OTListIt logfile created on: 5/13/2009 8:04:31 AM - Run 1 OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 958.48 Mb Total Physical Memory | 375.29 Mb Available Physical Memory | 39.15% Memory free 2.26 Gb Paging File | 1.77 Gb Available in Paging File | 78.19% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 225.36 Gb Total Space | 156.09 Gb Free Space | 69.26% Space Free | Partition Type: NTFS Drive D: | 7.51 Gb Total Space | 0.96 Gb Free Space | 12.81% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive L: | 1.92 Gb Total Space | 1.29 Gb Free Space | 66.96% Space Free | Partition Type: FAT32 Computer Name: TYLERSAWYER Current User Name: Compaq_Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Standard File Age = 30 Days Company Name Whitelist: On [color=orange]========== Processes (SafeList) ==========[/color] PRC - [2005/06/07 22:38:32 | 00,376,832 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe PRC - [2009/04/01 15:46:23 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2005/06/07 22:38:32 | 00,376,832 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe PRC - [2008/04/13 17:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE PRC - [2009/03/02 13:08:47 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2009/02/23 10:49:16 | 02,652,056 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe PRC - [2008/10/21 10:09:59 | 00,050,472 | ---- | M] (AOL LLC) -- C:\Program Files\AIM6\aim6.exe PRC - [2009/03/02 13:10:30 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe PRC - [2004/09/28 08:33:52 | 00,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe PRC - [2004/08/10 19:04:42 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe PRC - [2009/01/11 11:43:13 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe PRC - [2006/05/03 10:48:46 | 00,307,200 | ---- | M] (ta2027) -- C:\Program Files\Styler\Styler.exe PRC - [2005/06/21 06:10:30 | 00,053,248 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe PRC - [2003/06/20 06:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE PRC - [2008/12/11 16:58:44 | 00,146,800 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe PRC - [2004/09/29 12:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe PRC - [2008/12/07 14:56:50 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe PRC - [2009/02/22 21:36:57 | 00,202,040 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe PRC - [2004/08/10 19:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe PRC - [2007/01/04 14:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe PRC - [2009/04/27 20:15:35 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009/04/28 16:34:26 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTListIt2.exe [color=orange]========== Win32 Services (SafeList) ==========[/color] SRV - [2008/04/13 17:11:48 | 00,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\6to4svc.dll -- (6to4 [Auto | Running]) SRV - [2004/10/22 13:42:44 | 00,049,152 | ---- | M] (Alpha Networks Inc.) -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService [Auto | Stopped]) SRV - [2009/04/01 15:46:23 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running]) SRV - [2009/03/02 13:10:30 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running]) SRV - File not found -- -- (AOL ACS [Auto | Stopped]) SRV - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running]) SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) SRV - [2005/06/07 22:38:32 | 00,376,832 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running]) SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running]) SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2004/09/28 08:33:52 | 00,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe -- (ehRecvr [Auto | Running]) SRV - [2004/08/10 19:04:42 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe -- (ehSched [Auto | Running]) SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2008/04/13 17:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2005/04/04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped]) SRV - [2009/01/11 11:43:13 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running]) SRV - [2005/06/21 06:10:30 | 00,053,248 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running]) SRV - [2003/06/20 06:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running]) SRV - [2004/08/10 19:11:50 | 00,085,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mhn.dll -- (MHN [On_Demand | Stopped]) SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped]) SRV - [2008/04/13 17:12:02 | 00,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\nwwks.dll -- (NWCWorkstation [Auto | Running]) SRV - [2004/08/10 12:00:00 | 00,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ipxsap.dll -- (NwSapAgent [Auto | Running]) SRV - [2003/07/28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2008/12/11 16:58:44 | 00,146,800 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe -- (PCToolsFirewallPlus [Auto | Running]) SRV - [2004/09/29 12:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running]) SRV - [2008/12/07 14:56:50 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running]) SRV - [2009/02/22 21:36:57 | 00,202,040 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB [Auto | Running]) SRV - [2005/08/02 14:18:49 | 00,086,016 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped]) SRV - [2004/08/10 19:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running]) SRV - [2007/01/04 14:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Running]) SRV - [2007/10/25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped]) [color=orange]========== Driver Services (SafeList) ==========[/color] DRV - [2005/03/22 19:17:34 | 00,450,400 | ---- | M] (D-Link Corporation) -- C:\WINDOWS\system32\DRIVERS\A3AB.sys -- (A3AB [On_Demand | Running]) DRV - [2005/04/20 11:00:56 | 02,317,696 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running]) DRV - [2005/03/09 14:53:00 | 00,036,352 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running]) DRV - [2004/07/27 11:20:46 | 00,028,205 | ---- | M] (Alpha Networks Inc.) -- C:\WINDOWS\system32\ANIO.SYS -- (ANIO [Auto | Running]) DRV - [2005/06/07 22:44:36 | 01,235,968 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running]) DRV - [2009/02/13 12:35:05 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running]) DRV - [2009/03/24 16:08:22 | 00,055,640 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running]) DRV - [2009/03/30 10:33:07 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avipbb.sys -- (avipbb [System | Running]) DRV - [2003/11/05 15:45:12 | 00,017,408 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\bb-run.sys -- (bb-run [Boot | Running]) DRV - [2005/04/14 21:12:12 | 00,175,616 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\ftsata2.sys -- (ftsata2 [Boot | Running]) DRV - [2008/04/17 14:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running]) DRV - [2008/05/23 21:53:22 | 00,025,280 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Stopped]) DRV - [2005/03/09 18:09:18 | 00,870,912 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor [Boot | Running]) DRV - [2009/02/10 17:23:02 | 00,082,320 | ---- | M] (EZB Systems, Inc.) -- C:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive [System | Running]) DRV - [2004/08/04 05:41:36 | 00,606,684 | ---- | M] (LT) -- C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys -- (ltmodem5 [On_Demand | Stopped]) DRV - [2001/08/17 20:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running]) DRV - [2008/04/13 11:53:09 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped]) DRV - [2005/08/02 14:10:13 | 00,032,512 | ---- | M] (CACE Technologies) -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF [On_Demand | Stopped]) DRV - [2008/04/13 11:56:06 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running]) DRV - [2004/08/10 12:00:00 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running]) DRV - [2004/08/10 12:00:00 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running]) DRV - [2008/04/13 11:34:12 | 00,163,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwrdr.sys -- (NWRDR [On_Demand | Running]) DRV - [2008/12/18 12:16:56 | 00,073,840 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\drivers\PCTAppEvent.sys -- (PCTAppEvent [Auto | Running]) DRV - [2008/12/11 08:38:22 | 00,159,600 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\drivers\pctgntdi.sys -- (pctgntdi [System | Running]) DRV - [2009/01/21 10:38:32 | 00,095,640 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\drivers\pctplfw.sys -- (pctplfw [On_Demand | Running]) DRV - [2002/07/29 15:43:50 | 00,023,808 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\DRIVERS\PS2.sys -- (Ps2 [On_Demand | Running]) DRV - [2004/08/10 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running]) DRV - [2008/08/20 10:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running]) DRV - [2005/03/04 11:10:26 | 00,074,496 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys -- (RTL8023xp [On_Demand | Running]) DRV - [2004/08/04 05:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped]) DRV - [2009/01/15 17:17:40 | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV [System | Running]) DRV - [2009/01/15 17:17:42 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Stopped]) DRV - [2009/01/15 17:17:38 | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL [System | Running]) DRV - [2007/11/13 03:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped]) DRV - [2008/09/22 12:29:18 | 00,097,408 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\DRIVERS\pctfw.sys -- (SFilter [On_Demand | Running]) DRV - [2005/01/25 06:56:00 | 00,923,863 | ---- | M] (Motorola Inc.) -- C:\WINDOWS\system32\DRIVERS\smserial.sys -- (smserial [On_Demand | Running]) DRV - [2009/02/13 12:50:02 | 00,028,376 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running]) DRV - [2001/08/17 13:53:32 | 00,006,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\serscan.sys -- (StillCam [On_Demand | Running]) DRV - [2008/06/20 04:08:27 | 00,225,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\tcpip6.sys -- (Tcpip6 [System | Running]) DRV - [2008/11/07 15:23:30 | 00,032,000 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped]) DRV - [2007/02/18 01:15:34 | 00,232,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Drivers\vmm.sys -- (vmm [System | Running]) DRV - [2007/01/29 07:20:34 | 00,059,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys -- (VPCNetS2 [On_Demand | Running]) DRV - [2003/01/10 14:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\system32\DRIVERS\wanatw4.sys -- (wanatw [On_Demand | Stopped]) [color=orange]========== Standard Registry (SafeList) ==========[/color] [color=orange]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://youtube.com/; IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://geekstogo.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=orange]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.malwareremoval.com/forum/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: {C7E0B063-1DC2-4DD0-A502-1D67957B9ADE}:1.0 FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:3.0.3 FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20090325 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546 FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.0.2 FF - prefs.js..extensions.enabledItems: {239c61a8-e55f-11db-8314-0800200c9a66}:2.0.7 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10 FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\COMPONENTS [2009/04/07 21:47:49 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\PLUGINS [2009/04/07 21:47:50 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/01/11 11:43:14 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/19 21:30:07 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/07 19:26:08 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/07 19:26:08 | 00,000,000 | ---D | M] [2009/04/03 16:52:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Extensions [2009/04/03 16:52:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/05/12 20:29:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions [2009/05/08 18:20:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions\{239c61a8-e55f-11db-8314-0800200c9a66} [2009/05/08 18:20:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2009/05/09 12:07:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2009/05/07 19:45:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2008/06/08 15:03:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa} [2009/05/08 18:20:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\mozilla\Firefox\Profiles\p1c3jbp5.default\extensions\en-US@dictionaries.addons.mozilla.org [2009/05/12 20:29:01 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/04/27 20:15:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/06/08 10:13:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{C7E0B063-1DC2-4DD0-A502-1D67957B9ADE} [2008/02/07 19:55:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2008/04/27 10:14:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2009/04/27 20:15:34 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/04/27 20:15:34 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/03/26 11:56:22 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/03/26 11:56:22 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/03/26 11:56:22 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/03/26 11:56:22 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/03/26 11:56:22 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/03/26 11:56:22 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/03/26 11:56:22 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (255789 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 192.168.0.107 HP000D9D2057C8 O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.1001-search.info O1 - Hosts: 127.0.0.1 1001-search.info O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.123topsearch.com O1 - Hosts: 127.0.0.1 123topsearch.com O1 - Hosts: 127.0.0.1 www.132.com O1 - Hosts: 127.0.0.1 132.com O1 - Hosts: 127.0.0.1 www.136136.net O1 - Hosts: 8897 more lines... O2 - BHO: (no name) - {005DDBDE-D017-43B5-A595-D3D7937D5FAF} - Reg Error: Key error. File not found O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - Reg Error: Key error. File not found O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (no name) - {B17324EB-1C4E-453F-BAB4-E82D5F3314C2} - Reg Error: Key error. File not found O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {E7CEFE86-8BF0-4D4C-A6BC-76A56DFB36F4} - C:\WINDOWS\system32\mlJDwWNh.dll File not found O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C11483F7-D7D8-4804-98D8-6055470BB989} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found O4 - HKLM..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s (PC Tools) O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min (Avira GmbH) O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto (Microsoft Corporation) O4 - HKCU..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (AOL LLC) O4 - HKLM..\RunOnceEx: [] File not found O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk = C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data] O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML File not found O8 - Extra context menu item: &Search - ?p=ZRfox000 File not found O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html [2005/08/05 09:46:06 | 00,000,000 | ---D | M] O8 - Extra context menu item: Add to Video Converter... - C:\Program Files\MP3 Player Utilities 5.10\AVIConverter\grab.html () O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation) O9 - Extra Button: Doyles Room Poker - {725E77D3-B919-4eef-8EEE-D09DE618B6C1} - C:\Microgaming\Poker\DoylesRoomMPP\MPPoker.exe (Microgaming) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm () O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm () O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKLM\..Trusted Domains: 41 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5) O15 - HKCU\..Trusted Domains: 41 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab (System Requirements Lab Class) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127362109437 (WUWebControl Class) O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab (HpProductDetection Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149835123078 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} http://www.yoyogames.com/downloads/activex/YoYo.cab (YYGInstantPlay Control) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\mlJDwWNh) - File not found O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004/11/17 04:32:46 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009/05/06 19:46:37 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2001/07/28 05:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2004/04/30 21:01:14 | 00,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ] O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found [color=orange]========== Files/Folders - Created Within 30 Days ==========[/color] [1 C:\WINDOWS\System32\*.tmp files] [1 C:\WINDOWS\*.tmp files] [2009/05/12 21:38:15 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\eMusic Download Manager (2).lnk [2009/05/12 21:36:43 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\eMusic Download Manager.lnk [2009/05/12 21:26:47 | 00,206,445 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Vista_Desktop_Inspirtat_by_SkaaZ.jpg [2009/05/12 21:25:47 | 00,042,731 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\vista!!!.jpg [2009/05/12 21:22:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Styler [2009/05/12 21:20:41 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uxtheme.uxtender [2009/05/12 21:03:04 | 00,002,275 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk [2009/05/12 21:03:04 | 00,000,000 | ---D | C] -- C:\Program Files\Styler [2009/05/10 19:59:50 | 00,000,000 | ---D | C] -- C:\Program Files\DOSBox-0.72 [2009/05/07 20:52:05 | 00,010,752 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Edwards Resume.wps [2009/05/07 19:32:31 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini [2009/05/07 19:28:23 | 00,000,956 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\My Sharing Folders.lnk [2009/05/06 21:38:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Compaq_Administrator\Application Data\PCToolsFirewallPlus [2009/05/06 21:37:22 | 00,130,424 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys [2009/05/06 21:37:22 | 00,073,840 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys [2009/05/06 21:37:21 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys [2009/05/06 21:36:48 | 00,097,408 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctfw.sys [2009/05/06 21:36:48 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools [2009/05/06 21:36:46 | 00,095,640 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplfw.sys [2009/05/06 21:36:45 | 00,000,000 | ---D | C] -- C:\Program Files\PC Tools Firewall Plus [2009/05/06 21:33:10 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [2009/05/06 21:33:10 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys [2009/05/06 21:33:10 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys [2009/05/06 21:33:09 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys [2009/05/06 21:33:09 | 00,028,376 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys [2009/05/06 21:33:07 | 00,000,000 | ---D | C] -- C:\Program Files\Avira [2009/05/06 21:33:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira [2009/05/06 19:51:36 | 00,000,000 | ---D | C] -- C:\Program Files\WhatsRunning [2009/05/06 19:46:37 | 00,000,000 | RHSD | C] -- C:\autorun.inf [2009/05/06 19:42:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Download Manager [2009/05/06 08:14:28 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009/05/06 08:12:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft [2009/05/01 09:16:28 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Compaq_Administrator\My Documents\My DVDs [2009/04/29 18:14:24 | 00,000,000 | ---D | C] -- C:\MTV_OUTPUT [2009/04/29 18:13:56 | 00,000,000 | ---D | C] -- C:\Program Files\Video Convert [2009/04/29 18:09:49 | 00,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader [2009/04/28 17:25:49 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/04/28 16:34:33 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Rooter.exe [2009/04/28 16:34:23 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTListIt2.exe [2009/04/26 18:10:19 | 00,000,000 | ---D | C] -- C:\Program Files\WebSite Downloader for Windows [2009/04/23 18:14:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Compaq_Administrator\My Documents\sdfsdf [2009/04/20 16:53:15 | 00,000,000 | ---D | C] -- C:\!KillBox [2009/04/20 05:37:37 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat [2009/04/19 21:42:28 | 00,000,000 | -HSD | C] -- C:\found.000 [2009/04/19 21:29:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer [2009/04/19 21:29:06 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild [2009/04/19 21:28:57 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies [2009/04/19 21:28:29 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe [2009/04/19 21:28:29 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll [2009/04/19 21:28:29 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll [2009/04/19 21:28:29 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll [2009/04/19 21:28:29 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll [2009/04/19 21:28:28 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll [2009/04/19 21:28:28 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll [2009/04/19 21:28:28 | 00,000,000 | ---D | C] -- C:\824e87d83aae8e652c3aaf [2009/04/19 21:28:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel [2009/04/14 13:09:50 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll [2009/04/14 13:09:50 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll [2009/04/14 13:09:49 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll [2009/04/14 13:09:49 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll [2009/04/14 13:09:49 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe [2009/04/14 13:09:49 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe [2009/04/14 13:09:48 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll [2009/04/14 13:09:48 | 00,714,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll [2009/04/14 13:09:48 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll [2009/04/14 13:09:21 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp4res.dll [2009/04/14 13:09:20 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe [2008/12/07 00:15:45 | 00,137,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2008/12/07 00:15:25 | 00,000,319 | ---- | C] () -- C:\WINDOWS\game.ini [2008/11/17 19:01:31 | 00,000,979 | ---- | C] () -- C:\WINDOWS\DC.ini [2008/07/28 01:04:18 | 04,070,440 | -HS- | C] () -- C:\WINDOWS\System32\gcmeiget.ini [2008/07/19 08:05:00 | 01,608,386 | -HS- | C] () -- C:\WINDOWS\System32\vntuaevr.ini [2008/07/18 20:02:17 | 00,708,743 | -HS- | C] () -- C:\WINDOWS\System32\hqekmrsx.ini [2008/07/18 19:58:46 | 00,883,640 | -HS- | C] () -- C:\WINDOWS\System32\hNWwDJlm.ini2 [2008/07/18 19:58:44 | 00,884,227 | -HS- | C] () -- C:\WINDOWS\System32\hNWwDJlm.ini [2008/07/13 16:48:13 | 00,000,031 | ---- | C] () -- C:\WINDOWS\RACETRK.INI [2008/07/10 22:41:15 | 00,001,115 | ---- | C] () -- C:\WINDOWS\ABSOLUTE.INI [2008/07/10 22:38:34 | 00,001,094 | ---- | C] () -- C:\WINDOWS\MYSTERY.INI [2008/07/10 20:47:26 | 00,002,388 | ---- | C] () -- C:\WINDOWS\WILD7.INI [2008/07/10 20:46:59 | 00,000,972 | ---- | C] () -- C:\WINDOWS\8BALL.INI [2008/07/10 20:34:07 | 00,001,072 | ---- | C] () -- C:\WINDOWS\777Slots.INI [2008/07/10 20:34:06 | 00,001,072 | ---- | C] () -- C:\WINDOWS\ANIMATE.INI [2008/07/10 20:21:16 | 00,000,403 | ---- | C] () -- C:\WINDOWS\2XStars.ini [2008/07/10 20:19:57 | 00,000,234 | ---- | C] () -- C:\WINDOWS\DWSLOT.INI [2008/07/10 20:17:49 | 00,001,208 | ---- | C] () -- C:\WINDOWS\WIZARD.INI [2008/07/10 20:09:01 | 00,000,339 | ---- | C] () -- C:\WINDOWS\2XDyna.ini [2008/07/10 20:06:41 | 00,000,480 | ---- | C] () -- C:\WINDOWS\EXTREME.INI [2008/07/10 19:37:06 | 00,000,369 | ---- | C] () -- C:\WINDOWS\2XCherry.ini [2008/07/10 19:36:34 | 00,000,333 | ---- | C] () -- C:\WINDOWS\Ultisoft.ini [2008/06/24 00:55:34 | 00,000,118 | ---- | C] () -- C:\WINDOWS\chmpchss.INI [2008/06/24 00:48:56 | 00,000,366 | ---- | C] () -- C:\WINDOWS\CraGra.ini [2008/06/24 00:34:09 | 00,000,018 | ---- | C] () -- C:\WINDOWS\forth.ini [2008/05/26 20:38:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\MSDraw.ini [2008/05/17 10:10:26 | 00,001,733 | ---- | C] () -- C:\WINDOWS\TSearch.INI [2006/06/08 21:49:30 | 00,000,147 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini [2006/06/08 21:49:29 | 00,003,399 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini [2006/06/08 21:46:20 | 00,000,988 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini [2006/05/15 20:12:21 | 00,000,099 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2006/05/13 20:57:59 | 00,000,101 | ---- | C] () -- C:\WINDOWS\upst.ini [2006/05/13 20:57:59 | 00,000,030 | ---- | C] () -- C:\WINDOWS\atid.ini [2006/03/06 10:41:02 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\AMV_DecDLL.dll [2005/08/05 10:10:36 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2005/08/05 09:45:13 | 00,012,959 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS [2005/08/05 09:45:07 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll [2005/08/05 09:39:52 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2005/08/05 09:35:30 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2005/08/05 09:35:30 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2005/08/05 09:35:30 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2005/08/05 09:35:30 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2005/08/05 09:35:30 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2005/08/05 09:35:28 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2005/08/05 09:29:23 | 00,001,145 | ---- | C] () -- C:\WINDOWS\WININIT.INI [2005/08/05 09:25:03 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2005/08/05 09:22:33 | 00,065,536 | ---- | C] () -- C:\WINDOWS\sm56spn.dll [2005/08/05 09:22:33 | 00,065,536 | ---- | C] () -- C:\WINDOWS\sm56itl.dll [2005/08/05 09:22:33 | 00,065,536 | ---- | C] () -- C:\WINDOWS\sm56ger.dll [2005/08/05 09:22:33 | 00,065,536 | ---- | C] () -- C:\WINDOWS\sm56fra.dll [2005/08/05 09:22:33 | 00,065,536 | ---- | C] () -- C:\WINDOWS\sm56eng.dll [2005/08/05 09:22:33 | 00,065,536 | ---- | C] () -- C:\WINDOWS\sm56brz.dll [2005/08/05 09:22:33 | 00,049,152 | ---- | C] () -- C:\WINDOWS\sm56jpn.dll [2005/08/05 09:22:33 | 00,045,056 | ---- | C] () -- C:\WINDOWS\sm56cht.dll [2005/08/05 09:22:33 | 00,045,056 | ---- | C] () -- C:\WINDOWS\sm56chs.dll [2005/08/05 09:08:24 | 00,000,882 | ---- | C] () -- C:\WINDOWS\orun32.ini [2005/08/05 09:04:39 | 00,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll [2005/08/05 09:04:39 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll [2005/08/05 09:04:20 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll [2005/08/02 14:24:01 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll [2005/07/07 13:07:24 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2005/05/09 23:52:32 | 00,022,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys [2004/11/17 04:32:38 | 00,000,689 | ---- | C] () -- C:\WINDOWS\win.ini [2004/11/16 20:21:56 | 00,000,246 | ---- | C] () -- C:\WINDOWS\system.ini [2004/09/16 13:26:40 | 00,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS [2004/07/26 22:51:38 | 00,000,592 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2003/01/07 22:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [color=orange]========== Files - Modified Within 30 Days ==========[/color] [1 C:\WINDOWS\System32\*.tmp files] [1 C:\WINDOWS\*.tmp files] [2009/05/13 07:35:34 | 00,058,368 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/05/12 21:38:15 | 00,000,104 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\eMusic Download Manager (2).lnk [2009/05/12 21:36:43 | 00,000,104 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\eMusic Download Manager.lnk [2009/05/12 21:27:28 | 00,444,472 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/05/12 21:27:28 | 00,072,652 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/05/12 21:27:27 | 00,524,016 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/05/12 21:26:47 | 00,206,445 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Vista_Desktop_Inspirtat_by_SkaaZ.jpg [2009/05/12 21:25:48 | 00,042,731 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\vista!!!.jpg [2009/05/12 21:24:23 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/05/12 21:22:25 | 00,002,275 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk [2009/05/12 21:22:06 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/05/12 21:21:57 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/05/12 21:21:51 | 10,051,13344 | -HS- | M] () -- C:\hiberfil.sys [2009/05/12 21:21:01 | 00,000,186 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT [2009/05/12 21:21:00 | 07,893,270 | -H-- | M] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\IconCache.db [2009/05/12 21:20:42 | 00,218,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\uxtheme.dll [2009/05/12 20:18:23 | 00,000,689 | ---- | M] () -- C:\WINDOWS\win.ini [2009/05/12 20:18:23 | 00,000,279 | RHS- | M] () -- C:\boot.ini [2009/05/12 20:18:23 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini [2009/05/11 08:14:00 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009/05/08 21:42:55 | 00,057,512 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2009/05/07 22:13:20 | 00,010,752 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Edwards Resume.wps [2009/05/07 19:32:31 | 00,000,002 | ---- | M] () -- C:\WINDOWS\msoffice.ini [2009/05/07 19:28:23 | 00,000,956 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\My Sharing Folders.lnk [2009/05/07 19:17:34 | 00,242,328 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/05/07 00:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009/05/06 11:51:56 | 00,000,466 | ---- | M] () -- C:\WINDOWS\tasks\EasyShare Registration Task.job [2009/05/05 11:44:10 | 00,210,806 | ---- | M] () -- C:\logfile [2009/05/04 11:53:08 | 00,000,304 | ---- | M] () -- C:\WINDOWS\tasks\HPCeeSchedule.job [2009/05/01 09:56:13 | 11,782,144 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb [2009/05/01 09:56:13 | 06,178,816 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb [2009/05/01 09:44:02 | 00,024,278 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat [2009/04/28 16:34:34 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Rooter.exe [2009/04/28 16:34:26 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTListIt2.exe [2009/04/16 09:58:23 | 00,000,268 | -H-- | M] () -- C:\sqmdata05.sqm [2009/04/16 09:58:22 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm [2009/04/15 00:06:22 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [color=orange]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6 @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9662AE0 < End of report >