recent
[2010/04/23 19:11:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator.KOUCHI\Start Menu
[2010/04/23 19:11:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator.KOUCHI\My Documents
[2010/04/23 19:11:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\PrintHood
[2010/04/23 19:11:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\NetHood
[2010/04/23 19:11:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings
[2010/04/23 19:11:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\Microsoft
[2010/04/23 19:11:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.KOUCHI\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/23 19:11:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.KOUCHI\Templates
[2010/04/20 19:48:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/04/18 09:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Mozilla
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Mozilla
[2010/04/17 22:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Malwarebytes
[2010/04/17 22:38:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\GTek
[2010/04/17 18:55:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\NetworkService\Cookies
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Macromedia
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Identities
[2010/04/17 18:47:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\Cynthia\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\SendTo
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Recent
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Application Data
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Start Menu
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Pictures
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Music
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Favorites
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Templates
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\PrintHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\NetHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Local Settings
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sun
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sonic
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Real
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Desktop
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\ApplicationHistory
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Utilities
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Unused Desktop Shortcuts
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\TomAdamczyk
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\The Letter
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\SeacoastOrientalRugEnvlogo
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\sallie
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\R. conley
[2010/04/17 18:45:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\PPS Files
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\patti
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\P. Montrone
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Nilsson
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\m
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Kremans
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\joe
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Izabelle's 8th Bday & jumping Pandy 07 054
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Humor
[2010/04/17 18:45:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Hide These Temp
[2010/04/17 18:45:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\elena
[2010/04/17 18:44:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\My Documents\Advanta_files
[2010/04/17 18:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Share-to-Web Upload Folder
[2010/04/17 18:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ESET
[2010/04/17 18:36:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010/04/17 18:16:56 | 000,000,000 | —D | C] – C:\~ErdUserProfile.$$$
[2010/04/17 17:58:17 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Andrew\Cookies
[2010/04/17 17:58:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/04/17 17:57:47 | 000,000,000 | –SD | C] – C:\Documents and Settings\Andrew\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\SendTo
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Recent
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Application Data
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Start Menu
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Pictures
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Music
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Favorites
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Templates
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\PrintHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\NetHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Local Settings
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sun
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sonic
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Real
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Macromedia
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Identities
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ApplicationHistory
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 17:57:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\LocalService\Cookies
[2010/04/17 17:57:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\LocalService\Local Settings
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data
[2010/04/17 17:57:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | -H-D | C] – C:\Documents and Settings\NetworkService\Local Settings
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data
[2010/04/17 04:35:31 | 000,000,000 | -H-D | C] – C:\ErdUndoCache
[2010/04/15 19:32:45 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2010/04/15 19:15:47 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2010/04/15 17:58:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/12 23:40:08 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/12 22:57:38 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/12 22:36:43 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/12 22:33:20 | 000,033,280 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/12 08:26:57 | 000,000,000 | —D | C] – C:\OEMSettings
[2010/04/12 08:25:41 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2010/04/11 23:24:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 23:24:01 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 23:23:59 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/10 14:18:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/10 14:18:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/10 14:18:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/10 14:18:34 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/10 14:16:49 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/09 07:21:46 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/04/09 06:59:38 | 000,000,000 | —D | C] – C:\Infection
[2005/05/11 23:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
========== Files - Modified Within 30 Days ==========
[2010/05/08 14:31:16 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\Hosts
[2010/05/07 17:41:48 | 000,786,432 | -H– | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/05/07 17:41:48 | 000,786,432 | -H– | M] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/05/07 17:41:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/05/07 17:41:09 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/07 17:41:09 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/07 17:41:02 | 535,891,968 | -HS- | M] () – C:\hiberfil.sys
[2010/05/07 12:26:49 | 000,262,144 | -H– | M] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.dat
[2010/05/07 07:49:24 | 001,048,576 | -H– | M] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/05/07 07:49:24 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/05/07 07:49:19 | 004,840,552 | -H– | M] () – C:\Documents and Settings\Andrew\Local Settings\Application Data\IconCache.db
[2010/05/07 07:46:06 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/05/07 07:45:20 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/05/07 07:45:19 | 000,000,314 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/05/07 03:30:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/07 03:24:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
[2010/05/05 10:24:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/23 20:13:11 | 000,262,144 | -H– | M] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.dat
[2010/04/23 19:33:59 | 000,786,432 | -H– | M] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/23 19:33:59 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/23 19:12:37 | 000,000,020 | -HS- | M] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.ini
[2010/04/23 19:11:34 | 000,000,020 | -HS- | M] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.ini
[2010/04/17 18:38:47 | 000,000,104 | —- | M] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:07:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/15 19:06:24 | 000,182,038 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/15 18:28:48 | 000,001,964 | —- | M] () – C:\WINDOWS\disney.ini
[2010/04/14 18:31:58 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/14 18:14:01 | 000,000,292 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/12 22:36:56 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/04/09 17:14:00 | 000,000,749 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/04/09 17:14:00 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/04/08 20:17:45 | 000,000,882 | —- | M] () – C:\WINDOWS\orun32.ini
========== Files Created - No Company Name ==========
[2010/05/07 07:45:09 | 535,891,968 | -HS- | C] () – C:\hiberfil.sys
[2010/04/23 19:12:37 | 000,008,192 | -H– | C] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.dat.LOG
[2010/04/23 19:12:37 | 000,000,020 | -HS- | C] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.ini
[2010/04/23 19:12:33 | 000,262,144 | -H– | C] () – C:\Documents and Settings\Izabelle.KOUCHI\ntuser.dat
[2010/04/23 19:11:34 | 000,000,020 | -HS- | C] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.ini
[2010/04/23 19:11:30 | 000,020,480 | -H– | C] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.dat.LOG
[2010/04/23 19:11:15 | 000,262,144 | -H– | C] () – C:\Documents and Settings\Administrator.KOUCHI\ntuser.dat
[2010/04/17 18:47:41 | 000,786,432 | -H– | C] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/17 18:47:41 | 000,020,480 | -H– | C] () – C:\Documents and Settings\Cynthia\ntuser.dat.LOG
[2010/04/17 18:47:41 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/17 18:44:34 | 002,392,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Ey Iran.pps
[2010/04/17 18:44:34 | 000,728,850 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ISLAMICOSCARGOESTO.wmv
[2010/04/17 18:44:34 | 000,460,690 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Cash002.zip
[2010/04/17 18:44:34 | 000,455,999 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Heriz ka.pdf
[2010/04/17 18:44:34 | 000,301,056 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ANDREWSLIST.xls
[2010/04/17 18:44:34 | 000,226,340 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Andrewslist.123
[2010/04/17 18:44:34 | 000,068,096 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Invoice.doc
[2010/04/17 18:44:34 | 000,025,600 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Gift Certificate.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Espacio Design 4.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Appraisal letter March 30.doc
[2010/04/17 18:44:34 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ITALIAN.doc
[2010/04/17 18:44:34 | 000,000,794 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Bidjar 11.7 X18.9.lnk
[2010/04/17 18:44:34 | 000,000,761 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Get High Speed Internet!.lnk
[2010/04/17 18:44:33 | 000,486,272 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Speedsters.jpg
[2010/04/17 18:44:33 | 000,438,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Vahid.zip
[2010/04/17 18:44:33 | 000,430,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\123.pps
[2010/04/17 18:44:33 | 000,383,424 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\2008 Tagavi A Form 1040 Individual Tax Return.tax2008
[2010/04/17 18:44:33 | 000,227,684 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\5.5 X 7.9.JPG
[2010/04/17 18:44:33 | 000,154,870 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\AhundovFamilyTree.zip
[2010/04/17 18:44:33 | 000,122,300 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Setade_Koodeta.pdf
[2010/04/17 18:44:33 | 000,092,672 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\rug cleaning certificate.doc
[2010/04/17 18:44:33 | 000,077,062 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\SeacoastOrientalRugEnvlogo.zip
[2010/04/17 18:44:33 | 000,060,587 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\pelosinowruzletter_3.08.pdf
[2010/04/17 18:44:33 | 000,050,176 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\warm up certificate.doc
[2010/04/17 18:44:33 | 000,040,960 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\saddle fitting.doc
[2010/04/17 18:44:33 | 000,034,775 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\LtrtoclientwithdraftlettertoAttyMiller9-6-07.wpd.zip
[2010/04/17 18:44:33 | 000,029,184 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News.doc
[2010/04/17 18:44:33 | 000,026,624 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News #3 2nd edition.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Taylor.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\seacoast media.doc
[2010/04/17 18:44:33 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tonry.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\TUFTED.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted rugs.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted 2.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Sale.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\sale sideways.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Persian.doc
[2010/04/17 18:44:33 | 000,022,090 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Advanta.htm
[2010/04/17 18:44:33 | 000,020,992 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\nicker news3.doc
[2010/04/17 18:44:33 | 000,004,017 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\OrientalRugLogo-Letterhead.htm
[2010/04/17 18:44:33 | 000,000,440 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Shortcut to Vendors.lnk
[2010/04/17 18:38:47 | 000,000,104 | —- | C] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:01:18 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/04/17 17:57:47 | 000,028,672 | -H– | C] () – C:\Documents and Settings\Andrew\ntuser.dat.LOG
[2010/04/17 17:57:47 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/04/17 17:57:46 | 001,048,576 | -H– | C] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/04/17 17:57:40 | 000,786,432 | -H– | C] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/04/17 17:57:40 | 000,024,576 | -H– | C] () – C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2010/04/17 17:57:40 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\LocalService\NTUSER.INI
[2010/04/17 17:57:37 | 000,024,576 | -H– | C] () – C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2010/04/17 17:57:37 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\NetworkService\NTUSER.INI
[2010/04/17 17:57:36 | 000,786,432 | -H– | C] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/04/16 13:34:24 | 000,262,144 | —- | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NtUser.dat.bartbackup1
[2010/04/15 19:15:53 | 000,000,314 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/12 22:36:55 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/04/12 22:36:48 | 000,260,272 | —- | C] () – C:\cmldr
[2010/04/10 14:18:54 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/10 14:18:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/10 14:18:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/10 14:18:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/10 14:18:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/05 15:04:51 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/06/17 10:32:47 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/05/02 22:46:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/02 22:46:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/02 22:46:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/02 22:46:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/02 22:46:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/14 20:15:10 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/08/01 14:13:44 | 000,000,344 | —- | C] () – C:\WINDOWS\QTW.INI
[2007/06/08 12:28:18 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/06/08 12:27:56 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/06/08 12:23:33 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/03/05 14:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/28 15:36:44 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/09/18 14:56:55 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2005/06/30 10:17:00 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/04/13 11:38:24 | 000,004,560 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/18 12:20:46 | 000,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/11/18 12:11:29 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/11/18 12:11:28 | 000,000,365 | —- | C] () – C:\WINDOWS\upst.ini
[2004/10/30 15:14:45 | 000,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2004/08/24 13:39:18 | 000,000,844 | —- | C] () – C:\WINDOWS\hegames.ini
[2004/08/24 13:39:14 | 000,000,080 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2004/08/07 15:31:23 | 000,000,024 | —- | C] () – C:\WINDOWS\RVBOOK.INI
[2004/01/23 11:29:51 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2004/01/23 11:25:39 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2003/12/29 11:42:06 | 000,001,964 | —- | C] () – C:\WINDOWS\disney.ini
[2003/12/05 17:22:04 | 000,000,293 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/11/01 16:42:01 | 000,000,174 | —- | C] () – C:\WINDOWS\System32\mcini.ini
[2003/10/29 17:31:35 | 000,000,024 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/10/23 03:48:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/10/23 03:46:15 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/10/23 03:35:08 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/10/23 03:19:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/23 03:19:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/10/23 03:15:39 | 000,262,144 | —- | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\ntuser.dat
[2003/10/23 03:15:39 | 000,008,192 | -H– | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
[2003/10/23 03:07:02 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:13:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 000,042,112 | —- | C] () – C:\WINDOWS\System32\drivers\imapi.sys
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1980/01/01 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2010/05/07 07:45:20 | 000,000,488 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010/05/07 07:45:19 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
< End of report >
I've left the system sitting on Reatogo's PE. Since it takes forever to load up, I'm guessing we'll use Reatogo next.
Standing by…
H