Ok, scan worked this time. Here's the report…
OTScanIt2 logfile created on: 12/1/2008 9:54:04 AM - Run 9
OTScanIt2 by OldTimer - Version 1.0.2.0 Folder = C:\Documents and Settings\Maryann\Desktop\OTScanIt2
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 69.27% Memory free
3.85 Gb Paging File | 3.30 Gb Available in Paging File | 85.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.82 Gb Total Space | 27.73 Gb Free Space | 38.62% Space Free | Partition Type: FAT32
Drive D: | 72.31 Gb Total Space | 72.31 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MOM
Current User Name: Maryann
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 90 Days
[Processes - Safe List]
admserv.exe -> %SystemDrive%\Acer\Empowering Technology\admServ.exe -> [2005/10/24 16:40:52 | 01,314,816 | —- | M] (Avocent Inc.)
admtray.exe -> %SystemDrive%\Acer\Empowering Technology\admtray.exe -> [2005/10/24 16:45:32 | 02,462,208 | —- | M] (Avocent Inc.)
apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe -> [2007/03/09 11:09:58 | 00,063,712 | —- | M] (Adobe Systems Incorporated)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
cameraassistant.exe -> %ProgramFiles%\Acer\OrbiCam\CameraAssistant.exe -> [2006/06/26 15:47:48 | 00,331,776 | —- | M] (Acer)
clcapsvc.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe -> [2006/08/09 22:29:36 | 00,254,050 | —- | M] ()
clmlserver.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe -> [2006/08/09 22:28:36 | 00,061,440 | —- | M] (Cyberlink)
clmlservice.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe -> [2006/08/09 22:28:36 | 01,077,376 | —- | M] (Cyberlink)
clsched.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLSched.exe -> [2006/08/09 22:29:38 | 00,114,784 | —- | M] ()
cvpnd.exe -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> [2004/12/06 16:18:18 | 01,437,712 | —- | M] (Cisco Systems, Inc.)
edsloader.exe -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\eDSloader.exe -> [2005/12/27 15:50:28 | 00,069,632 | —- | M] (HiTRUST)
elkctrl.exe -> %SystemRoot%\system32\ElkCtrl.exe -> [2004/11/01 18:22:22 | 00,262,144 | —- | M] (Logitech Inc.)
epower_dmc.exe -> %SystemDrive%\Acer\Empowering Technology\ePower\ePower_DMC.exe -> [2006/08/10 19:29:14 | 00,352,256 | —- | M] (Acer Incorporated)
evteng.exe -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> [2005/11/28 11:29:00 | 00,114,753 | —- | M] (Intel Corporation)
googledesktop.exe -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/02 15:44:54 | 00,029,744 | —- | M] (Google)
googledesktop.exe -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/02 15:44:54 | 00,029,744 | —- | M] (Google)
googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2007/06/26 12:21:14 | 00,068,856 | —- | M] (Google Inc.)
groovemonitor.exe -> %ProgramFiles%\Microsoft Office\Office12\GrooveMonitor.exe -> [2007/08/24 07:00:48 | 00,033,648 | —- | M] (Microsoft Corporation)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | —- | M] (Apple Inc.)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/10/01 18:57:12 | 00,289,576 | —- | M] (Apple Inc.)
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe -> [2008/06/10 04:27:04 | 00,144,784 | —- | M] (Sun Microsystems, Inc.)
lmanager.exe -> %SystemDrive%\PROGRA~1\LAUNCH~1\LManager.exe -> [2006/07/20 22:15:32 | 00,593,920 | —- | M] (Dritek System Inc.)
lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2006/05/18 16:52:06 | 00,049,152 | —- | M] (Hewlett-Packard Company)
lvcomsx.exe -> %SystemRoot%\system32\LVCOMSX.EXE -> [2006/06/23 10:39:54 | 00,225,280 | —- | M] (Logitech)
lvprcsrv.exe -> %CommonProgramFiles%\logitech\lvmvfm\LVPrcSrv.exe -> [2006/06/23 10:40:58 | 00,086,016 | —- | M] (Logitech)
mbackmonitor.exe -> %ProgramFiles%\McAfee\MBK\MBackMonitor.exe -> [2007/01/16 13:59:46 | 00,071,208 | —- | M] (McAfee)
mcafeedatabackup.exe -> %ProgramFiles%\McAfee\MBK\McAfeeDataBackup.exe -> [2007/01/16 13:59:50 | 04,838,952 | —- | M] (McAfee)
mcagent.exe -> %SystemDrive%\PROGRA~1\mcafee.com\agent\mcagent.exe -> [2007/11/01 18:12:38 | 00,582,992 | —- | M] (McAfee, Inc.)
mcmscsvc.exe -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
mcnasvc.exe -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe -> [2008/01/25 01:38:12 | 02,458,128 | —- | M] (McAfee, Inc.)
mcproxy.exe -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe -> [2007/08/15 12:36:04 | 00,359,248 | —- | M] (McAfee, Inc.)
mcshield.exe -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe -> [2007/07/24 12:02:14 | 00,144,704 | —- | M] (McAfee, Inc.)
mcuimgr.exe -> %SystemDrive%\PROGRA~1\mcafee\msc\mcuimgr.exe -> [2007/11/01 18:12:38 | 00,265,040 | —- | M] (McAfee, Inc.)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
monitor.exe -> %SystemDrive%\Acer\Empowering Technology\eRecovery\Monitor.exe -> [2006/01/24 18:00:08 | 00,397,312 | —- | M] (acer Inc.)
mpfsrv.exe -> %ProgramFiles%\McAfee\MPF\MPFSrv.exe -> [2007/07/18 15:54:42 | 00,856,864 | —- | M] (McAfee, Inc.)
nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2006/07/20 05:58:00 | 00,143,426 | —- | M] (NVIDIA Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/11/30 14:41:16 | 00,477,184 | —- | M] (OldTimer Tools)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/11/30 14:41:16 | 00,477,184 | —- | M] (OldTimer Tools)
pcmservice.exe -> %ProgramFiles%\Acer\Acer Arcade\PCMService.exe -> [2006/08/09 22:29:08 | 00,151,552 | —- | M] (CyberLink Corp.)
regsrvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> [2005/11/28 11:28:14 | 00,217,164 | —- | M] (Intel Corporation)
richvideo.exe -> %ProgramFiles%\CyberLink\Shared Files\RichVideo.exe -> [2005/01/21 04:37:16 | 00,143,360 | —- | M] ()
rthdcpl.exe -> %SystemRoot%\RTHDCPL.EXE -> [2007/03/21 14:49:20 | 16,126,464 | R— | M] (Realtek Semiconductor Corp.)
rtkbtmnt.exe -> %SystemDrive%\DOCUME~1\Maryann\LOCALS~1\Temp\RtkBtMnt.exe -> [2007/05/02 23:43:32 | 00,208,896 | —- | M] (Realtek Semiconductor Corp.)
rundll32.exe -> %SystemRoot%\system32\rundll32.exe -> [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation)
rundll32.exe -> %SystemRoot%\system32\RUNDLL32.EXE -> [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation)
rundll32.exe -> %SystemRoot%\system32\rundll32.exe -> [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation)
s24evmon.exe -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> [2005/11/28 11:31:32 | 00,540,745 | —- | M] (Intel Corporation )
symlcsvc.exe -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> [2008/06/11 18:51:50 | 01,251,720 | —- | M] ()
syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> [2006/03/03 13:07:38 | 00,761,946 | —- | M] (Synaptics, Inc.)
unsecapp.exe -> %SystemRoot%\system32\wbem\unsecapp.exe -> [2004/08/04 05:00:00 | 00,016,896 | —- | M] (Microsoft Corporation)
wmiprvse.exe -> %SystemRoot%\system32\wbem\wmiprvse.exe -> [2004/08/04 05:00:00 | 00,218,112 | —- | M] (Microsoft Corporation)
wmiprvse.exe -> %SystemRoot%\system32\wbem\wmiprvse.exe -> [2004/08/04 05:00:00 | 00,218,112 | —- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation)
(AWService) AdminWorks Agent X6 [Win32_Own | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\admServ.exe -> [2005/10/24 16:40:52 | 01,314,816 | —- | M] (Avocent Inc.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
(BthServ) Bluetooth Support Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\bthserv.dll -> [2004/08/04 05:00:00 | 00,030,208 | —- | M] (Microsoft Corporation)
(CLCapSvc) CyberLink Background Capture Service (CBCS) [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe -> [2006/08/09 22:29:36 | 00,254,050 | —- | M] ()
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation)
(CLSched) CyberLink Task Scheduler (CTS) [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLSched.exe -> [2006/08/09 22:29:38 | 00,114,784 | —- | M] ()
(CVPND) Cisco Systems, Inc. VPN Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> [2004/12/06 16:18:18 | 01,437,712 | —- | M] (Cisco Systems, Inc.)
(CyberLink Media Library Service) CyberLink Media Library Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe -> [2006/08/09 22:28:36 | 00,061,440 | —- | M] (Cyberlink)
(EvtEng) Intel(R) PROSet/Wireless Event Log [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> [2005/11/28 11:29:00 | 00,114,753 | —- | M] (Intel Corporation)
(GoogleDesktopManager-061008-081103) Google Desktop Manager 5.7.806.10245 [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/02 15:44:54 | 00,029,744 | —- | M] (Google)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2007/01/31 21:42:44 | 00,138,168 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | —- | M] (Apple Inc.)
(Irmon) Infrared Monitor [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\irmon.dll -> [2004/09/30 10:49:36 | 00,027,136 | —- | M] (Microsoft Corporation)
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2006/05/18 16:52:06 | 00,049,152 | —- | M] (Hewlett-Packard Company)
(LVPrcSrv) Logitech Process Monitor [Win32_Own | Auto | Running] -> %CommonProgramFiles%\logitech\lvmvfm\LVPrcSrv.exe -> [2006/06/23 10:40:58 | 00,086,016 | —- | M] (Logitech)
(MBackMonitor) MBackMonitor [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MBK\MBackMonitor.exe -> [2007/01/16 13:59:46 | 00,071,208 | —- | M] (McAfee)
(mcmscsvc) McAfee Services [Win32_Own | Auto | Running] -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
(McNASvc) McAfee Network Agent [Win32_Own | Auto | Running] -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe -> [2008/01/25 01:38:12 | 02,458,128 | —- | M] (McAfee, Inc.)
(McODS) McAfee Scanner [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcods.exe -> [2007/11/07 09:35:40 | 00,378,184 | —- | M] (McAfee, Inc.)
(McProxy) McAfee Proxy Service [Win32_Own | Auto | Running] -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe -> [2007/08/15 12:36:04 | 00,359,248 | —- | M] (McAfee, Inc.)
(McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Running] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe -> [2007/07/24 12:02:14 | 00,144,704 | —- | M] (McAfee, Inc.)
(McSysmon) McAfee SystemGuards [Win32_Own | Disabled | Stopped] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe -> [2007/12/05 10:04:10 | 00,695,624 | —- | M] (McAfee, Inc.)
(Microsoft Office Groove Audit Service) Microsoft Office Groove Audit Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Microsoft Office\Office12\GrooveAuditService.exe -> [2007/08/24 06:59:20 | 00,068,464 | —- | M] (Microsoft Corporation)
(MpfService) McAfee Personal Firewall Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MPF\MPFSrv.exe -> [2007/07/18 15:54:42 | 00,856,864 | —- | M] (McAfee, Inc.)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2006/07/20 05:58:00 | 00,143,426 | —- | M] (NVIDIA Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation)
(RegSrvc) Intel(R) PROSet/Wireless Registry Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> [2005/11/28 11:28:14 | 00,217,164 | —- | M] (Intel Corporation)
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> %ProgramFiles%\CyberLink\Shared Files\RichVideo.exe -> [2005/01/21 04:37:16 | 00,143,360 | —- | M] ()
(S24EventMonitor) Intel(R) PROSet/Wireless Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> [2005/11/28 11:31:32 | 00,540,745 | —- | M] (Intel Corporation )
(Symantec Core LC) Symantec Core LC [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> [2008/06/11 18:51:50 | 01,251,720 | —- | M] ()
(winvnc) VNC Server [Win32_Own | On_Demand | Stopped] -> -> File not found
[Driver Services - Safe List]
(AegisP) AEGIS Protocol (IEEE 802.1x) v3.4.9.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\AegisP.sys -> [2006/12/26 02:46:28 | 00,021,275 | —- | M] (Meetinghouse Data Communications)
(AliIde) AliIde [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\aliide.sys -> [2004/08/04 05:00:00 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\amdagp.sys -> [2004/08/03 23:07:44 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(asc) asc [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\asc.sys -> [2004/08/04 05:00:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\asc3550.sys -> [2004/08/04 05:00:00 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\bcm4sbxp.sys -> [2005/10/31 14:17:00 | 00,045,312 | —- | M] (Broadcom Corporation)
(BthEnum) Bluetooth Request Block Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\BthEnum.sys -> [2004/08/04 05:00:00 | 00,017,024 | —- | M] (Microsoft Corporation)
(BthPan) Bluetooth Device (Personal Area Network) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\bthpan.sys -> [2004/08/04 05:00:00 | 00,100,992 | —- | M] (Microsoft Corporation)
(BTHPORT) Bluetooth Port Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\BTHport.sys -> [2008/06/13 08:10:50 | 00,272,128 | —- | M] (Microsoft Corporation)
(BTHUSB) Bluetooth Radio USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\BTHUSB.sys -> [2004/08/04 05:00:00 | 00,018,944 | —- | M] (Microsoft Corporation)
(CmdIde) CmdIde [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\cmdide.sys -> [2004/08/04 05:00:00 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(CVirtA) Cisco Systems VPN Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\CVirtA.sys -> [2003/05/01 13:26:34 | 00,005,220 | —- | M] (Cisco Systems, Inc.)
(CVPNDRVA) Cisco Systems IPsec Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\Drivers\CVPNDRVA.sys -> [2004/12/06 16:17:18 | 00,268,872 | —- | M] (Cisco Systems, Inc.)
(dac2w2k) dac2w2k [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\dac2w2k.sys -> [2004/08/04 05:00:00 | 00,179,584 | —- | M] (Mylex Corporation)
(DKbFltr) Dritek Keyboard Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\DKbFltr.sys -> [2004/12/08 14:10:00 | 00,016,896 | —- | M] (Dritek System Inc.)
(DNE) Deterministic Network Enhancer Miniport [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\dne2000.sys -> [2003/07/24 18:55:50 | 00,139,604 | —- | M] (Deterministic Networks, Inc.)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> [2007/02/06 03:00:00 | 00,383,800 | —- | M] (Symantec Corporation)
(EMSCR) EMSCR [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\EMS7SK.sys -> [2006/06/16 19:17:36 | 00,061,056 | —- | M] (ENE Technology Inc.)
(EpmPsd) Acer EPM Power Scheme Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\epm-psd.sys -> [2006/01/23 12:41:04 | 00,004,096 | —- | M] (Acer Value Labs, USA)
(EpmShd) Acer EPM System Hardware Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\epm-shd.sys -> [2006/01/23 12:41:04 | 00,078,208 | —- | M] (Acer Value Labs, USA)
(ESDCR) ESDCR [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ESD7SK.sys -> [2006/06/16 19:17:38 | 00,040,064 | —- | M] (ENE Technology Inc.)
(ESMCR) ESMCR [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ESM7SK.sys -> [2006/06/16 19:17:38 | 00,074,752 | —- | M] (ENE Technology Inc.)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2005/01/07 17:07:18 | 00,138,752 | —- | M] (Windows (R) Server 2003 DDK provider)
(HSFHWAZL) HSFHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSFHWAZL.sys -> [2005/10/24 10:20:52 | 00,218,496 | —- | M] (Conexant Systems, Inc.)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_DPV.sys -> [2005/10/18 16:53:24 | 00,998,656 | —- | M] (Conexant Systems, Inc.)
(ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\ialmnt5.sys -> [2006/03/23 12:47:06 | 01,166,972 | —- | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> [2007/03/26 19:21:06 | 04,395,008 | R— | M] (Realtek Semiconductor Corp.)
(lv321av) Logitech USB PC Camera (VC0321) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\lv321av.sys -> [2006/06/19 12:20:24 | 01,097,728 | —- | M] (Logitech)
(lvmvdrv) Logitech Machine Vision Engine Loader [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\lvmvdrv.sys -> [2006/06/23 10:40:58 | 02,400,128 | —- | M] ()
(LVPrcMon) Logitech LVPrcMon Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LVPrcMon.sys -> [2006/06/23 10:40:58 | 00,016,768 | —- | M] ()
(LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\lvusbsta.sys -> [2006/06/19 12:16:16 | 00,039,424 | —- | M] (Logitech)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2005/10/05 15:57:08 | 00,012,544 | —- | M] (Conexant)
(mfeavfk) McAfee Inc. mfeavfk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfeavfk.sys -> [2007/11/22 06:44:08 | 00,079,304 | —- | M] (McAfee, Inc.)
(mfebopk) McAfee Inc. mfebopk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfebopk.sys -> [2007/11/22 06:44:08 | 00,035,240 | —- | M] (McAfee, Inc.)
(mfehidk) McAfee Inc. mfehidk [Kernel | System | Running] -> %SystemRoot%\system32\drivers\mfehidk.sys -> [2007/11/22 06:44:08 | 00,201,320 | —- | M] (McAfee, Inc.)
(mferkdk) McAfee Inc. mferkdk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mferkdk.sys -> [2007/11/22 06:44:04 | 00,033,832 | —- | M] (McAfee, Inc.)
(mfesmfk) McAfee Inc. mfesmfk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mfesmfk.sys -> [2007/12/02 12:51:42 | 00,040,488 | —- | M] (McAfee, Inc.)
(MPFP) MPFP [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\Mpfp.sys -> [2007/07/13 06:20:24 | 00,113,952 | —- | M] (McAfee, Inc.)
(mraid35x) mraid35x [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\mraid35x.sys -> [2004/08/04 05:00:00 | 00,017,280 | —- | M] (American Megatrends Inc.)
(NdisFilt) OSA NdisFilter Protocol [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\NdisFilt.sys -> [2005/09/13 15:34:40 | 00,004,392 | —- | M] (OSA Technologies)
(NETMNT) Acer NetMonitor Protocol [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\NETMNT.sys -> [2005/05/02 12:13:42 | 00,009,600 | —- | M] ()
(NPF) NetGroup Packet Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\npf.sys -> [2006/01/23 12:41:42 | 00,032,512 | —- | M] (CACE Technologies)
(NTIDrvr) Upper Class Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\NTIDrvr.sys -> [2006/08/23 03:01:10 | 00,006,144 | —- | M] (NewTech Infosystems, Inc.)
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2006/07/20 05:58:00 | 03,685,152 | —- | M] (NVIDIA Corporation)
(OsaFsLoc) OsaFsLoc [Kernel | System | Running] -> %SystemRoot%\system32\drivers\OsaFsLoc.sys -> [2005/10/15 18:20:44 | 00,012,106 | —- | M] (OSA Technologies)
(osaio) osaio [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\osaio.sys -> [2005/06/30 16:58:24 | 00,007,296 | —- | M] (OSA Technologies, An Avocent Company)
(osanbm) osanbm [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\osanbm.sys -> [2005/01/14 15:57:16 | 00,004,010 | —- | M] (Windows (R) 2000 DDK provider)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/04 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ql1080) ql1080 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql1080.sys -> [2004/08/04 05:00:00 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql12160.sys -> [2004/08/04 05:00:00 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql1280.sys -> [2004/08/04 05:00:00 | 00,049,024 | —- | M] (QLogic Corporation)
(RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\rfcomm.sys -> [2004/08/04 05:00:00 | 00,059,648 | —- | M] (Microsoft Corporation)
(s24trans) WLAN Transport [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\s24trans.sys -> [2005/11/28 12:09:26 | 00,013,568 | —- | M] (Intel Corporation)
(sdbus) sdbus [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\sdbus.sys -> [2004/08/04 05:00:00 | 00,067,584 | —- | M] (Microsoft Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 04:25:54 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sisagp) SIS AGP Bus Filter [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sisagp.sys -> [2004/08/03 23:07:44 | 00,041,088 | —- | M] (Silicon Integrated Systems Corporation)
(SMCIRDA) SMSC IrCC Miniport Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\smcirda.sys -> [2005/10/31 14:16:00 | 00,046,080 | —- | M] (SMSC)
(Sparrow) Sparrow [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sparrow.sys -> [2004/08/04 05:00:00 | 00,019,072 | —- | M] (Adaptec, Inc.)
(symc810) symc810 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\symc810.sys -> [2004/08/04 05:00:00 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\symc8xx.sys -> [2004/08/04 05:00:00 | 00,032,640 | —- | M] (LSI Logic)
(symlcbrd) symlcbrd [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\symlcbrd.sys -> [2006/08/23 03:38:10 | 00,010,344 | —- | M] (Symantec Corporation)
(sym_hi) sym_hi [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sym_hi.sys -> [2004/08/04 05:00:00 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sym_u3.sys -> [2004/08/04 05:00:00 | 00,030,688 | —- | M] (LSI Logic)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\SynTP.sys -> [2006/03/03 12:52:30 | 00,192,672 | —- | M] (Synaptics, Inc.)
(UBHelper) UBHelper [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\UBHelper.sys -> [2004/12/17 17:14:44 | 00,013,952 | —- | M] ()
(ultra) ultra [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ultra.sys -> [2004/08/04 05:00:00 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(vsdatant) vsdatant [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\vsdatant.sys -> [2003/08/28 21:40:26 | 00,189,792 | —- | M] (Zone Labs Inc.)
(w39n51) Intel(R) PRO/Wireless 3945ABG Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\w39n51.sys -> [2006/04/03 12:17:24 | 01,429,632 | —- | M] (Intel® Corporation)
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_CNXT.sys -> [2005/10/18 16:52:30 | 00,721,280 | —- | M] (Conexant Systems, Inc.)
(WmiAcpi) Microsoft Windows Management Interface for ACPI [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\wmiacpi.sys -> [2004/08/03 23:07:42 | 00,008,832 | —- | M] (Microsoft Corporation)
(WS2IFSL) Windows Socket 2.0 Non-IFS Service Provider Support Environment [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ws2ifsl.sys -> [2004/08/04 05:00:00 | 00,012,032 | —- | M] (Microsoft Corporation)
(int15.sys) int15.sys [Kernel | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\eRecovery\int15.sys -> [2005/01/13 14:46:16 | 00,069,632 | —- | M] ()
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://en.us.acer.yahoo.com ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://www.google.com/ie ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com ->
HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultName" -> Yahoo! Search ->
HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultURL" -> http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> about:blank ->
HKEY_CURRENT_USER\: SearchURL\\"" -> http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
HKEY_CURRENT_USER\: "ProxyOverride" -> *.local ->
< FireFox Settings [Default Profile] > -> C:\Documents and Settings\Maryann\Application Data\Mozilla\FireFox\Profiles\b1p0iryz.default\prefs.js ->
browser.startup.homepage_override.mstone -> "rv:1.8.1.4" ->
< HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [&Yahoo! Toolbar Helper] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
{4e5ffa00-4f7f-43c2-874d-43b84ce07067} [HKLM] -> %SystemRoot%\system32\examuy.dll [Reg Error: Value does not exist or could not be read.] -> [2008/11/30 22:30:20 | 00,129,024 | —- | M] ()
{7274C06D-C70A-4DEF-876E-BBE9F9E6E1E1} [HKLM] -> %SystemRoot%\system32\qoMffFYr.dll [Reg Error: Value does not exist or could not be read.] -> [2008/11/26 11:12:36 | 00,318,464 | —- | M] ()
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\ssv.dll [SSVHelper Class] -> [2008/06/10 04:27:02 | 00,509,328 | —- | M] (Sun Microsystems, Inc.)
{8bc485fd-d543-44f0-8a1d-9c6e90fc088f} [HKLM] -> %SystemRoot%\system32\veglaf.dll [Reg Error: Value does not exist or could not be read.] -> [2008/11/30 22:30:02 | 00,075,776 | —- | M] ()
{A057A204-BACC-4D26-CEC4-75A487FD6484} [HKLM] -> %SystemDrive%\PROGRA~1\mypoints\mypoints.dll [MYPOINTS] -> [2008/10/29 18:45:34 | 01,909,248 | —- | M] (Infospace )
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\google\googletoolbar3.dll [Google Toolbar Helper] -> [2007/01/19 23:55:32 | 02,403,392 | R— | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [Google Toolbar Notifier BHO] -> [2008/10/30 19:56:50 | 00,737,776 | —- | M] (Google Inc.)
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} [HKLM] -> %ProgramFiles%\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [EpsonToolBandKicker Class] -> [2005/02/22 13:50:34 | 00,368,640 | —- | M] (SEIKO EPSON CORPORATION)
{fba9acc7-9a24-4a1f-972c-807dde81eceb} [HKLM] -> %SystemRoot%\system32\heyehita.dll [Reg Error: Value does not exist or could not be read.] -> [2008/08/28 21:17:10 | 00,061,952 | -HS- | M] ()
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar3.dll [&Google] -> [2007/01/19 23:55:32 | 02,403,392 | R— | M] (Google Inc.)
"{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}" [HKLM] -> %SystemRoot%\system32\eDStoolbar.dll [Acer eDataSecurity Management] -> [2006/02/22 12:50:56 | 00,106,496 | —- | M] (HiTRUST)
"{A057A204-BACC-4D26-CEC4-75A487FD6484}" [HKLM] -> %SystemDrive%\PROGRA~1\mypoints\mypoints.dll [MYPOINTS] -> [2008/10/29 18:45:34 | 01,909,248 | —- | M] (Infospace )
"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" [HKLM] -> %ProgramFiles%\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [EPSON Web-To-Page] -> [2005/02/22 13:50:34 | 00,368,640 | —- | M] (SEIKO EPSON CORPORATION)
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{C4069E3A-68F1-403E-B40E-20066696354B}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar3.dll [&Google] -> [2007/01/19 23:55:32 | 02,403,392 | R— | M] (Google Inc.)
WebBrowser\\"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{A057A204-BACC-4D26-CEC4-75A487FD6484}" [HKLM] -> %SystemDrive%\PROGRA~1\mypoints\mypoints.dll [MYPOINTS] -> [2008/10/29 18:45:34 | 01,909,248 | —- | M] (Infospace )
WebBrowser\\"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" [HKLM] -> %ProgramFiles%\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [EPSON Web-To-Page] -> [2005/02/22 13:50:34 | 00,368,640 | —- | M] (SEIKO EPSON CORPORATION)
WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"" -> [] -> File not found
"320d18a1" -> %SystemRoot%\system32\eyjeocid.DLL [rundll32.exe "C:\WINDOWS\system32\eyjeocid.dll",b] -> [2008/11/30 22:29:36 | 00,072,704 | —- | M] ()
"Acer ePower Management" -> %SystemDrive%\Acer\Empowering Technology\ePower\Acer ePower Management.exe [C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot] -> [2006/05/22 12:54:00 | 03,080,704 | —- | M] (Acer Value Labs, Taiwan)
"ADMTray.exe" -> %SystemDrive%\Acer\Empowering Technology\admtray.exe ["C:\Acer\Empowering Technology\admtray.exe"] -> [2005/10/24 16:45:32 | 02,462,208 | —- | M] (Avocent Inc.)
"Adobe Photo Downloader" -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe ["C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"] -> [2007/03/09 11:09:58 | 00,063,712 | —- | M] (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/01/11 22:16:38 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"Alcmtr" -> %SystemRoot%\ALCMTR.EXE [ALCMTR.EXE] -> [2005/05/03 18:43:28 | 00,069,632 | —- | M] (Realtek Semiconductor Corp.)
"AppleSyncNotifier" -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2008/09/03 20:12:50 | 00,111,936 | —- | M] (Apple Inc.)
"AzMixerSel" -> %ProgramFiles%\Realtek\InstallShield\AzMixerSel.exe [C:\Program Files\Realtek\InstallShield\AzMixerSel.exe] -> [2005/12/21 15:02:36 | 00,053,248 | —- | M] (Realtek Semiconductor Corp.)
"BluetoothAuthenticationAgent" -> %SystemRoot%\system32\bthprops.CPL [rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent] -> [2004/08/04 05:00:00 | 00,110,592 | —- | M] (Microsoft Corporation)
"eDataSecurity Loader" -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe] -> [2005/12/27 15:50:28 | 00,069,632 | —- | M] (HiTRUST)
"ePower_DMC" -> %SystemDrive%\Acer\Empowering Technology\ePower\ePower_DMC.exe [C:\Acer\Empowering Technology\ePower\ePower_DMC.exe] -> [2006/08/10 19:29:14 | 00,352,256 | —- | M] (Acer Incorporated)
"EPSON Stylus Photo R340 Series" -> %SystemRoot%\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O5 "LPT1:" /M "Stylus Photo R340"] -> [2005/04/26 04:00:00 | 00,098,304 | —- | M] (SEIKO EPSON CORPORATION)
"eRecoveryService" -> %SystemDrive%\Acer\Empowering Technology\eRecovery\Monitor.exe [C:\Acer\Empowering Technology\eRecovery\Monitor.exe] -> [2006/01/24 18:00:08 | 00,397,312 | —- | M] (acer Inc.)
"Google Desktop Search" -> ["C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup] -> File not found
"GrooveMonitor" -> %ProgramFiles%\Microsoft Office\Office12\GrooveMonitor.exe ["C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"] -> [2007/08/24 07:00:48 | 00,033,648 | —- | M] (Microsoft Corporation)
"igfxhkcmd" -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2006/03/23 12:13:40 | 00,077,824 | —- | M] (Intel Corporation)
"igfxpers" -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> [2006/03/23 12:17:50 | 00,118,784 | —- | M] (Intel Corporation)
"igfxtray" -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2006/03/23 12:17:04 | 00,094,208 | —- | M] (Intel Corporation)
"IMJPMIG8.1" -> %SystemRoot%\IME\imjp8_1\IMJPMIG.EXE ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/04 05:00:00 | 00,208,952 | —- | M] (Microsoft Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/10/01 18:57:12 | 00,289,576 | —- | M] (Apple Inc.)
"LaunchApp" -> %SystemRoot%\Alaunch.exe [Alaunch] -> [2005/06/22 09:36:20 | 00,520,192 | —- | M] (Acer Inc.)
"LManager" -> %SystemDrive%\PROGRA~1\LAUNCH~1\LManager.exe [C:\PROGRA~1\LAUNCH~1\LManager.exe] -> [2006/07/20 22:15:32 | 00,593,920 | —- | M] (Dritek System Inc.)
"LogitechCameraAssistant" -> %ProgramFiles%\Acer\OrbiCam\CameraAssistant.exe [C:\Program Files\Acer\OrbiCam\CameraAssistant.exe] -> [2006/06/26 15:47:48 | 00,331,776 | —- | M] (Acer)
"LogitechCameraService(E)" -> %SystemRoot%\system32\ElkCtrl.exe [C:\WINDOWS\system32\ElkCtrl.exe /automation] -> [2004/11/01 18:22:22 | 00,262,144 | —- | M] (Logitech Inc.)
"LogitechVideo[inspector]" -> %ProgramFiles%\Acer\OrbiCam\InstallHelper.exe [C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect] -> [2006/06/26 15:55:20 | 00,073,728 | —- | M] (Acer)
"LVCOMSX" -> %SystemRoot%\system32\LVCOMSX.EXE [C:\WINDOWS\system32\LVCOMSX.EXE] -> [2006/06/23 10:39:54 | 00,225,280 | —- | M] (Logitech)
"MBkLogOnHook" -> %ProgramFiles%\McAfee\MBK\LogOnHook.exe [C:\Program Files\McAfee\MBK\LogOnHook.exe] -> [2007/01/08 11:22:46 | 00,020,480 | —- | M] (McAfee)
"McAfee Backup" -> %ProgramFiles%\McAfee\MBK\McAfeeDataBackup.exe [C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe] -> [2007/01/16 13:59:50 | 04,838,952 | —- | M] (McAfee)
"mcagent_exe" -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe [C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey] -> [2007/11/01 18:12:38 | 00,582,992 | —- | M] (McAfee, Inc.)
"MSPY2002" -> \WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2004/08/04 05:00:00 | 00,059,392 | —- | M] ()
"ntiMUI" -> %ProgramFiles%\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe [C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe] -> [2006/05/15 11:15:06 | 00,045,056 | —- | M] ()
"NvCplDaemon" -> %SystemRoot%\system32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2006/07/20 05:58:00 | 07,581,696 | —- | M] (NVIDIA Corporation)
"NvMediaCenter" -> %SystemRoot%\system32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2006/07/20 05:58:00 | 00,086,016 | —- | M] (NVIDIA Corporation)
"nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2006/07/20 05:58:00 | 01,519,616 | —- | M] ()
"PCMService" -> %ProgramFiles%\Acer\Acer Arcade\PCMService.exe ["C:\Program Files\Acer\Acer Arcade\PCMService.exe"] -> [2006/08/09 22:29:08 | 00,151,552 | —- | M] (CyberLink Corp.)
"PHIME2002A" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/04 05:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"PHIME2002ASync" -> \WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2004/08/04 05:00:00 | 00,455,168 | —- | M] ()
"QuickTime Task" -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | —- | M] (Apple Inc.)
"rirawapola" -> %SystemRoot%\system32\demohajo.DLL [Rundll32.exe "C:\WINDOWS\system32\demohajo.dll",s] -> [2008/08/28 21:17:10 | 00,061,952 | -HS- | M] ()
"RTHDCPL" -> %SystemRoot%\RTHDCPL.EXE [RTHDCPL.EXE] -> [2007/03/21 14:49:20 | 16,126,464 | R— | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"] -> [2008/06/10 04:27:04 | 00,144,784 | —- | M] (Sun Microsystems, Inc.)
"SynTPEnh" -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2006/03/03 13:07:38 | 00,761,946 | —- | M] (Synaptics, Inc.)
"WinVNC" -> %ProgramFiles%\TightVNC\WinVNC.exe ["C:\Program Files\TightVNC\WinVNC.exe" -servicehelper] -> File not found
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2007/06/26 12:21:14 | 00,068,856 | —- | M] (Google Inc.)
"updateMgr" -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9] -> File not found
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk -> %ProgramFiles%\Cisco Systems\VPN Client\vpngui.exe -> [2004/12/06 16:18:22 | 01,474,576 | —- | M] (Cisco Systems, Inc.)
< Maryann Startup Folder > -> C:\Documents and Settings\Maryann\Start Menu\Programs\Startup ->
%UserProfile%\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> %ProgramFiles%\Microsoft Office\Office12\ONENOTEM.EXE -> [2007/12/07 20:44:36 | 00,101,440 | —- | M] (Microsoft Corporation)
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
\\"NoBandCustomize" -> [0] -> File not found
\\"NoMovingBands" -> [0] -> File not found
\\"NoCloseDragDropBands" -> [0] -> File not found
\\"NoSetTaskbar" -> [0] -> File not found
\\"NoToolbarsOnTaskbar" -> [0] -> File not found
\\"NoSaveSettings" -> [0] -> File not found
\\"NoActiveDesktop" -> [0] -> File not found
\\"ClassicShell" -> [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
&eBay Search -> %ProgramFiles%\eBay\eBay Toolbar2\eBayTb.dll [res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html] -> File not found
E&xport to Microsoft Excel -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000] -> [2008/07/30 03:25:02 | 17,930,264 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Menu: Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | —- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 06:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
update_microsoft.com [http] -> Trusted sites ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader3.cab[Facebook Photo Uploader 4 Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1220404172398&h=389c871dea29a6d78db8a31000ba26a3/&filename=jinstall-6u7-windows-i586-jc.cab[Java Plug-in 1.6.0_07] ->
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[Java Plug-in 1.5.0_11] ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab[Java Plug-in 1.6.0_01] ->
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab[Java Plug-in 1.6.0_02] ->
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{4BBD2084-F950-408B-B3C2-31AD3D4F2A3E} -> (Broadcom 440x 10/100 Integrated Controller) ->
{85A7FC9C-911D-4141-9F2F-3EBED9E85850} -> () ->
{9483339E-B024-4293-BD0D-BE1C63933A1C} -> (Intel(R) PRO/Wireless 3945ABG Network Connection) ->
{E1F03A83-4639-4726-9F79-644561FD2E84} -> () ->
{E9B00B7B-F433-424E-AF0B-D087D652E608} -> () ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL -> %SystemDrive%\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL -> [2008/09/02 15:44:56 | 00,113,664 | —- | M] (Google)
C:\WINDOWS\system32\pazodoga.dll examuy.dll -> %SystemRoot%\system32\pazodoga.dll examuy.dll -> File not found
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> [2006/03/23 12:12:42 | 00,139,264 | —- | M] (Intel Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Stub Execution Hook] -> [2007/08/24 07:01:22 | 02,212,224 | —- | M] (Microsoft Corporation)
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
C:\WINDOWS\system32\qoMffFYr -> %SystemRoot%\system32\qoMffFYr.dll -> [2008/11/26 11:12:36 | 00,318,464 | —- | M] ()
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 06:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 05:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 06:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 05:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\Acer\Acer Arcade\PCMService.exe" -> C:\Program Files\Acer\Acer Arcade\PCMService.exe [C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program] -> [2006/08/09 22:29:08 | 00,151,552 | —- | M] (CyberLink Corp.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" -> C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe [C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent] -> [2008/01/25 01:38:12 | 02,458,128 | —- | M] (McAfee, Inc.)
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/10/01 18:57:04 | 14,258,472 | —- | M] (Apple Inc.)
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" -> C:\Program Files\Microsoft Office\Office12\GROOVE.EXE [C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove] -> [2007/08/29 00:23:36 | 00,340,856 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" -> C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote] -> [2008/05/21 05:54:40 | 01,022,496 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook] -> [2008/05/21 04:37:24 | 12,844,576 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\Explorer.EXE" -> C:\WINDOWS\Explorer.EXE [C:\WINDOWS\Explorer.EXE:*:Enabled:Explorer] -> [2007/06/13 05:23:08 | 01,033,216 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\logonui.exe" -> C:\WINDOWS\System32\logonui.exe [C:\WINDOWS\System32\logonui.exe:*:Enabled:logonui] -> [2004/08/04 05:00:00 | 00,514,560 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\LSASS.EXE" -> C:\WINDOWS\System32\LSASS.EXE [C:\WINDOWS\System32\LSASS.EXE:*:Enabled:lsass] -> [2004/08/04 05:00:00 | 00,013,312 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\SERVICES.EXE" -> C:\WINDOWS\System32\SERVICES.EXE [C:\WINDOWS\System32\SERVICES.EXE:*:Enabled:services] -> [2004/08/04 05:00:00 | 00,108,032 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\WINLOGON.EXE" -> C:\WINDOWS\System32\WINLOGON.EXE [C:\WINDOWS\System32\WINLOGON.EXE:*:Enabled:winlogon] -> [2004/08/04 05:00:00 | 00,502,272 | —- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2004/08/04 05:00:00 | 00,049,536 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> %SystemDrive%\AUTOEXEC.BAT [ FAT32 ] -> [2006/08/23 03:02:06 | 00,000,050 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
[Registry - Additional Scans - Safe List]
< ColumnHandlers - Folder [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ ->
{F9DB5320-233E-11D1-9F84-707F02C10627} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\PDFShell.dll [PDF Shell Extension] -> [2007/05/10 22:54:08 | 00,372,736 | —- | M] (Adobe Systems, Inc.)
< Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\ ->
0 -> [Key] ->
0 -> FriendlyName = ->
0 -> Source = file:///C:/DOCUME~1/Maryann/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg ->
0 -> SubscribedURL = file:///C:/DOCUME~1/Maryann/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg ->
1 -> [Key] ->
1 -> FriendlyName = My Current Home Page ->
1 -> Source = About:Home ->
1 -> SubscribedURL = About:Home ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ ->
.bat [@ = batfile] -> "%1" %* ->
.chm [@ = chm.file] -> %SystemRoot%\hh.exe -> [2005/05/26 17:22:02 | 00,010,752 | —- | M] (Microsoft Corporation)
.cmd [@ = cmdfile] -> "%1" %* ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
.hlp [@ = hlpfile] -> %SystemRoot%\System32\winhlp32.exe -> [2004/08/04 05:00:00 | 00,008,192 | —- | M] (Microsoft Corporation)
.hta [@ = htafile] -> %SystemRoot%\system32\mshta.exe -> [2006/10/17 11:56:10 | 00,045,568 | —- | M] (Microsoft Corporation)
.html [@ = htmlfile] -> %ProgramFiles%\Internet Explorer\IEXPLORE.EXE -> [2008/08/23 00:56:16 | 00,635,848 | —- | M] (Microsoft Corporation)
.inf [@ = inffile] -> %SystemRoot%\System32\NOTEPAD.EXE -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
.ini [@ = inifile] -> %SystemRoot%\System32\NOTEPAD.EXE -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
.js [@ = JSFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.jse [@ = JSEFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.pif [@ = piffile] -> "%1" %* ->
.reg [@ = regfile] -> %SystemRoot%\regedit.exe -> [2004/08/04 05:00:00 | 00,146,432 | —- | M] (Microsoft Corporation)
.scr [@ = scrfile] -> "%1" /S ->
.txt [@ = txtfile] -> %SystemRoot%\system32\NOTEPAD.EXE -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
.vbe [@ = VBEFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.vbs [@ = VBSFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.wsf [@ = WSFFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.wsh [@ = WSHFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->
*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->
6to4 -> [] ->
Ias -> [] ->
Iprip -> [] ->
Irmon -> C:\WINDOWS\System32\irmon.dll [C:\WINDOWS\System32\irmon.dll] -> [2004/09/30 10:49:36 | 00,027,136 | —- | M] (Microsoft Corporation)
NWCWorkstation -> [] ->
Nwsapagent -> [] ->
WmdmPmSp -> [] ->
helpsvc -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll] -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Protocol Filters [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ ->
text/xml:{807563E5-5146-11D5-A672-00B0D022E945} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL[Microsoft Office InfoPath XML Mime Filter] -> [2006/10/26 21:41:48 | 00,044,344 | —- | M] (Microsoft Corporation)
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\GrooveSystemServices.dll[Local Groove Web Services Protocol] -> [2007/08/24 07:01:46 | 00,224,128 | —- | M] (Microsoft Corporation)
ipp: [HKLM] -> No CLSID value
ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL[MSDAMON.BINDER] -> [2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation)
msdaipp: [HKLM] -> No CLSID value
msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL[MSDAMON.BINDER] -> [2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation)
msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL[MSDAIPP.BINDER] -> [2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation)
ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Help\hxds.dll[HxProtocol Class] -> [2006/10/26 13:45:02 | 00,873,216 | —- | M] (Microsoft Corporation)
< SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ ->
{36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
{4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
Base -> Driver Group
Boot Bus Extender -> Driver Group
Boot file system -> Driver Group
File system -> Driver Group
Filter -> Driver Group
HelpSvc -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
mcmscsvc -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
MCODS -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcods.exe -> [2007/11/07 09:35:40 | 00,378,184 | —- | M] (McAfee, Inc.)
PCI Configuration -> Driver Group
PNP Filter -> Driver Group
Primary disk -> Driver Group
SCSI Class -> Driver Group
sermouse.sys -> Driver
System Bus Extender -> Driver Group
vga.sys -> Driver
< SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ ->
{36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} -> Net
{4D36E973-E325-11CE-BFC1-08002BE10318} -> NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} -> NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} -> NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
{4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
Base -> Driver Group
Boot Bus Extender -> Driver Group
Boot file system -> Driver Group
File system -> Driver Group
Filter -> Driver Group
HelpSvc -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
mcmscsvc -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
MCODS -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcods.exe -> [2007/11/07 09:35:40 | 00,378,184 | —- | M] (McAfee, Inc.)
MpfService -> %ProgramFiles%\McAfee\MPF\MPFSrv.exe -> [2007/07/18 15:54:42 | 00,856,864 | —- | M] (McAfee, Inc.)
NDIS Wrapper -> Driver Group
NetBIOSGroup -> Driver Group
NetDDEGroup -> Driver Group
Network -> Driver Group
NetworkProvider -> Driver Group
PCI Configuration -> Driver Group
PNP Filter -> Driver Group
PNP_TDI -> Driver Group
Primary disk -> Driver Group
rdpdd.sys -> %SystemRoot%\System32\rdpdd.dll -> [2004/08/04 05:00:00 | 00,092,168 | —- | M] (Microsoft Corporation)
SCSI Class -> Driver Group
sermouse.sys -> Driver
Streams Drivers -> Driver Group
System Bus Extender -> Driver Group
TDI -> Driver Group
vga.sys -> Driver
< Session Manager Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager ->
"BootExecute" -> autocheck autochk *; ->
"ExcludeFromKnownDlls" -> ->
*ObjectDirectories* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\ObjectDirectories ->
\Windows -> -> File not found
\RPC Control -> -> File not found
*MultiFile Done* -> ->
< Session Manager Environment Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment ->
"ComSpec" -> C:\WINDOWS\system32\cmd.exe -> [2004/08/04 05:00:00 | 00,388,608 | —- | M] (Microsoft Corporation)
"TEMP" -> %SystemRoot%\TEMP ->
"TMP" -> %SystemRoot%\TEMP ->
"windir" -> %SystemRoot% ->
*Path* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\Path ->
%SystemRoot%\system32 -> %SystemRoot%\system32 -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
%SystemRoot% -> %SystemRoot% -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
%SystemRoot%\System32\Wbem -> %SystemRoot%\System32\Wbem -> [2006/08/23 02:22:00 | 00,000,000 | —D | M]
C:\Program Files\Intel\Wireless\Bin\ -> %ProgramFiles%\Intel\Wireless\Bin -> [2006/12/26 02:44:58 | 00,000,000 | —D | M]
C:\Program Files\QuickTime\QTSystem\ -> %ProgramFiles%\QuickTime\QTSystem -> [2008/09/09 19:37:14 | 00,000,000 | —D | M]
*MultiFile Done* -> ->
*PATHEXT* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\PATHEXT ->
.COM -> -> File not found
.EXE -> -> File not found
.BAT -> -> File not found
.CMD -> -> File not found
.VBS -> -> File not found
.VBE -> -> File not found
.JS -> -> File not found
.JSE -> -> File not found
.WSF -> -> File not found
.WSH -> -> File not found
*MultiFile Done* -> ->
< Session Manager FileRenameOperations Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations ->
< Session Manager KnownDlls Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDlls ->
"advapi32" -> C:\WINDOWS\system32\advapi32.dll -> [2004/08/04 05:00:00 | 00,616,960 | —- | M] (Microsoft Corporation)
"comdlg32" -> C:\WINDOWS\system32\comdlg32.dll -> [2004/08/04 05:00:00 | 00,276,992 | —- | M] (Microsoft Corporation)
"DllDirectory" -> C:\WINDOWS\system32 -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
"gdi32" -> C:\WINDOWS\system32\gdi32.dll -> [2008/02/20 01:51:06 | 00,282,624 | —- | M] (Microsoft Corporation)
"imagehlp" -> C:\WINDOWS\system32\imagehlp.dll -> [2004/08/04 05:00:00 | 00,144,384 | —- | M] (Microsoft Corporation)
"kernel32" -> C:\WINDOWS\system32\kernel32.dll -> [2007/04/16 10:52:54 | 00,984,576 | —- | M] (Microsoft Corporation)
"lz32" -> C:\WINDOWS\system32\lz32.dll -> [2004/08/04 05:00:00 | 00,002,560 | —- | M] (Microsoft Corporation)
"ole32" -> C:\WINDOWS\system32\ole32.dll -> [2005/07/25 22:39:48 | 01,285,120 | —- | M] (Microsoft Corporation)
"oleaut32" -> C:\WINDOWS\system32\oleaut32.dll -> [2007/12/04 12:38:14 | 00,550,912 | —- | M] (Microsoft Corporation)
"olecli32" -> C:\WINDOWS\system32\olecli32.dll -> [2005/07/25 22:39:48 | 00,074,752 | —- | M] (Microsoft Corporation)
"olecnv32" -> C:\WINDOWS\system32\olecnv32.dll -> [2005/07/25 22:39:50 | 00,037,888 | —- | M] (Microsoft Corporation)
"olesvr32" -> C:\WINDOWS\system32\olesvr32.dll -> [2004/08/04 05:00:00 | 00,022,016 | —- | M] (Microsoft Corporation)
"olethk32" -> C:\WINDOWS\system32\olethk32.dll -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
"rpcrt4" -> C:\WINDOWS\system32\rpcrt4.dll -> [2007/07/09 08:16:16 | 00,582,656 | —- | M] (Microsoft Corporation)
"shell32" -> C:\WINDOWS\system32\shell32.dll -> [2007/10/25 21:34:02 | 08,460,288 | —- | M] (Microsoft Corporation)
"url" -> C:\WINDOWS\system32\url.dll -> [2008/08/26 02:24:30 | 00,105,984 | —- | M] (Microsoft Corporation)
"urlmon" -> C:\WINDOWS\system32\urlmon.dll -> [2008/08/26 02:24:32 | 01,159,680 | —- | M] (Microsoft Corporation)
"user32" -> C:\WINDOWS\system32\user32.dll -> [2007/03/08 10:36:28 | 00,577,536 | —- | M] (Microsoft Corporation)
"version" -> C:\WINDOWS\system32\version.dll -> [2004/08/04 05:00:00 | 00,018,944 | —- | M] (Microsoft Corporation)
"wininet" -> C:\WINDOWS\system32\wininet.dll -> [2008/08/26 02:24:32 | 00,826,368 | —- | M] (Microsoft Corporation)
"wldap32" -> C:\WINDOWS\system32\wldap32.dll -> [2004/08/04 05:00:00 | 00,172,032 | —- | M] (Microsoft Corporation)
< Session Manager SFC Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SFC ->
"CommonFilesDir" -> C:\Program Files\Common Files -> [2006/08/23 02:29:22 | 00,000,000 | —D | M]
"ProgramFilesDir" -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ ->
NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] -> %SystemRoot%\system32\wshbth.dll -> [2004/08/04 05:00:00 | 00,108,032 | —- | M] (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> [2008/08/29 09:53:50 | 00,147,456 | —- | M] (Apple Inc.)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 11/29/2008 11:33:52 PM Computer Name = MOM | Source = Microsoft Office 12 | ID = 2001 -> Description = Rejected Safe Mode action : Microsoft Office Outlook.
Application [ Error ] 11/30/2008 1:50:43 AM Computer Name = MOM | Source = Application Error | ID = 1000 -> Description = Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Application [ Error ] 11/30/2008 9:41:23 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 9:41:31 PM Computer Name = MOM | Source = Application Hang | ID = 1001 -> Description = Fault bucket 1035555179.
Application [ Error ] 11/30/2008 9:52:06 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:04:16 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:14:21 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:26:41 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:32:43 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 12/1/2008 10:11:24 AM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16735, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
OSession [ Error ] 1/4/2008 11:40:33 AM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6023.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 1093 seconds with 120 seconds of active time. This session ended with a crash.
OSession [ Error ] 7/25/2008 6:52:13 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8719 seconds with 180 seconds of active time. This session ended with a crash.
OSession [ Error ] 10/5/2008 8:35:16 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 28199 seconds with 0 seconds of active time. This session ended with a crash.
OSession [ Error ] 10/13/2008 7:04:04 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 88 seconds with 0 seconds of active time. This session ended with a crash.
OSession [ Error ] 10/24/2008 4:12:55 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 27501 seconds with 240 seconds of active time. This session ended with a crash.
OSession [ Error ] 11/5/2008 8:40:51 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 46 seconds with 0 seconds of active time. This session ended with a crash.
OSession [ Error ] 11/9/2008 12:57:31 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 111 seconds with 0 seconds of active time. This session ended with a crash.
System [ Error ] 11/30/2008 12:05:15 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 12:09:26 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 12:19:18 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 12:20:34 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 1:36:52 PM Computer Name = MOM | Source = DCOM | ID = 10010 -> Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.
System [ Error ] 11/30/2008 2:04:48 PM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 10:45:45 PM Computer Name = MOM | Source = Service Control Manager | ID = 7011 -> Description = Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
System [ Error ] 12/1/2008 11:15:40 AM Computer Name = MOM | Source = DCOM | ID = 10010 -> Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.
System [ Error ] 12/1/2008 11:40:49 AM Computer Name = MOM | Source = Srv | ID = 2000 -> Description = The server's call to a system service failed unexpectedly.
System [ Error ] 12/1/2008 11:40:49 AM Computer Name = MOM | Source = Srv | ID = 2000 -> Description = The server's call to a system service failed unexpectedly.
[Files/Folders - Created Within 90 Days]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp ->
examuy.dll -> %SystemRoot%\System32\examuy.dll -> [2008/11/30 22:30:19 | 00,129,024 | —- | C] ()
bsghddwu.dll -> %SystemRoot%\System32\bsghddwu.dll -> [2008/11/30 22:30:19 | 00,129,024 | —- | C] ()
ujnjymct.dll -> %SystemRoot%\System32\ujnjymct.dll -> [2008/11/30 22:30:02 | 00,129,024 | —- | C] ()
wthvwwmy.dll -> %SystemRoot%\System32\wthvwwmy.dll -> [2008/11/30 22:30:00 | 00,075,776 | —- | C] ()
veglaf.dll -> %SystemRoot%\System32\veglaf.dll -> [2008/11/30 22:30:00 | 00,075,776 | —- | C] ()
dicoejye.ini -> %SystemRoot%\System32\dicoejye.ini -> [2008/11/30 22:29:34 | 01,691,436 | -HS- | C] ()
eyjeocid.dll -> %SystemRoot%\System32\eyjeocid.dll -> [2008/11/30 22:29:34 | 00,072,704 | —- | C] ()
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/11/30 19:02:16 | 00,000,000 | —D | C]
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/11/30 19:00:18 | 00,536,920 | —- | C] ()
yvzcxo.dll -> %SystemRoot%\System32\yvzcxo.dll -> [2008/11/30 16:46:38 | 00,075,776 | —- | C] ()
ofmnnjam.dll -> %SystemRoot%\System32\ofmnnjam.dll -> [2008/11/30 16:46:38 | 00,075,776 | —- | C] ()
lecbjl.dll -> %SystemRoot%\System32\lecbjl.dll -> [2008/11/30 16:46:37 | 00,129,024 | —- | C] ()
lbwtoaac.dll -> %SystemRoot%\System32\lbwtoaac.dll -> [2008/11/30 16:46:36 | 00,129,024 | —- | C] ()
LopSD.exe -> %UserProfile%\Desktop\LopSD.exe -> [2008/11/30 15:44:00 | 00,529,069 | —- | C] ()
Lop SD -> %SystemDrive%\Lop SD -> [2008/11/30 10:21:31 | 00,000,000 | —D | C]
ERDNT -> %SystemRoot%\ERDNT -> [2008/11/29 19:44:00 | 00,000,000 | —D | C]
NTREGOPT.lnk -> %UserProfile%\Desktop\NTREGOPT.lnk -> [2008/11/29 19:43:29 | 00,000,519 | —- | C] ()
ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk -> [2008/11/29 19:43:29 | 00,000,500 | —- | C] ()
ERUNT -> %ProgramFiles%\ERUNT -> [2008/11/29 19:43:28 | 00,000,000 | —D | C]
erunt_setup.exe -> %UserProfile%\Desktop\erunt_setup.exe -> [2008/11/29 19:42:30 | 00,791,393 | —- | C] (Lars Hederer )
Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/11/29 19:32:31 | 00,000,000 | —D | C]
HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> [2008/11/29 19:32:13 | 00,812,344 | —- | C] (Trend Micro Inc.)
Hijackthis -> %ProgramFiles%\Hijackthis -> [2008/11/29 19:18:05 | 00,000,000 | —D | C]
nphnrvrs.ini -> %SystemRoot%\System32\nphnrvrs.ini -> [2008/11/29 16:48:13 | 01,691,436 | -HS- | C] ()
uvegyt.dll -> %SystemRoot%\System32\uvegyt.dll -> [2008/11/29 16:45:16 | 00,129,024 | —- | C] ()
snghoxvm.dll -> %SystemRoot%\System32\snghoxvm.dll -> [2008/11/29 16:45:15 | 00,129,024 | —- | C] ()
rmirseiq.ini -> %SystemRoot%\System32\rmirseiq.ini -> [2008/11/29 16:44:57 | 01,691,436 | -HS- | C] ()
jxmjgz.dll -> %SystemRoot%\System32\jxmjgz.dll -> [2008/11/29 16:44:33 | 00,075,776 | —- | C] ()
sxnbkwiy.dll -> %SystemRoot%\System32\sxnbkwiy.dll -> [2008/11/29 16:44:30 | 00,075,776 | —- | C] ()
~.exe -> %SystemRoot%\System32\~.exe -> [2008/11/28 21:17:08 | 00,061,952 | —- | C] ()
qomdne.dll -> %SystemRoot%\System32\qomdne.dll -> [2008/11/28 16:04:01 | 00,075,776 | —- | C] ()
hpuvxyhp.dll -> %SystemRoot%\System32\hpuvxyhp.dll -> [2008/11/28 16:04:00 | 00,075,776 | —- | C] ()
mfftix.dll -> %SystemRoot%\System32\mfftix.dll -> [2008/11/28 16:01:03 | 00,129,024 | —- | C] ()
aujmlggl.dll -> %SystemRoot%\System32\aujmlggl.dll -> [2008/11/28 16:01:01 | 00,129,024 | —- | C] ()
uwnnvtfw.ini -> %SystemRoot%\System32\uwnnvtfw.ini -> [2008/11/28 15:59:51 | 01,691,436 | -HS- | C] ()
McAfee -> %AppData%\McAfee -> [2008/11/28 11:28:01 | 00,000,000 | —D | C]
llwdna.dll -> %SystemRoot%\System32\llwdna.dll -> [2008/11/27 14:26:26 | 00,129,024 | —- | C] ()
sisbqrnt.dll -> %SystemRoot%\System32\sisbqrnt.dll -> [2008/11/27 14:26:25 | 00,129,024 | —- | C] ()
durgjtqm.ini -> %SystemRoot%\System32\durgjtqm.ini -> [2008/11/27 14:25:18 | 01,691,436 | -HS- | C] ()
uqveuyne.dll -> %SystemRoot%\System32\uqveuyne.dll -> [2008/11/27 14:21:24 | 00,075,776 | —- | C] ()
azpfhp.dll -> %SystemRoot%\System32\azpfhp.dll -> [2008/11/27 14:21:24 | 00,075,776 | —- | C] ()
zjstnc.dll -> %SystemRoot%\System32\zjstnc.dll -> [2008/11/27 14:11:10 | 00,075,776 | —- | C] ()
eskmtlpl.dll -> %SystemRoot%\System32\eskmtlpl.dll -> [2008/11/27 14:11:09 | 00,075,776 | —- | C] ()
appmgmt -> %SystemRoot%\System32\appmgmt -> [2008/11/27 01:03:27 | 00,000,000 | —D | C]
pss -> %SystemRoot%\pss -> [2008/11/26 23:03:40 | 00,000,000 | —D | C]
Config.MPF -> %SystemRoot%\System32\Config.MPF -> [2008/11/26 15:59:20 | 00,004,069 | —- | C] ()
McAfee Security Center.lnk -> %AllUsersProfile%\Desktop\McAfee Security Center.lnk -> [2008/11/26 15:43:49 | 00,000,579 | —- | C] ()
dunzip32.dll -> %SystemRoot%\System32\dunzip32.dll -> [2008/11/26 15:43:10 | 00,143,360 | —- | C] (Inner Media, Inc.)
mferkdk.sys -> %SystemRoot%\System32\drivers\mferkdk.sys -> [2008/11/26 15:39:27 | 00,033,832 | —- | C] (McAfee, Inc.)
mfehidk.sys -> %SystemRoot%\System32\drivers\mfehidk.sys -> [2008/11/26 15:39:22 | 00,201,320 | —- | C] (McAfee, Inc.)
mfeavfk.sys -> %SystemRoot%\System32\drivers\mfeavfk.sys -> [2008/11/26 15:39:22 | 00,079,304 | —- | C] (McAfee, Inc.)
mfesmfk.sys -> %SystemRoot%\System32\drivers\mfesmfk.sys -> [2008/11/26 15:39:22 | 00,040,488 | —- | C] (McAfee, Inc.)
mfebopk.sys -> %SystemRoot%\System32\drivers\mfebopk.sys -> [2008/11/26 15:39:22 | 00,035,240 | —- | C] (McAfee, Inc.)
Mpfp.sys -> %SystemRoot%\System32\drivers\Mpfp.sys -> [2008/11/26 15:39:01 | 00,113,952 | —- | C] (McAfee, Inc.)
McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [2008/11/26 15:38:24 | 00,000,344 | —- | C] ()
McQcTask.job -> %SystemRoot%\tasks\McQcTask.job -> [2008/11/26 15:38:23 | 00,000,336 | —- | C] ()
McAfee.com -> %ProgramFiles%\McAfee.com -> [2008/11/26 15:37:50 | 00,000,000 | —D | C]
McAfee -> %CommonProgramFiles%\McAfee -> [2008/11/26 15:37:36 | 00,000,000 | —D | C]
McAfee -> %ProgramFiles%\McAfee -> [2008/11/26 15:37:19 | 00,000,000 | —D | C]
McAfee -> %AllUsersProfile%\Application Data\McAfee -> [2008/11/26 15:16:45 | 00,000,000 | —D | C]
DMSetup-Serial.exe -> %UserProfile%\Desktop\DMSetup-Serial.exe -> [2008/11/26 15:16:18 | 01,226,248 | —- | C] (McAfee, Inc.)
txrjmu.dll -> %SystemRoot%\System32\txrjmu.dll -> [2008/11/26 11:36:50 | 00,075,776 | —- | C] ()
thqwcnrr.dll -> %SystemRoot%\System32\thqwcnrr.dll -> [2008/11/26 11:36:50 | 00,075,776 | —- | C] ()
atrfes.dll -> %SystemRoot%\System32\atrfes.dll -> [2008/11/26 11:36:25 | 00,075,776 | —- | C] ()
qmlsajge.dll -> %SystemRoot%\System32\qmlsajge.dll -> [2008/11/26 11:36:21 | 00,075,776 | —- | C] ()
ezwjpw.dll -> %SystemRoot%\System32\ezwjpw.dll -> [2008/11/26 11:15:41 | 00,129,024 | —- | C] ()
vvufqhjy.dll -> %SystemRoot%\System32\vvufqhjy.dll -> [2008/11/26 11:15:39 | 00,129,024 | —- | C] ()
rYFffMoq.ini2 -> %SystemRoot%\System32\rYFffMoq.ini2 -> [2008/11/26 11:12:38 | 00,901,656 | -HS- | C] ()
rYFffMoq.ini -> %SystemRoot%\System32\rYFffMoq.ini -> [2008/11/26 11:12:38 | 00,901,656 | -HS- | C] ()
qoMffFYr.dll -> %SystemRoot%\System32\qoMffFYr.dll -> [2008/11/26 11:12:29 | 00,318,464 | —- | C] ()
MSINET.OCX -> %SystemRoot%\System32\MSINET.OCX -> [2008/11/25 23:29:39 | 00,115,016 | —- | C] (Microsoft Corporation)
MSINET.oca -> %SystemRoot%\System32\MSINET.oca -> [2008/11/25 23:29:39 | 00,029,184 | —- | C] ()
MSINET.DEP -> %SystemRoot%\System32\MSINET.DEP -> [2008/11/25 23:29:39 | 00,002,407 | —- | C] ()
2008-09-Faith Formation calendar.pdf -> %UserProfile%\Desktop\2008-09-Faith Formation calendar.pdf -> [2008/11/23 19:27:01 | 00,277,116 | —- | C] ()
~$ristmas lists.docx -> %UserProfile%\My Documents\~$ristmas lists.docx -> [2008/11/23 13:43:44 | 00,000,162 | -H– | C] ()
Christmas lists.docx -> %UserProfile%\My Documents\Christmas lists.docx -> [2008/11/23 13:43:43 | 00,013,677 | —- | C] ()
OneNote Notebooks -> %UserProfile%\My Documents\OneNote Notebooks -> [2008/11/23 13:06:03 | 00,000,000 | —D | C]
OneNote 2007 Screen Clipper and Launcher.lnk -> %UserProfile%\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> [2008/11/23 13:06:02 | 00,000,855 | —- | C] ()
FOUND.020 -> %SystemDrive%\FOUND.020 -> [2008/11/17 20:40:24 | 00,000,000 | -HSD | C]
osaio.sys -> %SystemRoot%\System32\drivers\osaio.sys -> [2008/11/13 18:08:59 | 00,007,296 | —- | C] (OSA Technologies, An Avocent Company)
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/11/13 18:08:57 | 00,000,006 | -H– | C] ()
FOUND.019 -> %SystemDrive%\FOUND.019 -> [2008/11/13 18:07:32 | 00,000,000 | -HSD | C]
110908_bento_closeup.JPG -> %UserProfile%\Desktop\110908_bento_closeup.JPG -> [2008/11/09 22:31:45 | 00,306,112 | —- | C] ()
110908_bento.JPG -> %UserProfile%\Desktop\110908_bento.JPG -> [2008/11/09 22:31:05 | 00,938,713 | —- | C] ()
Reading Log.docx -> %UserProfile%\My Documents\Reading Log.docx -> [2008/11/09 18:50:23 | 00,011,382 | —- | C] ()
~$ading Log.docx -> %UserProfile%\My Documents\~$ading Log.docx -> [2008/11/09 18:50:23 | 00,000,162 | -H– | C] ()
my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> %UserProfile%\My Documents\my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> [2008/11/08 22:36:04 | 00,377,436 | —- | C] ()
gen's page -> %UserProfile%\Desktop\gen's page -> [2008/11/02 19:02:13 | 00,000,000 | —D | C]
CURRENT EVENTS worksheet.doc -> %UserProfile%\My Documents\CURRENT EVENTS worksheet.doc -> [2008/10/29 21:29:54 | 00,025,088 | —- | C] ()
2009 calendar.docx -> %UserProfile%\Desktop\2009 calendar.docx -> [2008/10/22 19:20:10 | 00,035,851 | —- | C] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/10/19 23:32:56 | 04,843,052 | -H– | C] ()
bthservsdp.dat -> %SystemRoot%\bthservsdp.dat -> [2008/10/18 23:17:05 | 00,000,012 | —- | C] ()
FOUND.018 -> %SystemDrive%\FOUND.018 -> [2008/10/18 22:07:44 | 00,000,000 | -HSD | C]
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/10/17 14:50:46 | 00,002,137 | —- | C] ()
iPod -> %ProgramFiles%\iPod -> [2008/10/17 14:50:28 | 00,000,000 | —D | C]
iTunes -> %ProgramFiles%\iTunes -> [2008/10/17 14:50:27 | 00,000,000 | —D | C]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> %AllUsersProfile%\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/10/17 14:50:27 | 00,000,000 | —D | C]
christmas2.JPG -> %UserProfile%\My Documents\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | C] ()
christmas2.JPG -> %UserProfile%\Desktop\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | C] ()
Amelia.jpg -> %UserProfile%\Desktop\Amelia.jpg -> [2008/10/12 21:52:00 | 00,098,782 | —- | C] ()
FOUND.017 -> %SystemDrive%\FOUND.017 -> [2008/10/12 19:00:26 | 00,000,000 | -HSD | C]
Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> %UserProfile%\Desktop\Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> [2008/10/08 19:14:17 | 00,058,880 | —- | C] ()
FOUND.016 -> %SystemDrive%\FOUND.016 -> [2008/10/08 18:20:56 | 00,000,000 | -HSD | C]
cruises.doc -> %UserProfile%\Desktop\cruises.doc -> [2008/10/04 19:25:03 | 00,019,968 | —- | C] ()
Smarter_than_a_5th_grader%281%29(1).xls -> %UserProfile%\Desktop\Smarter_than_a_5th_grader%281%29(1).xls -> [2008/10/03 13:47:16 | 00,152,576 | —- | C] ()
Oct-Dec2008.docx -> %UserProfile%\Desktop\Oct-Dec2008.docx -> [2008/10/02 20:58:46 | 00,017,099 | —- | C] ()
msxml4.dll -> %SystemRoot%\System32\msxml4.dll -> [2008/09/30 16:43:34 | 01,286,152 | —- | C] (Microsoft Corporation)
Cruise -> %UserProfile%\Desktop\Cruise -> [2008/09/25 23:43:33 | 00,000,000 | —D | C]
clip_image001.jpg -> %UserProfile%\My Documents\clip_image001.jpg -> [2008/09/24 19:43:06 | 00,200,640 | —- | C] ()
marscam.ini -> %SystemRoot%\marscam.ini -> [2008/09/20 15:20:41 | 00,000,037 | —- | C] ()
Bug chart.docx -> %AllUsersProfile%\Documents\Bug chart.docx -> [2008/09/20 13:45:18 | 00,011,106 | —- | C] ()
~$g chart.docx -> %AllUsersProfile%\Documents\~$g chart.docx -> [2008/09/20 13:45:18 | 00,000,162 | -H– | C] ()
Sept 12 LArts.pdf -> %AllUsersProfile%\Documents\Sept 12 LArts.pdf -> [2008/09/13 16:42:57 | 00,124,655 | —- | C] ()
Life Science Assignments.doc -> %AllUsersProfile%\Documents\Life Science Assignments.doc -> [2008/09/13 16:39:21 | 00,062,464 | —- | C] ()
Bonjour -> %ProgramFiles%\Bonjour -> [2008/09/09 19:39:23 | 00,000,000 | —D | C]
QuickTime -> %ProgramFiles%\QuickTime -> [2008/09/09 19:37:12 | 00,000,000 | —D | C]
FOUND.015 -> %SystemDrive%\FOUND.015 -> [2008/09/02 22:35:28 | 00,000,000 | -HSD | C]
Sun -> %ProgramFiles%\Sun -> [2008/09/02 20:10:42 | 00,000,000 | —D | C]
[Files/Folders - Modified Within 90 Days]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp ->
C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help -> [2006/08/23 02:40:56 | 00,000,000 | —D | M]
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [2008/11/26 19:06:50 | 00,001,306 | —- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2006/12/26 18:14:40 | 00,000,000 | —D | M]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/11/11 23:27:04 | 00,055,955 | —- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/11/11 23:27:04 | 00,055,570 | —- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2007/06/02 19:26:56 | 00,000,000 | —D | M]
opa12.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [2007/06/02 19:33:34 | 00,008,416 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp -> [2006/08/23 02:29:04 | 00,000,000 | —D | M]
RtkBtMnt.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\RtkBtMnt.exe -> [2007/05/02 23:43:32 | 00,208,896 | —- | M] (Realtek Semiconductor Corp.)
gds1033.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\gds1033.exe -> [2007/03/14 04:16:08 | 00,746,600 | —- | M] ()
ycomp_setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ycomp_setup.exe -> [2006/09/12 15:57:58 | 00,866,840 | —- | M] ()
ose00000.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ose00000.exe -> [2006/10/30 05:35:16 | 00,145,184 | R— | M] (Microsoft Corporation)
jre-6u2-windows-i586-p-iftw_7070c3f7.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\jre-6u2-windows-i586-p-iftw_7070c3f7.exe -> [2007/07/12 15:45:16 | 00,382,352 | —- | M] (Sun Microsystems, Inc.)
ytb_7.0.8.0_1.4.1_ysp_1.2_pub_us_setup_.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ytb_7.0.8.0_1.4.1_ysp_1.2_pub_us_setup_.exe -> [2007/11/07 18:45:00 | 01,788,000 | —- | M] (Yahoo! Inc.)
wic.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\wic.exe -> [2008/06/11 18:27:58 | 01,227,048 | —- | M] (Microsoft Corporation)
dotnet.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\dotnet.exe -> [2008/06/11 18:28:52 | 24,758,792 | —- | M] (Microsoft Corporation)
SymLCSVC.EXE -> C:\Documents and Settings\Maryann\Local Settings\Temp\SymLCSVC.EXE -> [2008/11/26 15:30:44 | 01,119,888 | —- | M] (Symantec Corporation)
1549 C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp ->
C:\Documents and Settings\Maryann\Local Settings\Temp\_ir_sf7_temp_0\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\_ir_sf7_temp_0 -> [2007/09/15 10:37:32 | 00,000,000 | —D | M]
irsetup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\_ir_sf7_temp_0\irsetup.exe -> [2007/09/15 10:37:32 | 00,473,600 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8 -> [2007/06/21 22:54:00 | 00,000,000 | —D | M]
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8\Setup.exe -> [2007/05/11 03:50:42 | 00,304,784 | —- | M] (Adobe Systems Incorporated)
C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8_\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8_ -> [2007/11/04 01:15:04 | 00,000,000 | —D | M]
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8_\Setup.exe -> [2007/05/11 03:50:42 | 00,304,784 | —- | M] (Adobe Systems Incorporated)
C:\Documents and Settings\Maryann\Local Settings\Temp\ICD1.tmp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD1.tmp\ -> [2007/03/05 20:45:18 | 00,000,000 | —D | M]
jinstall.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD1.tmp\jinstall.exe -> [2007/01/30 16:28:04 | 00,245,873 | —- | M] (Sun Microsystems, Inc.)
C:\Documents and Settings\Maryann\Local Settings\Temp\ICD2.tmp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD2.tmp\ -> [2008/09/02 20:08:16 | 00,000,000 | —D | M]
jinstall.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD2.tmp\jinstall.exe -> [2008/06/10 04:55:10 | 00,376,832 | —- | M] (Sun Microsystems, Inc.)
C:\Documents and Settings\Maryann\Local Settings\Temp\pft4~tmp\Disk1\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\pft4~tmp\Disk1 -> [2008/01/20 09:44:26 | 00,000,000 | —D | M]
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\pft4~tmp\Disk1\Setup.exe -> [2000/10/05 16:00:06 | 00,054,272 | —- | M] (InstallShield Software Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164 -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
ChCfg.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\ChCfg.exe -> [2006/08/01 15:02:32 | 00,049,152 | —- | M] ()
SetCDfmt.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\SetCDfmt.exe -> [2001/12/03 01:27:00 | 00,023,552 | —- | M] ()
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\Setup.exe -> [2005/11/14 16:24:00 | 00,121,064 | —- | M] (Macrovision Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
kb888111w2ksp4.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\kb888111w2ksp4.exe -> [2005/01/07 18:18:00 | 00,742,104 | R— | M] (Microsoft Corporation)
kb888111xpsp1.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\kb888111xpsp1.exe -> [2005/01/07 18:15:00 | 00,774,360 | R— | M] (Microsoft Corporation)
kb888111xpsp2.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\kb888111xpsp2.exe -> [2005/01/10 11:15:00 | 00,720,088 | R— | M] (Microsoft Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K3\us\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K3\us -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
kb888111srvrtm.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K3\us\kb888111srvrtm.exe -> [2005/01/07 18:23:00 | 00,771,288 | R— | M] (Microsoft Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
Alcmtr.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\Alcmtr.exe -> [2005/05/03 18:43:28 | 00,069,632 | —- | M] (Realtek Semiconductor Corp.)
AlcWzrd.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\AlcWzrd.exe -> [2006/05/04 16:26:36 | 02,808,832 | —- | M] (RealTek Semicoductor Corp.)
CPLUtl64.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\CPLUtl64.exe -> [2006/03/30 18:58:22 | 00,037,376 | —- | M] ()
MicCal.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\MicCal.exe -> [2006/10/11 17:42:58 | 02,157,568 | —- | M] (Realtek Semiconductor Corp.)
RTHDCPL.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RTHDCPL.exe -> [2007/03/21 14:49:20 | 16,126,464 | —- | M] (Realtek Semiconductor Corp.)
RTLCPL.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RTLCPL.exe -> [2007/03/23 19:19:10 | 09,715,200 | —- | M] (Realtek Semiconductor Corp.)
RtlUpd.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RtlUpd.exe -> [2007/01/16 10:39:36 | 01,191,936 | —- | M] (Realtek Semiconductor Corp.)
RtlUpd64.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RtlUpd64.exe -> [2007/01/16 10:39:24 | 01,356,800 | —- | M] (Realtek Semiconductor Corp.)
SkyTel.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\SkyTel.exe -> [2007/03/16 15:06:54 | 01,822,720 | —- | M] (Realtek Semiconductor Corp.)
SoundMan.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\SoundMan.exe -> [2006/07/21 16:14:36 | 00,086,016 | —- | M] (Realtek Semiconductor Corp.)
C:\Documents and Settings\Maryann\Local Settings\Temp\_PASFX531\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\_PASFX531 -> [2008/03/11 22:43:56 | 00,000,000 | —D | M]
7Z.DLL -> C:\Documents and Settings\Maryann\Local Settings\Temp\_PASFX531\7Z.DLL -> [2008/03/11 22:43:58 | 00,076,288 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\PRE2AD.tmp\x64\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\PRE2AD.tmp\x64 -> [2008/11/26 15:36:44 | 00,000,000 | —D | M]
McShield.DLL -> C:\Documents and Settings\Maryann\Local Settings\Temp\PRE2AD.tmp\x64\McShield.DLL -> [2007/07/24 12:01:38 | 00,024,384 | —- | M] (McAfee, Inc.)
C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\ -> [2008/01/20 09:43:44 | 00,000,000 | —D | M]
proj.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\proj.dll -> [2008/01/20 09:43:44 | 00,151,552 | —- | M] (Macromedia, Inc.)
dirapi.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\dirapi.dll -> [2008/01/20 09:43:46 | 01,097,728 | —- | M] (Macromedia, Inc.)
iml32.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\iml32.dll -> [2008/01/20 09:43:46 | 00,561,152 | —- | M] (Macromedia, Inc.)
msvcrt.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\msvcrt.dll -> [2008/01/20 09:43:46 | 00,266,293 | —- | M] (Microsoft Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164 -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
RtlExUpd.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\RtlExUpd.dll -> [2007/01/12 16:54:44 | 00,520,192 | —- | M] (Realtek Semiconductor Corp.)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
RTCOMDLL.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RTCOMDLL.dll -> [2007/03/15 14:39:04 | 00,262,144 | —- | M] ()
RtlCPAPI.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RtlCPAPI.dll -> [2007/03/07 14:59:30 | 00,131,072 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp -> [2006/08/23 02:29:04 | 00,000,000 | —D | M]
symcprop.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\symcprop.dat -> [2008/11/26 15:30:16 | 00,008,708 | —- | M] ()
SSALiveUpdate.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\SSALiveUpdate.dat -> [2008/11/26 15:27:14 | 00,000,124 | —- | M] ()
AVRES_OPTRF_LiveUpdate.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\AVRES_OPTRF_LiveUpdate.dat -> [2008/11/26 15:26:28 | 00,000,124 | —- | M] ()
AVSTELiveUpdate.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\AVSTELiveUpdate.dat -> [2008/11/26 15:30:16 | 00,000,124 | —- | M] ()
1549 C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp ->
C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2006/08/23 04:03:42 | 00,000,000 | —D | M]
GVista.exe -> C:\WINDOWS\Temp\GVista.exe -> [2006/03/09 01:24:30 | 00,628,030 | —- | M] ()
setup.exe -> C:\WINDOWS\Temp\setup.exe -> [2004/12/09 17:58:00 | 00,438,272 | —- | M] (Dritek System Inc.)
Uninstall_eRecovery.exe -> C:\WINDOWS\Temp\Uninstall_eRecovery.exe -> [2005/09/26 16:40:32 | 00,258,048 | —- | M] (Acer Inc.)
3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
C:\WINDOWS\Temp\EMEAWG\ -> C:\WINDOWS\Temp\EMEAWG -> [2006/12/26 02:51:16 | 00,000,000 | —D | M]
Setup.exe -> C:\WINDOWS\Temp\EMEAWG\Setup.exe -> [2006/09/23 12:19:10 | 00,165,888 | —- | M] (Microsoft Corporation)
CC_Install.exe -> C:\WINDOWS\Temp\EMEAWG\CC_Install.exe -> [2006/09/23 12:05:32 | 00,049,152 | —- | M] (Acer Inc.)
C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2006/08/23 04:03:42 | 00,000,000 | —D | M]
CloseProcessWindow.dll -> C:\WINDOWS\Temp\CloseProcessWindow.dll -> [2004/11/03 09:06:50 | 00,159,744 | —- | M] (acer inc.)
HkWndMsgU.dll -> C:\WINDOWS\Temp\HkWndMsgU.dll -> [2006/01/09 14:53:30 | 00,192,512 | —- | M] (Dritek System Inc.)
HkWndMsgU64.dll -> C:\WINDOWS\Temp\HkWndMsgU64.dll -> [2006/01/09 14:54:24 | 00,218,624 | —- | M] (Dritek System Inc.)
MMDUtl.dll -> C:\WINDOWS\Temp\MMDUtl.dll -> [2006/02/08 18:38:40 | 00,208,896 | —- | M] (Dritek System Inc.)
SetupDev.dll -> C:\WINDOWS\Temp\SetupDev.dll -> [2004/11/01 11:58:42 | 00,057,344 | —- | M] (Dritek System Inc.)
3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
C:\WINDOWS\Temp\EMEAWG\ -> C:\WINDOWS\Temp\EMEAWG -> [2006/12/26 02:51:16 | 00,000,000 | —D | M]
Microsoft.VisualBasic.Compatibility.dll -> C:\WINDOWS\Temp\EMEAWG\Microsoft.VisualBasic.Compatibility.dll -> [2003/03/19 01:53:26 | 00,237,568 | —- | M] (Microsoft Corporation)
C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2006/08/23 04:03:42 | 00,000,000 | —D | M]
Perflib_Perfdata_54c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_54c.dat -> [2008/11/26 11:13:16 | 00,016,384 | —- | M] ()
Perflib_Perfdata_f24.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f24.dat -> [2008/11/27 11:13:50 | 00,016,384 | —- | M] ()
Perflib_Perfdata_16ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_16ac.dat -> [2008/11/28 11:22:16 | 00,016,384 | —- | M] ()
Perflib_Perfdata_cf4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cf4.dat -> [2008/11/28 15:58:48 | 00,016,384 | —- | M] ()
Perflib_Perfdata_d10.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d10.dat -> [2008/11/29 16:43:38 | 00,016,384 | —- | M] ()
Perflib_Perfdata_8d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8d4.dat -> [2008/11/30 10:22:06 | 00,016,384 | —- | M] ()
Perflib_Perfdata_e5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e5c.dat -> [2008/11/30 22:28:36 | 00,016,384 | —- | M] ()
3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
C:\WINDOWS\Temp\Cookies\ -> C:\WINDOWS\Temp\Cookies -> [2006/12/26 00:34:18 | 00,000,000 | -HSD | M]
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [2008/12/01 07:15:00 | 00,016,384 | —- | M] ()
C:\WINDOWS\Temp\History\History.IE5\ -> C:\WINDOWS\Temp\History\History.IE5\ -> [2006/12/26 00:34:18 | 00,000,000 | -HSD | M]
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2008/12/01 07:15:00 | 00,016,384 | —- | M] ()
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> [2006/12/26 00:34:18 | 00,000,000 | -HSD | M]
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/12/01 07:15:00 | 00,032,768 | —- | M] ()
ponihiti -> %SystemRoot%\System32\ponihiti -> [2008/12/01 09:56:14 | 00,008,812 | -H– | M] ()
rYFffMoq.ini -> %SystemRoot%\System32\rYFffMoq.ini -> [2008/12/01 09:56:04 | 00,901,656 | -HS- | M] ()
rYFffMoq.ini2 -> %SystemRoot%\System32\rYFffMoq.ini2 -> [2008/12/01 09:54:46 | 00,901,656 | -HS- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/12/01 09:37:38 | 00,001,158 | —- | M] ()
eRLog.ini -> %SystemRoot%\System32\eRLog.ini -> [2008/12/01 09:37:24 | 00,000,454 | —- | M] ()
nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [2008/12/01 09:36:32 | 00,051,048 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/12/01 09:35:54 | 00,000,006 | -H– | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/12/01 09:35:46 | 00,002,048 | –S- | M] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2008/12/01 09:35:38 | 21,455,05280 | -HS- | M] ()
Config.MPF -> %SystemRoot%\System32\Config.MPF -> [2008/12/01 09:15:42 | 00,004,069 | —- | M] ()
bthservsdp.dat -> %SystemRoot%\bthservsdp.dat -> [2008/12/01 09:15:42 | 00,000,012 | —- | M] ()
examuy.dll -> %SystemRoot%\System32\examuy.dll -> [2008/11/30 22:30:20 | 00,129,024 | —- | M] ()
bsghddwu.dll -> %SystemRoot%\System32\bsghddwu.dll -> [2008/11/30 22:30:20 | 00,129,024 | —- | M] ()
ujnjymct.dll -> %SystemRoot%\System32\ujnjymct.dll -> [2008/11/30 22:30:04 | 00,129,024 | —- | M] ()
wthvwwmy.dll -> %SystemRoot%\System32\wthvwwmy.dll -> [2008/11/30 22:30:02 | 00,075,776 | —- | M] ()
veglaf.dll -> %SystemRoot%\System32\veglaf.dll -> [2008/11/30 22:30:02 | 00,075,776 | —- | M] ()
dicoejye.ini -> %SystemRoot%\System32\dicoejye.ini -> [2008/11/30 22:29:46 | 01,691,436 | -HS- | M] ()
eyjeocid.dll -> %SystemRoot%\System32\eyjeocid.dll -> [2008/11/30 22:29:36 | 00,072,704 | —- | M] ()
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/11/30 19:00:22 | 00,536,920 | —- | M] ()
nphnrvrs.ini -> %SystemRoot%\System32\nphnrvrs.ini -> [2008/11/30 16:48:54 | 01,691,436 | -HS- | M] ()
yvzcxo.dll -> %SystemRoot%\System32\yvzcxo.dll -> [2008/11/30 16:46:40 | 00,075,776 | —- | M] ()
ofmnnjam.dll -> %SystemRoot%\System32\ofmnnjam.dll -> [2008/11/30 16:46:40 | 00,075,776 | —- | M] ()
lecbjl.dll -> %SystemRoot%\System32\lecbjl.dll -> [2008/11/30 16:46:38 | 00,129,024 | —- | M] ()
lbwtoaac.dll -> %SystemRoot%\System32\lbwtoaac.dll -> [2008/11/30 16:46:38 | 00,129,024 | —- | M] ()
LopSD.exe -> %UserProfile%\Desktop\LopSD.exe -> [2008/11/30 15:44:02 | 00,529,069 | —- | M] ()
NTREGOPT.lnk -> %UserProfile%\Desktop\NTREGOPT.lnk -> [2008/11/29 19:43:30 | 00,000,519 | —- | M] ()
ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk -> [2008/11/29 19:43:30 | 00,000,500 | —- | M] ()
erunt_setup.exe -> %UserProfile%\Desktop\erunt_setup.exe -> [2008/11/29 19:42:34 | 00,791,393 | —- | M] (Lars Hederer )
HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> [2008/11/29 19:32:16 | 00,812,344 | —- | M] (Trend Micro Inc.)
uvegyt.dll -> %SystemRoot%\System32\uvegyt.dll -> [2008/11/29 16:45:18 | 00,129,024 | —- | M] ()
snghoxvm.dll -> %SystemRoot%\System32\snghoxvm.dll -> [2008/11/29 16:45:18 | 00,129,024 | —- | M] ()
rmirseiq.ini -> %SystemRoot%\System32\rmirseiq.ini -> [2008/11/29 16:45:08 | 01,691,436 | -HS- | M] ()
sxnbkwiy.dll -> %SystemRoot%\System32\sxnbkwiy.dll -> [2008/11/29 16:44:32 | 00,075,776 | —- | M] ()
jxmjgz.dll -> %SystemRoot%\System32\jxmjgz.dll -> [2008/11/29 16:44:32 | 00,075,776 | —- | M] ()
uwnnvtfw.ini -> %SystemRoot%\System32\uwnnvtfw.ini -> [2008/11/29 16:43:54 | 01,691,436 | -HS- | M] ()
Gift lists.xlsx -> %UserProfile%\My Documents\Gift lists.xlsx -> [2008/11/29 00:01:48 | 00,020,492 | —- | M] ()
~.exe -> %SystemRoot%\System32\~.exe -> [2008/11/28 21:17:24 | 00,061,952 | —- | M] ()
qomdne.dll -> %SystemRoot%\System32\qomdne.dll -> [2008/11/28 16:04:02 | 00,075,776 | —- | M] ()
hpuvxyhp.dll -> %SystemRoot%\System32\hpuvxyhp.dll -> [2008/11/28 16:04:02 | 00,075,776 | —- | M] ()
mfftix.dll -> %SystemRoot%\System32\mfftix.dll -> [2008/11/28 16:01:02 | 00,129,024 | —- | M] ()
aujmlggl.dll -> %SystemRoot%\System32\aujmlggl.dll -> [2008/11/28 16:01:02 | 00,129,024 | —- | M] ()
durgjtqm.ini -> %SystemRoot%\System32\durgjtqm.ini -> [2008/11/28 15:59:32 | 01,691,436 | -HS- | M] ()
sisbqrnt.dll -> %SystemRoot%\System32\sisbqrnt.dll -> [2008/11/27 14:26:28 | 00,129,024 | —- | M] ()
llwdna.dll -> %SystemRoot%\System32\llwdna.dll -> [2008/11/27 14:26:28 | 00,129,024 | —- | M] ()
uqveuyne.dll -> %SystemRoot%\System32\uqveuyne.dll -> [2008/11/27 14:21:26 | 00,075,776 | —- | M] ()
azpfhp.dll -> %SystemRoot%\System32\azpfhp.dll -> [2008/11/27 14:21:26 | 00,075,776 | —- | M] ()
zjstnc.dll -> %SystemRoot%\System32\zjstnc.dll -> [2008/11/27 14:11:12 | 00,075,776 | —- | M] ()
eskmtlpl.dll -> %SystemRoot%\System32\eskmtlpl.dll -> [2008/11/27 14:11:12 | 00,075,776 | —- | M] ()
McAfee Security Center.lnk -> %AllUsersProfile%\Desktop\McAfee Security Center.lnk -> [2008/11/26 15:43:50 | 00,000,579 | —- | M] ()
McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [2008/11/26 15:38:26 | 00,000,344 | —- | M] ()
McQcTask.job -> %SystemRoot%\tasks\McQcTask.job -> [2008/11/26 15:38:24 | 00,000,336 | —- | M] ()
DMSetup-Serial.exe -> %UserProfile%\Desktop\DMSetup-Serial.exe -> [2008/11/26 15:16:16 | 01,226,248 | —- | M] (McAfee, Inc.)
txrjmu.dll -> %SystemRoot%\System32\txrjmu.dll -> [2008/11/26 11:36:52 | 00,075,776 | —- | M] ()
thqwcnrr.dll -> %SystemRoot%\System32\thqwcnrr.dll -> [2008/11/26 11:36:52 | 00,075,776 | —- | M] ()
qmlsajge.dll -> %SystemRoot%\System32\qmlsajge.dll -> [2008/11/26 11:36:22 | 00,075,776 | —- | M] ()
atrfes.dll -> %SystemRoot%\System32\atrfes.dll -> [2008/11/26 11:36:22 | 00,075,776 | —- | M] ()
vvufqhjy.dll -> %SystemRoot%\System32\vvufqhjy.dll -> [2008/11/26 11:15:42 | 00,129,024 | —- | M] ()
ezwjpw.dll -> %SystemRoot%\System32\ezwjpw.dll -> [2008/11/26 11:15:42 | 00,129,024 | —- | M] ()
qoMffFYr.dll -> %SystemRoot%\System32\qoMffFYr.dll -> [2008/11/26 11:12:36 | 00,318,464 | —- | M] ()
MSINET.OCX -> %SystemRoot%\System32\MSINET.OCX -> [2008/11/25 23:29:40 | 00,115,016 | —- | M] (Microsoft Corporation)
MSINET.oca -> %SystemRoot%\System32\MSINET.oca -> [2008/11/25 23:29:40 | 00,029,184 | —- | M] ()
MSINET.DEP -> %SystemRoot%\System32\MSINET.DEP -> [2008/11/25 23:29:40 | 00,002,407 | —- | M] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/11/25 17:17:14 | 00,002,137 | —- | M] ()
Oct-Dec2008.docx -> %UserProfile%\Desktop\Oct-Dec2008.docx -> [2008/11/23 19:28:00 | 00,017,099 | —- | M] ()
2008-09-Faith Formation calendar.pdf -> %UserProfile%\Desktop\2008-09-Faith Formation calendar.pdf -> [2008/11/23 19:27:02 | 00,277,116 | —- | M] ()
Christmas lists.docx -> %UserProfile%\My Documents\Christmas lists.docx -> [2008/11/23 19:20:40 | 00,013,677 | —- | M] ()
~$ristmas lists.docx -> %UserProfile%\My Documents\~$ristmas lists.docx -> [2008/11/23 13:43:46 | 00,000,162 | -H– | M] ()
OneNote 2007 Screen Clipper and Launcher.lnk -> %UserProfile%\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> [2008/11/23 13:06:04 | 00,000,855 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/11/11 23:24:16 | 00,001,393 | —- | M] ()
110908_bento_closeup.JPG -> %UserProfile%\Desktop\110908_bento_closeup.JPG -> [2008/11/09 22:32:02 | 00,306,112 | —- | M] ()
110908_bento.JPG -> %UserProfile%\Desktop\110908_bento.JPG -> [2008/11/09 22:30:50 | 00,938,713 | —- | M] ()
Reading Log.docx -> %UserProfile%\My Documents\Reading Log.docx -> [2008/11/09 18:57:28 | 00,011,382 | —- | M] ()
~$ading Log.docx -> %UserProfile%\My Documents\~$ading Log.docx -> [2008/11/09 18:50:24 | 00,000,162 | -H– | M] ()
my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> %UserProfile%\My Documents\my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> [2008/11/08 22:36:06 | 00,377,436 | —- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/11/02 19:18:34 | 00,020,992 | —- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/11/02 08:34:18 | 01,662,432 | —- | M] ()
Virtual Earth.lnk -> %AllUsersProfile%\Desktop\Virtual Earth.lnk -> [2008/11/01 17:08:58 | 00,001,809 | —- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/11/01 16:14:14 | 04,843,052 | -H– | M] ()
CURRENT EVENTS worksheet.doc -> %UserProfile%\My Documents\CURRENT EVENTS worksheet.doc -> [2008/10/29 21:29:56 | 00,025,088 | —- | M] ()
mrxsmb.sys -> %SystemRoot%\System32\drivers\mrxsmb.sys -> [2008/10/24 05:10:42 | 00,453,632 | —- | M] (Microsoft Corporation)
mrxsmb.sys -> %SystemRoot%\System32\dllcache\mrxsmb.sys -> [2008/10/24 05:10:42 | 00,453,632 | —- | M] (Microsoft Corporation)
2009 calendar.docx -> %UserProfile%\Desktop\2009 calendar.docx -> [2008/10/22 19:20:12 | 00,035,851 | —- | M] ()
wuaueng.dll -> %SystemRoot%\System32\wuaueng.dll -> [2008/10/16 14:13:40 | 01,809,944 | —- | M] (Microsoft Corporation)
wuaueng.dll -> %SystemRoot%\System32\dllcache\wuaueng.dll -> [2008/10/16 14:13:40 | 01,809,944 | —- | M] (Microsoft Corporation)
wuweb.dll -> %SystemRoot%\System32\wuweb.dll -> [2008/10/16 14:13:40 | 00,202,776 | —- | M] (Microsoft Corporation)
wuweb.dll -> %SystemRoot%\System32\dllcache\wuweb.dll -> [2008/10/16 14:13:40 | 00,202,776 | —- | M] (Microsoft Corporation)
wucltui.dll -> %SystemRoot%\System32\wucltui.dll -> [2008/10/16 14:12:22 | 00,323,608 | —- | M] (Microsoft Corporation)
wucltui.dll -> %SystemRoot%\System32\dllcache\wucltui.dll -> [2008/10/16 14:12:22 | 00,323,608 | —- | M] (Microsoft Corporation)
wuapi.dll -> %SystemRoot%\System32\wuapi.dll -> [2008/10/16 14:12:20 | 00,561,688 | —- | M] (Microsoft Corporation)
wuapi.dll -> %SystemRoot%\System32\dllcache\wuapi.dll -> [2008/10/16 14:12:20 | 00,561,688 | —- | M] (Microsoft Corporation)
wuaucpl.cpl -> %SystemRoot%\System32\wuaucpl.cpl -> [2008/10/16 14:12:20 | 00,213,528 | —- | M] (Microsoft Corporation)
wuaucpl.cpl -> %SystemRoot%\System32\dllcache\wuaucpl.cpl -> [2008/10/16 14:12:20 | 00,213,528 | —- | M] (Microsoft Corporation)
cdm.dll -> %SystemRoot%\System32\dllcache\cdm.dll -> [2008/10/16 14:09:44 | 00,092,696 | —- | M] (Microsoft Corporation)
cdm.dll -> %SystemRoot%\System32\cdm.dll -> [2008/10/16 14:09:44 | 00,092,696 | —- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\System32\wuauclt.exe -> [2008/10/16 14:09:44 | 00,051,224 | —- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\System32\dllcache\wuauclt.exe -> [2008/10/16 14:09:44 | 00,051,224 | —- | M] (Microsoft Corporation)
wups2.dll -> %SystemRoot%\System32\wups2.dll -> [2008/10/16 14:09:44 | 00,043,544 | —- | M] (Microsoft Corporation)
wucltui.dll.mui -> %SystemRoot%\System32\wucltui.dll.mui -> [2008/10/16 14:09:40 | 00,031,768 | —- | M] (Microsoft Corporation)
wups.dll -> %SystemRoot%\System32\wups.dll -> [2008/10/16 14:08:58 | 00,034,328 | —- | M] (Microsoft Corporation)
wups.dll -> %SystemRoot%\System32\dllcache\wups.dll -> [2008/10/16 14:08:58 | 00,034,328 | —- | M] (Microsoft Corporation)
wuaucpl.cpl.mui -> %SystemRoot%\System32\wuaucpl.cpl.mui -> [2008/10/16 14:07:46 | 00,023,576 | —- | M] (Microsoft Corporation)
wuapi.dll.mui -> %SystemRoot%\System32\wuapi.dll.mui -> [2008/10/16 14:07:44 | 00,023,576 | —- | M] (Microsoft Corporation)
wuaueng.dll.mui -> %SystemRoot%\System32\wuaueng.dll.mui -> [2008/10/16 14:07:14 | 00,018,456 | —- | M] (Microsoft Corporation)
mucltui.dll -> %SystemRoot%\System32\mucltui.dll -> [2008/10/16 14:06:48 | 00,268,648 | —- | M] (Microsoft Corporation)
muweb.dll -> %SystemRoot%\System32\muweb.dll -> [2008/10/16 14:06:48 | 00,208,744 | —- | M] (Microsoft Corporation)
mucltui.dll.mui -> %SystemRoot%\System32\mucltui.dll.mui -> [2008/10/16 14:06:48 | 00,027,496 | —- | M] (Microsoft Corporation)
netapi32.dll -> %SystemRoot%\System32\netapi32.dll -> [2008/10/15 11:57:56 | 00,332,800 | —- | M] (Microsoft Corporation)
netapi32.dll -> %SystemRoot%\System32\dllcache\netapi32.dll -> [2008/10/15 11:57:56 | 00,332,800 | —- | M] (Microsoft Corporation)
christmas2.JPG -> %UserProfile%\My Documents\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | M] ()
christmas2.JPG -> %UserProfile%\Desktop\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | M] ()
Amelia.jpg -> %UserProfile%\Desktop\Amelia.jpg -> [2008/10/12 21:52:00 | 00,098,782 | —- | M] ()
Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> %UserProfile%\Desktop\Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> [2008/10/08 19:15:44 | 00,058,880 | —- | M] ()
d3d9caps.dat -> %SystemRoot%\System32\d3d9caps.dat -> [2008/10/06 23:27:50 | 00,000,664 | —- | M] ()
Trader Joes shopping list sorted.doc -> %UserProfile%\Desktop\Trader Joes shopping list sorted.doc -> [2008/10/05 12:51:20 | 00,027,648 | —- | M] ()
cruises.doc -> %UserProfile%\Desktop\cruises.doc -> [2008/10/04 19:25:02 | 00,019,968 | —- | M] ()
Smarter_than_a_5th_grader%281%29(1).xls -> %UserProfile%\Desktop\Smarter_than_a_5th_grader%281%29(1).xls -> [2008/10/03 14:14:40 | 00,152,576 | —- | M] ()
ieframe.dll -> %SystemRoot%\System32\ieframe.dll -> [2008/10/03 12:41:16 | 06,066,176 | —- | M] (Microsoft Corporation)
ieframe.dll -> %SystemRoot%\System32\dllcache\ieframe.dll -> [2008/10/03 12:41:16 | 06,066,176 | —- | M] (Microsoft Corporation)
msxml4.dll -> %SystemRoot%\System32\msxml4.dll -> [2008/09/30 16:43:34 | 01,286,152 | —- | M] (Microsoft Corporation)
clip_image001.jpg -> %UserProfile%\My Documents\clip_image001.jpg -> [2008/09/24 19:43:02 | 00,200,640 | —- | M] ()
marscam.ini -> %SystemRoot%\marscam.ini -> [2008/09/20 15:20:42 | 00,000,037 | —- | M] ()
Bug chart.docx -> %AllUsersProfile%\Documents\Bug chart.docx -> [2008/09/20 13:45:20 | 00,011,106 | —- | M] ()
~$g chart.docx -> %AllUsersProfile%\Documents\~$g chart.docx -> [2008/09/20 13:45:20 | 00,000,162 | -H– | M] ()
win32k.sys -> %SystemRoot%\System32\win32k.sys -> [2008/09/15 06:57:42 | 01,846,016 | —- | M] (Microsoft Corporation)
win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/09/15 06:57:42 | 01,846,016 | —- | M] (Microsoft Corporation)
Sept 12 LArts.pdf -> %AllUsersProfile%\Documents\Sept 12 LArts.pdf -> [2008/09/13 16:42:58 | 00,124,655 | —- | M] ()
Life Science Assignments.doc -> %AllUsersProfile%\Documents\Life Science Assignments.doc -> [2008/09/13 16:39:24 | 00,062,464 | —- | M] ()
WgaLogon.dll -> %SystemRoot%\System32\WgaLogon.dll -> [2008/09/05 23:30:42 | 00,241,704 | —- | M] (Microsoft Corporation)
wgaLogon.dll -> %SystemRoot%\System32\dllcache\wgaLogon.dll -> [2008/09/05 23:30:42 | 00,241,704 | —- | M] (Microsoft Corporation)
LegitCheckControl.dll -> %SystemRoot%\System32\LegitCheckControl.dll -> [2008/09/05 23:30:06 | 01,480,232 | —- | M] (Microsoft Corporation)
WgaTray.exe -> %SystemRoot%\System32\WgaTray.exe -> [2008/09/05 23:29:58 | 00,917,032 | —- | M] (Microsoft Corporation)
WgaTray.exe -> %SystemRoot%\System32\dllcache\WgaTray.exe -> [2008/09/05 23:29:58 | 00,917,032 | —- | M] (Microsoft Corporation)
msxml3.dll -> %SystemRoot%\System32\msxml3.dll -> [2008/09/04 10:42:02 | 01,106,944 | —- | M] (Microsoft Corporation)
msxml3.dll -> %SystemRoot%\System32\dllcache\msxml3.dll -> [2008/09/04 10:42:02 | 01,106,944 | —- | M] (Microsoft Corporation)
[File - Lop Check]
36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp ->
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2006/08/23 02:29:04 | 00,000,000 | RH-D | M]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/10/17 14:50:28 | 00,000,000 | —D | M]
Acer -> C:\Documents and Settings\All Users\Application Data\Acer -> [2006/08/23 03:06:58 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\All Users\Application Data\CyberLink -> [2006/12/26 02:41:50 | 00,000,000 | —D | M]
FLEXnet -> C:\Documents and Settings\All Users\Application Data\FLEXnet -> [2008/03/13 20:23:36 | 00,000,000 | —D | M]
Intel -> C:\Documents and Settings\All Users\Application Data\Intel -> [2006/12/26 02:44:58 | 00,000,000 | —D | M]
PopCap -> C:\Documents and Settings\All Users\Application Data\PopCap -> [2007/02/09 17:18:44 | 00,000,000 | —D | M]
Quark -> C:\Documents and Settings\All Users\Application Data\Quark -> [2007/01/19 19:30:38 | 00,000,000 | —D | M]
TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2008/08/13 11:54:06 | 00,000,000 | —D | M]
Trymedia -> C:\Documents and Settings\All Users\Application Data\Trymedia -> [2007/02/10 10:12:38 | 00,000,000 | —D | M]
WholeSecurity -> C:\Documents and Settings\All Users\Application Data\WholeSecurity -> [2007/02/17 09:55:04 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Maryann\Application Data -> [2006/08/23 02:29:04 | 00,000,000 | RH-D | M]
Acer -> C:\Documents and Settings\Maryann\Application Data\Acer -> [2006/08/23 03:09:44 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\Maryann\Application Data\CyberLink -> [2006/12/26 03:26:26 | 00,000,000 | —D | M]
ICAClient -> C:\Documents and Settings\Maryann\Application Data\ICAClient -> [2007/02/28 22:55:38 | 00,000,000 | —D | M]
Leadertech -> C:\Documents and Settings\Maryann\Application Data\Leadertech -> [2007/07/07 23:37:40 | 00,000,000 | —D | M]
Move Networks -> C:\Documents and Settings\Maryann\Application Data\Move Networks -> [2007/09/23 22:03:28 | 00,000,000 | —D | M]
mypoints -> C:\Documents and Settings\Maryann\Application Data\mypoints -> [2008/03/01 18:08:08 | 00,000,000 | —D | M]
Quark -> C:\Documents and Settings\Maryann\Application Data\Quark -> [2007/01/19 19:30:58 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2006/08/23 02:38:34 | 00,000,000 | –SD | M]
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 05:00:00 | 00,000,065 | RH– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2008/12/01 09:35:54 | 00,000,006 | -H– | M] ()
McQcTask.job -> C:\WINDOWS\Tasks\McQcTask.job -> [2008/11/26 15:38:24 | 00,000,336 | —- | M] ()
McDefragTask.job -> C:\WINDOWS\Tasks\McDefragTask.job -> [2008/11/26 15:38:26 | 00,000,344 | —- | M] ()
[File - Purity Scan]
[File - Signature Check]
< Cached Copy > -> < OS Copy > -> < MD5's >
C:\WINDOWS\system32\dllcache\explorer.exe [2007/06/13 05:23:08 | 01,033,216 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\explorer.exe [2007/06/13 05:23:08 | 01,033,216 | —- | M] (Microsoft Corporation) -> Cached Copy = 97BD6515465659FF8F3B7BE375B2EA87 \ OS Copy = 97BD6515465659FF8F3B7BE375B2EA87
C:\WINDOWS\system32\dllcache\csrss.exe [2004/08/03 22:00:00 | 00,006,144 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\csrss.exe [2004/08/04 05:00:00 | 00,006,144 | —- | M] (Microsoft Corporation) -> Cached Copy = F12B178B1678D778CFD3FF1FC38C71FB \ OS Copy = F12B178B1678D778CFD3FF1FC38C71FB
C:\WINDOWS\system32\dllcache\lsass.exe [2004/08/03 22:00:00 | 00,013,312 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\lsass.exe [2004/08/04 05:00:00 | 00,013,312 | —- | M] (Microsoft Corporation) -> Cached Copy = 84885F9B82F4D55C6146EBF6065D75D2 \ OS Copy = 84885F9B82F4D55C6146EBF6065D75D2
C:\WINDOWS\system32\dllcache\rundll32.exe [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\rundll32.exe [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation) -> Cached Copy = DA285490BBD8A1D0CE6623577D5BA1FF \ OS Copy = DA285490BBD8A1D0CE6623577D5BA1FF
C:\WINDOWS\system32\dllcache\services.exe [2004/08/03 22:00:00 | 00,108,032 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\services.exe [2004/08/04 05:00:00 | 00,108,032 | —- | M] (Microsoft Corporation) -> Cached Copy = C6CE6EEC82F187615D1002BB3BB50ED4 \ OS Copy = C6CE6EEC82F187615D1002BB3BB50ED4
C:\WINDOWS\system32\dllcache\smss.exe [2004/08/03 22:00:00 | 00,050,688 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\smss.exe [2004/08/04 05:00:00 | 00,050,688 | —- | M] (Microsoft Corporation) -> Cached Copy = BD7FB0957C716F1A60333AEE04DE2178 \ OS Copy = BD7FB0957C716F1A60333AEE04DE2178
C:\WINDOWS\system32\dllcache\spoolsv.exe [2005/06/10 17:53:32 | 00,057,856 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\spoolsv.exe [2005/06/10 17:53:32 | 00,057,856 | —- | M] (Microsoft Corporation) -> Cached Copy = DA81EC57ACD4CDC3D4C51CF3D409AF9F \ OS Copy = DA81EC57ACD4CDC3D4C51CF3D409AF9F
C:\WINDOWS\system32\dllcache\svchost.exe [2004/08/03 22:00:00 | 00,014,336 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\svchost.exe [2004/08/04 05:00:00 | 00,014,336 | —- | M] (Microsoft Corporation) -> Cached Copy = 8F078AE4ED187AAABC0A305146DE6716 \ OS Copy = 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\dllcache\taskmgr.exe [2004/08/04 05:00:00 | 00,135,680 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\taskmgr.exe [2004/08/04 05:00:00 | 00,135,680 | —- | M] (Microsoft Corporation) -> Cached Copy = FC160ACE21C81837692B339D230DD4BE \ OS Copy = FC160ACE21C81837692B339D230DD4BE
C:\WINDOWS\system32\dllcache\userinit.exe [2004/08/04 05:00:00 | 00,024,576 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\userinit.exe [2004/08/04 05:00:00 | 00,024,576 | —- | M] (Microsoft Corporation) -> Cached Copy = 39B1FFB03C2296323832ACBAE50D2AFF \ OS Copy = 39B1FFB03C2296323832ACBAE50D2AFF
C:\WINDOWS\system32\dllcache\winlogon.exe [2004/08/03 22:00:00 | 00,502,272 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\winlogon.exe [2004/08/04 05:00:00 | 00,502,272 | —- | M] (Microsoft Corporation) -> Cached Copy = 01C3346C241652F43AED8E2149881BFE \ OS Copy = 01C3346C241652F43AED8E2149881BFE
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden services …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden services …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[Custom Scans]
< C:\Windows\Prefetch\*.* /s >
C:\Windows\Prefetch\ -> C:\Windows\Prefetch -> [2006/08/23 02:45:32 | 00,000,000 | —D | M]
RUNDLL32.EXE-71AB9752.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 18:53:40 | 00,035,378 | —- | M] ()
INSTALLHELPER.EXE-34E4A3DB.pf -> C:\Windows\Prefetch\INSTALLHELPER.EXE -> [2008/12/01 09:37:08 | 00,021,066 | —- | M] ()
LOGONUI.EXE-312BE1BF.pf -> C:\Windows\Prefetch\LOGONUI.EXE -> [2008/12/01 12:37:28 | 00,056,898 | —- | M] ()
RUNDLL32.EXE-6E8D4657.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 18:55:02 | 00,027,692 | —- | M] ()
GOOGLETOOLBARNOTIFIER.EXE-0047A1C5.pf -> C:\Windows\Prefetch\GOOGLETOOLBARNOTIFIER.EXE -> [2008/12/01 09:38:00 | 00,064,704 | —- | M] ()
OUTLOOK.EXE-326CF986.pf -> C:\Windows\Prefetch\OUTLOOK.EXE -> [2008/12/01 07:05:36 | 00,107,008 | —- | M] ()
MONITOR.EXE-0693E15D.pf -> C:\Windows\Prefetch\MONITOR.EXE -> [2008/12/01 09:37:08 | 00,027,666 | —- | M] ()
NAVW32.EXE-32139521.pf -> C:\Windows\Prefetch\NAVW32.EXE -> [2008/11/26 14:55:06 | 00,073,710 | —- | M] ()
RUNDLL32.EXE-4FF9832D.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 18:55:58 | 00,026,002 | —- | M] ()
E_FPREAJA.EXE-1AD749DD.pf -> C:\Windows\Prefetch\E_FPREAJA.EXE -> [2008/11/30 18:56:12 | 00,036,548 | —- | M] ()
E_FAMTAJA.EXE-259013E3.pf -> C:\Windows\Prefetch\E_FAMTAJA.EXE -> [2008/11/30 18:56:18 | 00,029,998 | —- | M] ()
E_FARNAJA.EXE-0F851086.pf -> C:\Windows\Prefetch\E_FARNAJA.EXE -> [2008/11/30 18:56:18 | 00,029,484 | —- | M] ()
NOTEPAD.EXE-2F2D61E1.pf -> C:\Windows\Prefetch\NOTEPAD.EXE -> [2008/12/01 09:41:04 | 00,029,262 | —- | M] ()
RUNDLL32.EXE-41C4C933.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:08 | 00,034,598 | —- | M] ()
MCSHELL.EXE-0086A5A5.pf -> C:\Windows\Prefetch\MCSHELL.EXE -> [2008/12/01 09:37:56 | 00,060,352 | —- | M] ()
OTSCANIT2.EXE-38B52C6F.pf -> C:\Windows\Prefetch\OTSCANIT2.EXE -> [2008/11/30 19:02:08 | 00,026,218 | —- | M] ()
OTSCANIT2.EXE-292E33A5.pf -> C:\Windows\Prefetch\OTSCANIT2.EXE -> [2008/12/01 09:52:56 | 00,033,780 | —- | M] ()
CATCHME.EXE-372FD807.pf -> C:\Windows\Prefetch\CATCHME.EXE -> [2008/12/01 12:38:00 | 00,015,682 | —- | M] ()
VPNGUI.EXE-1D86AE14.pf -> C:\Windows\Prefetch\VPNGUI.EXE -> [2008/12/01 09:38:18 | 00,031,902 | —- | M] ()
DUMPREP.EXE-0AF2BF67.pf -> C:\Windows\Prefetch\DUMPREP.EXE -> [2008/12/01 08:11:26 | 00,200,330 | —- | M] ()
DWWIN.EXE-2C373FB7.pf -> C:\Windows\Prefetch\DWWIN.EXE -> [2008/12/01 08:11:32 | 00,034,168 | —- | M] ()
MCSVRCNT.EXE-082353A7.pf -> C:\Windows\Prefetch\MCSVRCNT.EXE -> [2008/12/01 11:53:32 | 00,046,470 | —- | M] ()
MCVSMAP.EXE-068969FB.pf -> C:\Windows\Prefetch\MCVSMAP.EXE -> [2008/12/01 11:53:34 | 00,029,274 | —- | M] ()
MCINFO.EXE-079FCA72.pf -> C:\Windows\Prefetch\MCINFO.EXE -> [2008/12/01 11:53:36 | 00,048,986 | —- | M] ()
MCSYNC.EXE-0369EAA9.pf -> C:\Windows\Prefetch\MCSYNC.EXE -> [2008/12/01 11:53:36 | 00,036,560 | —- | M] ()
ACER EPOWER MANAGEMENT.EXE-269102ED.pf -> C:\Windows\Prefetch\ACER EPOWER MANAGEMENT.EXE -> [2008/12/01 09:37:08 | 00,023,120 | —- | M] ()
MCUPDATE.EXE-32479339.pf -> C:\Windows\Prefetch\MCUPDATE.EXE -> [2008/12/01 11:53:36 | 00,053,838 | —- | M] ()
LMANAGER.EXE-38229E59.pf -> C:\Windows\Prefetch\LMANAGER.EXE -> [2008/12/01 09:37:08 | 00,023,556 | —- | M] ()
CAMERAASSISTANT.EXE-0C1735AF.pf -> C:\Windows\Prefetch\CAMERAASSISTANT.EXE -> [2008/12/01 09:37:16 | 00,030,518 | —- | M] ()
LVCOMSX.EXE-30FB8DC0.pf -> C:\Windows\Prefetch\LVCOMSX.EXE -> [2008/12/01 09:37:12 | 00,043,968 | —- | M] ()
UNSECAPP.EXE-16EB9856.pf -> C:\Windows\Prefetch\UNSECAPP.EXE -> [2008/12/01 09:37:50 | 00,027,324 | —- | M] ()
MCUPDMGR.EXE-2AB0177A.pf -> C:\Windows\Prefetch\MCUPDMGR.EXE -> [2008/12/01 11:53:42 | 00,062,338 | —- | M] ()
IEXPLORE.EXE-2D97EBE6.pf -> C:\Windows\Prefetch\IEXPLORE.EXE -> [2008/12/01 11:42:02 | 00,104,042 | —- | M] ()
HWUPDCHK.EXE-2CCE7F93.pf -> C:\Windows\Prefetch\HWUPDCHK.EXE -> [2008/12/01 11:53:36 | 00,037,170 | —- | M] ()
MCSYSMON.EXE-3AA753B8.pf -> C:\Windows\Prefetch\MCSYSMON.EXE -> [2008/12/01 07:06:14 | 00,040,298 | —- | M] ()
NTOSBOOT-B00DFAAD.pf -> C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf -> [2008/12/01 09:37:08 | 00,704,692 | —- | M] ()
RUNDLL32.EXE-4D15288E.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 20:16:20 | 00,040,626 | —- | M] ()
MBKLAU~1.EXE-1942AFB4.pf -> C:\Windows\Prefetch\MBKLAU~1.EXE -> [2008/11/30 20:27:18 | 00,058,516 | —- | M] ()
GOOGLEDESKTOP.EXE-16DAD850.pf -> C:\Windows\Prefetch\GOOGLEDESKTOP.EXE -> [2008/12/01 09:37:38 | 00,025,354 | —- | M] ()
EXPLORER.EXE-02121B1A.pf -> C:\Windows\Prefetch\EXPLORER.EXE -> [2008/12/01 09:51:44 | 00,071,126 | —- | M] ()
SNDVOL32.EXE-0EC6FD20.pf -> C:\Windows\Prefetch\SNDVOL32.EXE -> [2008/11/30 22:46:08 | 00,030,014 | —- | M] ()
ALAUNCH.EXE-145B15F4.pf -> C:\Windows\Prefetch\ALAUNCH.EXE -> [2008/12/01 07:05:02 | 00,019,134 | —- | M] ()
AZMIXERSEL.EXE-0057985F.pf -> C:\Windows\Prefetch\AZMIXERSEL.EXE -> [2008/12/01 07:05:00 | 00,018,782 | —- | M] ()
IGFXSRVC.EXE-1D88F978.pf -> C:\Windows\Prefetch\IGFXSRVC.EXE -> [2008/12/01 07:05:02 | 00,016,980 | —- | M] ()
SYNTPENH.EXE-2B70B91C.pf -> C:\Windows\Prefetch\SYNTPENH.EXE -> [2008/11/30 22:27:58 | 00,017,030 | —- | M] ()
NTIMUI.EXE-2D0A7662.pf -> C:\Windows\Prefetch\NTIMUI.EXE -> [2008/12/01 07:05:02 | 00,030,494 | —- | M] ()
IPODSERVICE.EXE-37043579.pf -> C:\Windows\Prefetch\IPODSERVICE.EXE -> [2008/12/01 09:38:18 | 00,081,846 | —- | M] ()
ELKCTRL.EXE-0C71F1E7.pf -> C:\Windows\Prefetch\ELKCTRL.EXE -> [2008/12/01 09:37:20 | 00,022,974 | —- | M] ()
ADMTRAY.EXE-261081D2.pf -> C:\Windows\Prefetch\ADMTRAY.EXE -> [2008/12/01 07:05:02 | 00,022,544 | —- | M] ()
EDSLOADER.EXE-2A914953.pf -> C:\Windows\Prefetch\EDSLOADER.EXE -> [2008/12/01 07:05:02 | 00,033,412 | —- | M] ()
RUNDLL32.EXE-3B866543.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 07:05:02 | 00,022,522 | —- | M] ()
RUNDLL32.EXE-5ACE91DC.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 07:14:44 | 00,030,828 | —- | M] ()
EPOWER_DMC.EXE-0838B86A.pf -> C:\Windows\Prefetch\EPOWER_DMC.EXE -> [2008/12/01 07:05:04 | 00,008,222 | —- | M] ()
LOGON.SCR-24ADF392.pf -> C:\Windows\Prefetch\LOGON.SCR -> [2008/12/01 10:17:24 | 00,011,336 | —- | M] ()
JUSCHED.EXE-0C11AB3F.pf -> C:\Windows\Prefetch\JUSCHED.EXE -> [2008/12/01 09:37:20 | 00,017,092 | —- | M] ()
E_FATIAJA.EXE-1E181673.pf -> C:\Windows\Prefetch\E_FATIAJA.EXE -> [2008/12/01 09:37:26 | 00,015,226 | —- | M] ()
ALCMTR.EXE-01A7139B.pf -> C:\Windows\Prefetch\ALCMTR.EXE -> [2008/12/01 09:37:26 | 00,016,922 | —- | M] ()
RTHDCPL.EXE-005A6E31.pf -> C:\Windows\Prefetch\RTHDCPL.EXE -> [2008/12/01 09:37:34 | 00,025,486 | —- | M] ()
ALG.EXE-275708CF.pf -> C:\Windows\Prefetch\ALG.EXE -> [2008/12/01 09:37:38 | 00,020,518 | —- | M] ()
GROOVEMONITOR.EXE-23AE9D0A.pf -> C:\Windows\Prefetch\GROOVEMONITOR.EXE -> [2008/12/01 09:37:36 | 00,030,918 | —- | M] ()
MCUIMGR.EXE-232A5ACA.pf -> C:\Windows\Prefetch\MCUIMGR.EXE -> [2008/12/01 09:38:22 | 00,029,830 | —- | M] ()
APDPROXY.EXE-1570C10E.pf -> C:\Windows\Prefetch\APDPROXY.EXE -> [2008/12/01 09:37:38 | 00,028,338 | —- | M] ()
READER_SL.EXE-02E193BD.pf -> C:\Windows\Prefetch\READER_SL.EXE -> [2008/12/01 09:37:40 | 00,021,200 | —- | M] ()
APPLESYNCNOTIFIER.EXE-118555EB.pf -> C:\Windows\Prefetch\APPLESYNCNOTIFIER.EXE -> [2008/12/01 07:05:54 | 00,018,104 | —- | M] ()
MCAGENT.EXE-0AA61076.pf -> C:\Windows\Prefetch\MCAGENT.EXE -> [2008/12/01 09:37:40 | 00,019,522 | —- | M] ()
ITUNESHELPER.EXE-0A1B0F2C.pf -> C:\Windows\Prefetch\ITUNESHELPER.EXE -> [2008/12/01 09:37:46 | 00,023,074 | —- | M] ()
MCAFEEDATABACKUP.EXE-0F64DECB.pf -> C:\Windows\Prefetch\MCAFEEDATABACKUP.EXE -> [2008/12/01 09:37:52 | 00,034,142 | —- | M] ()
LOGONHOOK.EXE-0165E737.pf -> C:\Windows\Prefetch\LOGONHOOK.EXE -> [2008/12/01 09:37:50 | 00,021,588 | —- | M] ()
RUNDLL32.EXE-5CBEC4AF.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:50 | 00,021,942 | —- | M] ()
RUNDLL32.EXE-43401C69.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:28:36 | 00,007,164 | —- | M] ()
ONENOTEM.EXE-14CC9B1E.pf -> C:\Windows\Prefetch\ONENOTEM.EXE -> [2008/12/01 09:38:06 | 00,030,204 | —- | M] ()
CVTRES.EXE-16681F8A.pf -> C:\Windows\Prefetch\CVTRES.EXE -> [2008/12/01 09:38:30 | 00,017,056 | —- | M] ()
CSC.EXE-22F6101C.pf -> C:\Windows\Prefetch\CSC.EXE -> [2008/12/01 09:38:30 | 00,050,720 | —- | M] ()
RUNDLL32.EXE-58320A10.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:29:48 | 00,025,502 | —- | M] ()
RUNDLL32.EXE-757ED321.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:30:04 | 00,029,980 | —- | M] ()
RUNDLL32.EXE-3B4320EE.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:30:26 | 00,027,222 | —- | M] ()
IGFXPERS.EXE-19DA7B04.pf -> C:\Windows\Prefetch\IGFXPERS.EXE -> [2008/12/01 07:05:00 | 00,016,786 | —- | M] ()
HKCMD.EXE-0F06AE14.pf -> C:\Windows\Prefetch\HKCMD.EXE -> [2008/12/01 07:05:00 | 00,017,012 | —- | M] ()
IGFXTRAY.EXE-0A23D403.pf -> C:\Windows\Prefetch\IGFXTRAY.EXE -> [2008/12/01 07:05:00 | 00,017,742 | —- | M] ()
TINTSETP.EXE-2DD83AEF.pf -> C:\Windows\Prefetch\TINTSETP.EXE -> [2008/12/01 09:37:08 | 00,011,808 | —- | M] ()
IMSCINST.EXE-2B626103.pf -> C:\Windows\Prefetch\IMSCINST.EXE -> [2008/12/01 09:37:08 | 00,016,026 | —- | M] ()
IMJPMIG.EXE-32ABEE9A.pf -> C:\Windows\Prefetch\IMJPMIG.EXE -> [2008/12/01 07:05:02 | 00,017,486 | —- | M] ()
NWIZ.EXE-2D374245.pf -> C:\Windows\Prefetch\NWIZ.EXE -> [2008/12/01 09:37:08 | 00,017,960 | —- | M] ()
RUNDLL32.EXE-7316AB2B.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:52 | 00,014,708 | —- | M] ()
TASKMGR.EXE-06144C13.pf -> C:\Windows\Prefetch\TASKMGR.EXE -> [2008/12/01 08:09:54 | 00,029,822 | —- | M] ()
FXSSVC.EXE-140862E7.pf -> C:\Windows\Prefetch\FXSSVC.EXE -> [2008/12/01 09:37:08 | 00,016,022 | —- | M] ()
RUNDLL32.EXE-6ACD0C83.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:08 | 00,028,394 | —- | M] ()
RUNDLL32.EXE-3CAE7316.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:08 | 00,017,952 | —- | M] ()
PCMSERVICE.EXE-384B5F7A.pf -> C:\Windows\Prefetch\PCMSERVICE.EXE -> [2008/12/01 09:37:08 | 00,004,784 | —- | M] ()
ICWCONN1.EXE-01D53BFC.pf -> C:\Windows\Prefetch\ICWCONN1.EXE -> [2008/12/01 11:42:18 | 00,023,142 | —- | M] ()
Layout.ini -> C:\Windows\Prefetch\Layout.ini -> [2008/12/01 10:21:42 | 00,236,944 | —- | M] ()
REGSVR32.EXE-396DEA2C.pf -> C:\Windows\Prefetch\REGSVR32.EXE -> [2008/12/01 09:37:16 | 00,020,778 | —- | M] ()
IMAPI.EXE-201490BB.pf -> C:\Windows\Prefetch\IMAPI.EXE -> [2008/12/01 09:51:56 | 00,078,052 | —- | M] ()
RTKBTMNT.EXE-219E8D85.pf -> C:\Windows\Prefetch\RTKBTMNT.EXE -> [2008/12/01 09:37:44 | 00,078,252 | —- | M] ()
QTTASK.EXE-1876A1A1.pf -> C:\Windows\Prefetch\QTTASK.EXE -> [2008/12/01 07:05:50 | 00,015,738 | —- | M] ()
MSMSGS.EXE-0620E8B3.pf -> C:\Windows\Prefetch\MSMSGS.EXE -> [2008/11/26 15:28:44 | 00,027,584 | —- | M] ()
CTFMON.EXE-05E57A5E.pf -> C:\Windows\Prefetch\CTFMON.EXE -> [2008/12/01 09:37:52 | 00,021,908 | —- | M] ()
WMIPRVSE.EXE-0D449B4F.pf -> C:\Windows\Prefetch\WMIPRVSE.EXE -> [2008/12/01 09:37:42 | 00,041,650 | —- | M] ()
WUAUCLT.EXE-1360D60A.pf -> C:\Windows\Prefetch\WUAUCLT.EXE -> [2008/11/27 22:51:30 | 00,041,952 | —- | M] ()
NSCSRVCE.EXE-24B30AFD.pf -> C:\Windows\Prefetch\NSCSRVCE.EXE -> [2008/11/26 14:54:26 | 00,042,926 | —- | M] ()
LUCOMS~1.EXE-1610F181.pf -> C:\Windows\Prefetch\LUCOMS~1.EXE -> [2008/11/27 01:03:34 | 00,055,528 | —- | M] ()
VERCLSID.EXE-28F52AD2.pf -> C:\Windows\Prefetch\VERCLSID.EXE -> [2008/12/01 10:41:54 | 00,029,376 | —- | M] ()
LUCALLBACKPROXY.EXE-29128DB6.pf -> C:\Windows\Prefetch\LUCALLBACKPROXY.EXE -> [2008/11/26 14:58:10 | 00,054,174 | —- | M] ()
AUPDATE.EXE-223E3682.pf -> C:\Windows\Prefetch\AUPDATE.EXE -> [2008/11/26 23:40:42 | 00,045,410 | —- | M] ()
< %systemroot%\system32\drivers\*.dat >
< C:\WINDOWS\Temp\bca4e2da.$$$ >
< C:\WINDOWS\Temp\ed47fa.$ >
< C:\WINDOWS\Temp\fa56d7ec.$$$ >
< C:\Windows\System32\antiwpa.dll >
< c:\windows\system32\drivers\winfilse.exe >
< c:\windows\system32\drivers\srosa2.sys >
< c:\windows\system32\drivers\srosa.sys >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|{FBE1D620-5418-4AAE-A0F0-316D590663A1} /rs >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|tds /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\\DisplayString -> NTDS ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before First Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before First Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\\DisplayString -> NTDS ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\\DisplayString -> NTDS ->
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|SROSA /rs >
< C:\Program Files\*crack*. >
Program Files -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< C:\Program Files\*keygen*. >
Program Files -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< C:\*crack*. >
OTScanIt2 -> C: -> [2008/11/30 19:02:18 | 00,000,000 | —D | M]
< C:\*keygen*. >
OTScanIt2 -> C: -> [2008/11/30 19:02:18 | 00,000,000 | —D | M]
< C:\*.zip >
< C:\*.rar >
< C:\*.exe >
< C:\Program Files\*.zip >
< C:\Program Files\*.rar >
< C:\Program Files\*.exe >
< C:\Program Files\Common Files\*bak*. >
Common Files -> C:\Program Files\Common Files -> [2006/08/23 02:29:22 | 00,000,000 | —D | M]
< C:\WINDOWS\SYSTEM32\*bak*. >
3 C:\WINDOWS\SYSTEM32\*.tmp files -> C:\WINDOWS\SYSTEM32\*.tmp ->
system32 -> C:\WINDOWS\SYSTEM32 -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
CatRoot_bak -> C:\WINDOWS\SYSTEM32\CatRoot_bak -> [2008/08/04 20:45:32 | 00,000,000 | —D | M]
< C:\Program Files\*bak*. >
Program Files -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< End of report >