thanks for such a quick reply and assisting me through this.
ok here is the OTL log
OTL.txt first
OTL logfile created on: 6/04/2011 3:04:49 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Alessandra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.95 Gb Total Space | 169.71 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 3.67 Gb Free Space | 36.72% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 261.59 Gb Free Space | 87.76% Space Free | Partition Type: NTFS
Computer Name: ALESSANDRA-PC | User Name: Alessandra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Alessandra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe ()
PRC - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - C:\Program Files\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Windows\System32\drivers\ACFXAU32.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Users\Alessandra\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll ()
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (mi-raysat_3dsmax2011_32) – C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (FAService) – C:\Program Files\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (Adobe Version Cue CS4) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (XAudioService) – C:\Windows\System32\drivers\ACFXAU32.exe (Conexant Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKsla30762e3) – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D62022C1-AF51-403B-8475-31D9F31255C0}\MpKsla30762e3.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (FACAP) – C:\Windows\System32\drivers\facap.sys (Sensible Vision )
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (k57nd60x) Broadcom NetLink ™ – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\ACFXAU32.sys (Conexant Systems, Inc.)
DRV - (acfva) – C:\Windows\System32\drivers\ACFVA32.sys (Conexant Systems Inc.)
DRV - (dgcfltr) – C:\Windows\System32\drivers\ACFDCP32.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\ACFSDK32.sys (Conexant)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.shareware.pro/?lang=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/02/14 16:39:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/03/15 21:15:50 | 000,000,000 | —D | M]
O1 HOSTS File: ([2010/05/19 13:07:12 | 000,000,089 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - C:\Program Files\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] C:\Program Files\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [k70ccreloc.exe] C:\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\k70ccreloc.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: latrobe.edu.au ([owa] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\FastAccess: DllName - C:\Program Files\Sensible Vision\Fast Access\FALogNot.dll - C:\Program Files\Sensible Vision\Fast Access\FALogNot.dll ()
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Alessandra\Pictures\2010 painting studies\IMG_0105.JPG
O24 - Desktop BackupWallPaper: C:\Users\Alessandra\Pictures\2010 painting studies\IMG_0105.JPG
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/18 15:18:07 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2006/09/19 07:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/02/02 21:37:32 | 000,000,000 | RH-D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/17 12:56:50 | 000,000,036 | RH– | M] () - F:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/04/06 14:58:58 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Alessandra\Desktop\OTL.exe
[2011/04/06 00:13:22 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Local\Adobe
[2011/04/05 23:04:00 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547
[2011/03/24 16:16:39 | 000,000,000 | —D | C] – C:\Users\Alessandra\Documents\jobs
[2011/03/24 07:43:31 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/24 07:43:31 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/21 11:11:51 | 000,000,000 | —D | C] – C:\Users\Alessandra\Documents\edx
[2011/03/15 21:15:04 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2011/03/15 21:15:04 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/03/15 21:14:49 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Roaming\HpUpdate
[2011/03/15 21:14:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2011/03/15 21:12:41 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2011/03/15 21:12:24 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/03/15 21:11:32 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Local\HP
[2011/03/15 21:10:08 | 000,213,864 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpinkcoi8711.dll
[2011/03/15 21:10:07 | 000,267,112 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpinksts8711LM.dll
[2011/03/15 21:09:40 | 001,792,872 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\HPScanMiniDrv_DJ2050_510g.dll
[2011/03/15 20:43:29 | 000,000,000 | —D | C] – C:\Users\Alessandra\Documents\fonts
[2011/03/13 19:36:26 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/13 19:36:25 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/13 19:36:25 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/13 19:36:25 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2009/08/05 13:17:21 | 008,653,312 | —- | C] (Dell, Inc. ) – C:\Users\Alessandra\AppData\Roaming\DataSafeDotNet.exe
========== Files - Modified Within 30 Days ==========
[2011/04/06 14:59:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Alessandra\Desktop\OTL.exe
[2011/04/06 14:54:12 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/06 14:54:12 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/06 14:47:38 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 14:47:38 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 14:47:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/06 14:47:25 | 3215,835,136 | -HS- | M] () – C:\hiberfil.sys
[2011/04/06 11:24:30 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/06 00:12:08 | 000,006,836 | —- | M] () – C:\Users\Alessandra\AppData\Local\d3d9caps.dat
[2011/04/05 19:43:50 | 000,072,884 | —- | M] () – C:\Users\Alessandra\Documents\312b rent.JPG
[2011/04/03 19:57:27 | 001,728,076 | —- | M] () – C:\Users\Alessandra\Documents\dress 1 (2).tif
[2011/04/03 19:56:43 | 001,723,810 | —- | M] () – C:\Users\Alessandra\Documents\dress 9.tif
[2011/04/03 19:56:05 | 002,059,870 | —- | M] () – C:\Users\Alessandra\Documents\dress 8.tif
[2011/04/03 19:55:26 | 001,087,634 | —- | M] () – C:\Users\Alessandra\Documents\dress 5.tif
[2011/04/03 19:55:07 | 001,719,628 | —- | M] () – C:\Users\Alessandra\Documents\dress 2.tif
[2011/04/03 19:54:36 | 002,634,500 | —- | M] () – C:\Users\Alessandra\Documents\dress3.tif
[2011/04/03 19:54:08 | 001,601,856 | —- | M] () – C:\Users\Alessandra\Documents\dress4.tif
[2011/04/03 19:53:30 | 002,736,800 | —- | M] () – C:\Users\Alessandra\Documents\dress 1.tif
[2011/04/03 19:50:00 | 001,288,118 | —- | M] () – C:\Users\Alessandra\Documents\dress 6.tif
[2011/04/03 19:49:49 | 002,170,666 | —- | M] () – C:\Users\Alessandra\Documents\dress 7.tif
[2011/04/02 21:38:19 | 000,053,248 | —- | M] () – C:\Users\Alessandra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/29 22:57:07 | 022,937,556 | —- | M] () – C:\Users\Alessandra\Documents\DEAIM.tif
[2011/03/27 15:26:31 | 000,139,628 | —- | M] () – C:\Users\Alessandra\Desktop\pre selection kit interior design.pdf
[2011/03/24 15:30:33 | 008,416,770 | —- | M] () – C:\Users\Alessandra\Documents\Scan.tif
[2011/03/20 17:22:40 | 000,889,973 | —- | M] () – C:\Users\Alessandra\Documents\turtle-care-guide-2010.pdf
[2011/03/16 11:25:56 | 029,688,790 | —- | M] () – C:\Users\Alessandra\Documents\hue.tif
[2011/03/16 10:18:38 | 000,000,672 | —- | M] () – C:\Windows\tasks\hpwebreg_CN11O3925G05D1.job
[2011/03/16 10:18:32 | 002,316,904 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/03/15 21:14:09 | 000,002,101 | —- | M] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series.lnk
[2011/03/15 21:14:09 | 000,001,054 | —- | M] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series Scan.lnk
[2011/03/14 21:41:30 | 000,834,247 | —- | M] () – C:\Users\Alessandra\Desktop\75 tram.pdf
[2011/03/14 21:40:32 | 000,799,861 | —- | M] () – C:\Users\Alessandra\Desktop\70 tram.pdf
[2011/03/14 21:14:44 | 000,070,110 | —- | M] () – C:\Users\Alessandra\Desktop\F1C-timetable.pdf
========== Files Created - No Company Name ==========
[2011/04/05 19:43:48 | 000,072,884 | —- | C] () – C:\Users\Alessandra\Documents\312b rent.JPG
[2011/04/03 19:52:55 | 001,728,076 | —- | C] () – C:\Users\Alessandra\Documents\dress 1 (2).tif
[2011/04/03 19:45:56 | 001,723,810 | —- | C] () – C:\Users\Alessandra\Documents\dress 9.tif
[2011/04/03 19:45:23 | 002,059,870 | —- | C] () – C:\Users\Alessandra\Documents\dress 8.tif
[2011/04/03 19:39:12 | 002,170,666 | —- | C] () – C:\Users\Alessandra\Documents\dress 7.tif
[2011/04/03 19:38:26 | 001,288,118 | —- | C] () – C:\Users\Alessandra\Documents\dress 6.tif
[2011/04/03 19:36:34 | 001,087,634 | —- | C] () – C:\Users\Alessandra\Documents\dress 5.tif
[2011/04/03 19:33:06 | 001,601,856 | —- | C] () – C:\Users\Alessandra\Documents\dress4.tif
[2011/04/03 19:31:49 | 002,634,500 | —- | C] () – C:\Users\Alessandra\Documents\dress3.tif
[2011/04/03 19:23:47 | 001,719,628 | —- | C] () – C:\Users\Alessandra\Documents\dress 2.tif
[2011/04/03 19:22:05 | 002,736,800 | —- | C] () – C:\Users\Alessandra\Documents\dress 1.tif
[2011/03/29 22:57:05 | 022,937,556 | —- | C] () – C:\Users\Alessandra\Documents\DEAIM.tif
[2011/03/27 15:26:31 | 000,139,628 | —- | C] () – C:\Users\Alessandra\Desktop\pre selection kit interior design.pdf
[2011/03/24 15:28:17 | 008,416,770 | —- | C] () – C:\Users\Alessandra\Documents\Scan.tif
[2011/03/20 17:22:36 | 000,889,973 | —- | C] () – C:\Users\Alessandra\Documents\turtle-care-guide-2010.pdf
[2011/03/16 11:25:53 | 029,688,790 | —- | C] () – C:\Users\Alessandra\Documents\hue.tif
[2011/03/15 21:16:35 | 000,000,672 | —- | C] () – C:\Windows\tasks\hpwebreg_CN11O3925G05D1.job
[2011/03/15 21:15:52 | 000,001,203 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Default Manager.lnk
[2011/03/15 21:14:09 | 000,002,101 | —- | C] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series.lnk
[2011/03/15 21:14:09 | 000,001,054 | —- | C] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series Scan.lnk
[2011/03/14 21:41:30 | 000,834,247 | —- | C] () – C:\Users\Alessandra\Desktop\75 tram.pdf
[2011/03/14 21:40:32 | 000,799,861 | —- | C] () – C:\Users\Alessandra\Desktop\70 tram.pdf
[2011/03/14 21:14:44 | 000,070,110 | —- | C] () – C:\Users\Alessandra\Desktop\F1C-timetable.pdf
[2010/09/10 13:09:49 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2010/09/08 23:40:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/08 23:40:16 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/08 23:40:13 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/08 23:40:13 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/08 23:40:13 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/08/01 19:13:09 | 000,000,000 | —- | C] () – C:\Windows\OpPrintServer.INI
[2010/05/14 19:15:35 | 000,053,248 | —- | C] () – C:\Windows\System32\pxhpinst.exe
[2010/02/11 18:11:29 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/02/11 17:59:19 | 000,000,000 | —- | C] () – C:\Windows\EEventManager.INI
[2009/11/08 08:49:21 | 000,006,836 | —- | C] () – C:\Users\Alessandra\AppData\Local\d3d9caps.dat
[2009/10/05 15:59:52 | 000,111,932 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2009/10/05 15:59:52 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2009/10/05 15:59:51 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2009/10/05 15:59:51 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2009/10/05 15:59:51 | 000,026,154 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2009/10/05 15:59:51 | 000,024,903 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2009/10/05 15:59:51 | 000,021,390 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2009/10/05 15:59:51 | 000,020,148 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2009/10/05 15:59:51 | 000,011,811 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2009/10/05 15:59:51 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2009/10/05 15:59:51 | 000,001,146 | —- | C] () – C:\Windows\System32\EPPICPresetData_DU.dat
[2009/10/05 15:59:51 | 000,001,139 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2009/10/05 15:59:51 | 000,001,139 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2009/10/05 15:59:51 | 000,001,136 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2009/10/05 15:59:51 | 000,001,129 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2009/10/05 15:59:51 | 000,001,129 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2009/10/05 15:59:51 | 000,001,120 | —- | C] () – C:\Windows\System32\EPPICPresetData_IT.dat
[2009/10/05 15:59:51 | 000,001,107 | —- | C] () – C:\Windows\System32\EPPICPresetData_GE.dat
[2009/10/05 15:59:51 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2009/08/20 18:33:54 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/20 18:33:53 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/04/17 17:22:45 | 000,053,248 | —- | C] () – C:\Users\Alessandra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/03 00:44:10 | 000,000,422 | —- | C] () – C:\Users\Alessandra\AppData\Roaming\wklnhst.dat
[2009/03/12 18:36:54 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2009/03/12 18:36:54 | 000,174,819 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/03/12 18:36:54 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2009/03/12 18:36:54 | 000,090,112 | —- | C] () – C:\Windows\System32\atibrtmon.exe
[2009/03/12 18:32:34 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/12 10:44:39 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/03/12 03:22:02 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/03/12 03:11:57 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/03/12 03:02:26 | 000,000,628 | —- | C] () – C:\Windows\System32\PCI_VEN_1102&DEV_FF05&SUBSYS_00001102.ini
[2009/03/12 03:02:25 | 000,101,376 | —- | C] () – C:\Windows\System32\APOMngr.dll
[2009/03/12 03:02:25 | 000,066,560 | —- | C] () – C:\Windows\System32\CmdRtr.dll
[2008/09/05 19:16:36 | 000,233,216 | —- | C] () – C:\Windows\System32\FACrashRpt.dll
[2008/09/05 19:16:36 | 000,059,136 | —- | C] () – C:\Windows\System32\FAib.dll
[2008/09/05 19:16:20 | 000,087,296 | —- | C] () – C:\Windows\System32\FAIEExtension.dll
[2007/04/16 05:24:16 | 000,023,752 | —- | C] () – C:\Windows\System32\providers.bin
[2006/11/02 22:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 22:47:37 | 002,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 22:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 20:33:01 | 000,609,196 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 20:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 20:33:01 | 000,108,672 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 20:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 20:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 18:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 18:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 17:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 17:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/14 15:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll
========== LOP Check ==========
[2011/04/05 23:04:03 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547
[2010/05/18 18:57:02 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Autodesk
[2011/02/13 13:27:57 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/01/12 12:17:20 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\DriverCure
[2009/10/05 16:21:56 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Epson
[2010/05/17 19:32:53 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Publish Providers
[2010/05/20 16:04:44 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Sony
[2009/04/03 00:44:12 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Template
[2010/01/12 12:58:25 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Uniblue
[2010/05/19 12:56:43 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\uTorrent
[2011/04/06 11:24:30 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/19 07:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 16:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/02/18 12:34:17 | 000,015,887 | —- | M] () – C:\ComboFix.txt
[2006/09/19 07:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/03/12 18:37:06 | 000,005,286 | RH– | M] () – C:\dell.sdr
[2011/04/06 14:47:25 | 3215,835,136 | -HS- | M] () – C:\hiberfil.sys
[2010/05/01 12:46:19 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2010/05/17 18:21:48 | 000,000,778 | -H– | M] () – C:\os117275.bin
[2011/04/06 14:47:17 | 3529,646,080 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 22:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 22:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 22:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/03 18:34:51 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/19 07:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 22:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/05 00:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/21 12:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/21 13:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 13:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 13:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 20:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 20:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/04 19:17:14 | 000,000,350 | -HS- | M] () – C:\Users\Alessandra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/02/17 15:53:14 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Alessandra\Desktop\ATF_Cleaner.exe
[2011/04/06 14:59:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Alessandra\Desktop\OTL.exe
[2009/09/30 15:34:32 | 070,124,864 | —- | M] (CANON INC.) – C:\Users\Alessandra\Desktop\rc150upd_7l.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2010/02/11 17:22:20 | 004,493,736 | —- | M] (Microsoft Corporation) – C:\Users\Alessandra\mssefullinstall-x86fre-en-us-vista-win7.exe
[2010/05/13 14:57:58 | 160,991,560 | —- | M] (Sony Creative Software Inc.) – C:\Users\Alessandra\soundforgepro10.0b.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/04/02 18:19:02 | 000,000,402 | -HS- | M] () – C:\Users\Alessandra\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/02/11 18:11:29 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-06 00:47:53
< End of report >