OTL logfile created on: 7/25/2009 10:48:53 AM - Run 1 OTL by OldTimer - Version 3.0.10.3 Folder = I:\Documents and Settings\User\Desktop Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 447.48 Mb Total Physical Memory | 156.61 Mb Available Physical Memory | 35.00% Memory free 1.03 Gb Paging File | 0.63 Gb Available in Paging File | 60.89% Paging File free Paging file location(s): I:\pagefile.sys 0 0 [binary data] %SystemDrive% = I: | %SystemRoot% = I:\WINDOWS | %ProgramFiles% = I:\Program Files C: Drive not present or media not loaded D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded Drive I: | 149.04 Gb Total Space | 134.74 Gb Free Space | 90.40% Space Free | Partition Type: NTFS Computer Name: ADMIN Current User Name: User Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2005/03/02 11:16:44 | 00,065,536 | ---- | M] () -- I:\WINDOWS\System32\WLTRYSVC.EXE PRC - [2005/05/25 16:15:00 | 00,819,308 | ---- | M] (U.S. Robotics Corporation) -- I:\WINDOWS\System32\bcmwltry.exe PRC - [2004/01/13 18:00:02 | 00,311,296 | ---- | M] (Lexmark International, Inc.) -- I:\WINDOWS\System32\LEXBCES.EXE PRC - [2004/01/13 17:55:52 | 00,174,592 | ---- | M] (Lexmark International, Inc.) -- I:\WINDOWS\System32\LEXPPS.EXE PRC - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- I:\Program Files\Bonjour\mDNSResponder.exe PRC - [2005/10/04 12:42:50 | 00,177,776 | ---- | M] (Symantec Corporation) -- I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe PRC - [2005/11/15 13:27:44 | 00,020,208 | ---- | M] (Symantec Corporation) -- I:\Program Files\Symantec AntiVirus\DefWatch.exe PRC - [2005/10/22 20:47:00 | 00,069,632 | ---- | M] (HP) -- I:\WINDOWS\System32\HPZipm12.exe PRC - [2009/06/10 06:00:48 | 00,980,264 | ---- | M] (Sunbelt Software) -- I:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMSvc.exe PRC - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\System32\wdfmgr.exe PRC - [2007/06/13 03:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\Explorer.EXE PRC - [2009/06/10 06:03:02 | 00,959,784 | ---- | M] (Sunbelt Software) -- I:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMTray.exe PRC - [2005/01/19 12:01:22 | 00,634,982 | ---- | M] (U.S. Robotics Corporation) -- I:\WINDOWS\System32\WLTRAY.exe PRC - [2005/06/06 23:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) -- I:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe PRC - [2007/02/13 13:00:40 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- I:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2009/07/14 15:42:56 | 00,753,664 | ---- | M] (Systems Integration 2) -- I:\WINDOWS\svcwinra.exe PRC - [2009/06/11 22:10:54 | 00,397,312 | ---- | M] (Systems Integration 2) -- I:\WINDOWS\resfilter32.exe PRC - [2009/06/17 21:18:03 | 00,307,704 | ---- | M] (Mozilla Corporation) -- I:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009/07/25 10:40:08 | 00,513,536 | ---- | M] (OldTimer Tools) -- I:\Documents and Settings\User\Desktop\OTL.exe PRC - [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- I:\Program Files\Internet Explorer\iexplore.exe PRC - [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- I:\Program Files\Internet Explorer\iexplore.exe [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2007/06/17 22:27:36 | 00,072,704 | ---- | M] (Adobe Systems) -- I:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped]) SRV - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running]) SRV - [2005/09/23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- I:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running]) SRV - [2005/10/04 12:42:42 | 00,185,968 | ---- | M] (Symantec Corporation) -- I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [On_Demand | Stopped]) SRV - [2005/10/04 12:42:48 | 00,083,568 | ---- | M] (Symantec Corporation) -- I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped]) SRV - [2005/10/04 12:42:50 | 00,177,776 | ---- | M] (Symantec Corporation) -- I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running]) SRV - [2005/09/23 08:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2005/11/15 13:27:44 | 00,020,208 | ---- | M] (Symantec Corporation) -- I:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running]) SRV - [2009/05/01 23:40:46 | 00,182,768 | ---- | M] (Google) -- I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped]) SRV - [2004/08/04 01:56:46 | 00,038,912 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2004/01/13 18:00:02 | 00,311,296 | ---- | M] (Lexmark International, Inc.) -- I:\WINDOWS\System32\LEXBCES.EXE -- (LexBceS [Auto | Running]) SRV - [2007/06/24 14:35:18 | 00,068,096 | ---- | M] () -- I:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service [On_Demand | Stopped]) SRV - [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2005/10/22 20:47:00 | 00,069,632 | ---- | M] (HP) -- I:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running]) SRV - [2005/11/15 13:27:56 | 00,169,200 | ---- | M] (symantec) -- I:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped]) SRV - [2009/06/10 06:00:48 | 00,980,264 | ---- | M] (Sunbelt Software) -- I:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMSvc.exe -- (SBAMSvc [Auto | Running]) SRV - [2005/10/19 17:39:34 | 00,214,672 | ---- | M] (Symantec Corporation) -- I:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped]) SRV - [2005/03/30 21:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- I:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped]) SRV - [2005/11/15 13:27:54 | 01,756,912 | ---- | M] (Symantec Corporation) -- I:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [On_Demand | Stopped]) SRV - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running]) SRV - [2007/10/18 12:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- I:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped]) SRV - [2007/10/25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- I:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped]) SRV - [2005/03/02 11:16:44 | 00,065,536 | ---- | M] () -- I:\WINDOWS\System32\WLTRYSVC.EXE -- (wltrysvc [Auto | Running]) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = I:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = I:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig" FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: I:\Program Files\Mozilla Firefox\components [2009/06/17 21:18:11 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: I:\Program Files\Mozilla Firefox\plugins [2009/07/19 19:52:10 | 00,000,000 | ---D | M] [2008/12/22 12:33:17 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\mozilla\Extensions [2008/12/20 10:59:31 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/12/22 12:33:17 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\mozilla\Extensions\home2@tomtom.com [2009/07/19 20:59:40 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\9hh186sv.default\extensions [2008/12/11 22:05:13 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\9hh186sv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/05/01 17:14:21 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\9hh186sv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2008/12/20 10:59:35 | 00,000,000 | ---D | M] -- I:\Program Files\mozilla firefox\extensions [2007/02/13 13:01:38 | 00,000,000 | ---D | M] -- I:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/06/17 21:18:10 | 00,000,000 | ---D | M] -- I:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/06/17 21:18:02 | 00,023,032 | ---- | M] (Mozilla Foundation) -- I:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/06/17 21:18:02 | 00,134,648 | ---- | M] (Mozilla Foundation) -- I:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/06/17 21:18:06 | 00,065,528 | ---- | M] (mozilla.org) -- I:\Program Files\mozilla firefox\plugins\npnul32.dll [2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- I:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2008/11/30 15:01:43 | 00,143,360 | ---- | M] (Apple Inc.) -- I:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2008/12/20 10:59:11 | 00,001,394 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2008/12/20 10:59:11 | 00,002,193 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\answers.xml [2008/12/20 10:59:11 | 00,001,534 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2008/12/20 10:59:11 | 00,002,343 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\eBay.xml [2008/12/20 10:59:11 | 00,001,706 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\google.xml [2008/12/20 10:59:11 | 00,001,178 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2008/12/20 10:59:11 | 00,000,792 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (734 bytes) - I:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found. O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - I:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - I:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O4 - HKLM..\Run: [Adobe Photo Downloader] I:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AppleSyncNotifier] I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [Rpeawk] I:\Program Files\Ruhhzz\Rpeaw32.exe File not found O4 - HKLM..\Run: [SBAMTray] I:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMTray.exe (Sunbelt Software) O4 - HKLM..\Run: [StandardKeyboard] I:\WINDOWS\WIRELE~1\WirelessKB.exe File not found O4 - HKLM..\Run: [tcrinit] I:\WINDOWS\svcwinra.exe (Systems Integration 2) O4 - HKLM..\Run: [TkBellExe] I:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [U.S. Robotics Wireless Manager UI] I:\WINDOWS\System32\WLTRAY.exe (U.S. Robotics Corporation) O4 - Startup: I:\Documents and Settings\All Users\Start Menu\Programs\Startup\Hawking Wireless Utility.lnk.disabled () O4 - Startup: I:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = I:\Program Files\ERUNT\AUTOBACK.EXE () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O8 - Extra context menu item: E&xport to Microsoft Excel - I:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll (Sun Microsystems, Inc.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - I:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O12 - Plugin for: .NPSSView - I:\Program Files\Common Files\Crystal Decisions\2.0\crystalreportviewers\Viewers\ActiveXViewer\NPssView.dll File not found O15 - HKLM\..Trusted Domains: antimalwareguard.com ([]* in Trusted sites) O15 - HKLM\..Trusted Domains: gomyhit.com ([]* in Trusted sites) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: ([]msn in My Computer) O15 - HKCU\..Trusted Domains: antimalwareguard.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: gomyhit.com ([]* in Trusted sites) O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB (Reg Error: Key error.) O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.) O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control) O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} http://software-dl.real.com/13b6347e9aa0e0838219/netzip/RdxIE601.cab (Reg Error: Key error.) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203043576078 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: Web-Based Email Tools http://email.secureserver.net/Download.CAB (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - I:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - I:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - I:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - I:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - I:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter: - x-sdch - I:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - I:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\NavLogon: DllName - I:\WINDOWS\System32\NavLogon.dll - I:\WINDOWS\System32\NavLogon.dll (Symantec Corporation) O24 - Desktop Components:0 (My Current Home Page) - About:Home O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{5993fbef-cee4-11dd-99e0-0014c1415df3}\Shell\AutoRun\command - "" = D:\InstallSeagateManager.exe -- File not found O33 - MountPoints2\{9ae7db3d-c1ab-11dd-99cc-0014c1415df3}\Shell\AutoRun\command - "" = C:\System\DriveGuard\DriveProtect.exe -- File not found O33 - MountPoints2\{9ae7db3d-c1ab-11dd-99cc-0014c1415df3}\Shell\Explore\Command - "" = C:\System\DriveGuard\DriveProtect.exe -- File not found O33 - MountPoints2\{9ae7db3d-c1ab-11dd-99cc-0014c1415df3}\Shell\Open\Command - "" = C:\System\DriveGuard\DriveProtect.exe -- File not found O33 - MountPoints2\{d2737268-d03f-11dd-99e4-0014c1415df3}\Shell\AutoRun\command - "" = C:\InstallTomTomHOME.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - I:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (/r) - File not found O34 - HKLM BootExecute: (\??\I:) - File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - I:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found [color=#E56717]========== Files/Folders - Created Within 14 Days ==========[/color] [2009/07/25 10:45:30 | 00,000,000 | R--D | C] -- I:\Documents and Settings\User\My Documents\My Music [2009/07/25 10:43:09 | 00,000,000 | -H-D | C] -- I:\WINDOWS\ie8 [2009/07/25 10:40:08 | 00,513,536 | ---- | C] (OldTimer Tools) -- I:\Documents and Settings\User\Desktop\OTL.exe [2009/07/25 10:38:13 | 00,000,000 | ---D | C] -- I:\Documents and Settings\User\Desktop\RootRepeal [2009/07/25 10:37:18 | 00,462,508 | ---- | C] () -- I:\Documents and Settings\User\Desktop\RootRepeal.zip [2009/07/25 10:34:42 | 00,000,000 | ---D | C] -- I:\WINDOWS\ERDNT [2009/07/25 10:34:04 | 00,000,808 | ---- | C] () -- I:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/07/25 10:34:00 | 00,000,652 | ---- | C] () -- I:\Documents and Settings\User\Desktop\NTREGOPT.lnk [2009/07/25 10:34:00 | 00,000,633 | ---- | C] () -- I:\Documents and Settings\User\Desktop\ERUNT.lnk [2009/07/25 10:33:57 | 00,000,000 | ---D | C] -- I:\Program Files\ERUNT [2009/07/25 10:29:25 | 00,791,393 | ---- | C] (Lars Hederer ) -- I:\Documents and Settings\User\Desktop\erunt_setup.exe [2009/07/25 10:28:51 | 00,021,504 | ---- | C] (Doug Knox) -- I:\Documents and Settings\User\Desktop\SysRestorePoint.exe [2009/07/25 10:28:30 | 00,265,216 | ---- | C] (OldTimer Tools) -- I:\Documents and Settings\User\Desktop\TFC.exe [2009/07/25 09:50:40 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- I:\Documents and Settings\User\Desktop\HJTInstall.exe [2009/07/25 09:41:00 | 00,069,936 | ---- | C] (Sunbelt Software) -- I:\WINDOWS\System32\drivers\sbapifs.sys [2009/07/25 09:41:00 | 00,013,360 | ---- | C] (Sunbelt Software) -- I:\WINDOWS\System32\drivers\sbaphd.sys [2009/07/25 08:32:12 | 00,000,000 | ---D | C] -- I:\Documents and Settings\User\Application Data\Sunbelt [2009/07/25 08:32:07 | 00,000,000 | ---D | C] -- I:\Documents and Settings\All Users\Application Data\Sunbelt [2009/07/25 08:30:27 | 00,202,928 | ---- | C] (Sunbelt Software) -- I:\WINDOWS\System32\drivers\sbtis.sys [2009/07/25 08:30:21 | 00,001,901 | ---- | C] () -- I:\Documents and Settings\All Users\Desktop\VIPRE.lnk [2009/07/25 08:27:55 | 14,286,592 | ---- | C] (Sunbelt Software ) -- I:\Documents and Settings\User\Desktop\vipre.exe [2009/07/25 08:09:18 | 03,775,176 | ---- | C] (Malwarebytes Corporation ) -- I:\Documents and Settings\User\Desktop\mbam-setup.exe [2009/07/25 08:05:04 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- I:\Documents and Settings\User\Desktop\spybotsd162.exe [2009/07/25 07:45:45 | 06,111,232 | ---- | C] ( ) -- I:\WINDOWS\sspro.exe [2009/07/25 07:45:45 | 00,133,120 | ---- | C] () -- I:\WINDOWS\msatools64.dll [2009/07/25 07:45:44 | 00,566,784 | ---- | C] (Systems Integration 2) -- I:\WINDOWS\lsemanager.exe [2009/07/25 07:45:44 | 00,131,072 | ---- | C] () -- I:\WINDOWS\perfsysdeam.dll [2009/07/25 07:45:43 | 00,397,312 | ---- | C] (Systems Integration 2) -- I:\WINDOWS\resfilter32.exe [2009/07/25 07:45:42 | 00,605,696 | ---- | C] (Systems Integration 2) -- I:\WINDOWS\mdiwinsvr.exe [2009/07/25 07:45:41 | 00,753,664 | ---- | C] (Systems Integration 2) -- I:\WINDOWS\svcwinra.exe [2009/07/25 07:45:40 | 00,002,671 | ---- | C] () -- I:\WINDOWS\swn32reg.dll [2009/07/25 07:45:40 | 00,000,000 | ---- | C] () -- I:\WINDOWS\sspra32wl.dll [2009/07/25 07:44:55 | 00,000,000 | ---D | C] -- I:\WINDOWS\fontstore [2009/07/25 07:31:12 | 00,000,000 | ---D | C] -- I:\Documents and Settings\All Users\Application Data\Rpeawf [2009/07/24 23:54:29 | 00,000,000 | ---D | C] -- I:\Documents and Settings\User\My Documents\DCIM [2009/07/19 20:25:32 | 00,806,912 | ---- | C] (Codejock Software) -- I:\WINDOWS\System32\Codejock.CommandBars.9700.ocx [2009/07/19 20:25:31 | 00,536,576 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPTab30.ocx [2009/07/19 20:25:31 | 00,221,184 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPSpin30.ocx [2009/07/19 20:25:31 | 00,172,032 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPText30.ocx [2009/07/19 20:25:30 | 00,212,992 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPSelection30.ocx [2009/07/19 20:25:30 | 00,172,032 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPScroll30.ocx [2009/07/19 20:25:30 | 00,053,248 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPRegSvr20.dll [2009/07/19 20:25:29 | 00,831,488 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPListView30.ocx [2009/07/19 20:25:29 | 00,360,448 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPList30.ocx [2009/07/19 20:25:29 | 00,110,592 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPIML30.ocx [2009/07/19 20:25:28 | 00,450,560 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPCalendar30.ocx [2009/07/19 20:25:28 | 00,126,976 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPFrame30.ocx [2009/07/19 20:25:27 | 00,299,008 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPCombo30.ocx [2009/07/19 20:25:27 | 00,184,320 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaXPButton30.ocx [2009/07/19 20:25:26 | 00,692,224 | ---- | C] (CIA, The Company) -- I:\WINDOWS\System32\ciaResSvr20.dll [2009/07/19 20:25:26 | 00,200,704 | ---- | C] (CIA, The company) -- I:\WINDOWS\System32\ciaSCls20.dll [2009/07/19 20:25:21 | 00,196,608 | ---- | C] (Personal) -- I:\WINDOWS\System32\VBSplitter.ocx [2009/07/19 20:25:20 | 00,278,528 | ---- | C] (Inner Media, Inc.) -- I:\WINDOWS\System32\duzactx.dll [2009/07/19 20:25:20 | 00,267,080 | ---- | C] (Teebo Software Solutions) -- I:\WINDOWS\System32\tssProgressBarXP.ocx [2009/07/19 20:25:19 | 00,732,656 | ---- | C] (WeOnlyDo Software) -- I:\WINDOWS\System32\wodPop3.dll [2009/07/19 20:25:17 | 00,753,136 | ---- | C] (WeOnlyDo! Software) -- I:\WINDOWS\System32\wodSmtp.dll [2009/07/19 20:25:10 | 00,000,000 | ---D | C] -- I:\WINDOWS\FontApp [2009/07/19 20:25:10 | 00,000,000 | ---- | C] () -- I:\WINDOWS\ssprb32wl.dll [2009/07/19 20:25:10 | 00,000,000 | ---- | C] () -- I:\WINDOWS\sp32snwl.dll [2009/07/19 19:35:33 | 00,000,000 | ---D | C] -- I:\Documents and Settings\All Users\Application Data\Rphtsf [2009/07/19 19:32:26 | 00,000,000 | ---D | C] -- I:\Program Files\Rapkpr [2009/07/17 17:06:33 | 00,000,433 | ---- | C] () -- I:\My Documents.lnk [2009/07/11 15:27:39 | 00,000,000 | ---D | C] -- I:\Program Files\MSECache [color=#E56717]========== Files - Modified Within 14 Days ==========[/color] [2009/07/25 10:49:29 | 00,490,626 | ---- | M] () -- I:\WINDOWS\System32\PerfStringBackup.INI [2009/07/25 10:49:29 | 00,415,584 | ---- | M] () -- I:\WINDOWS\System32\perfh009.dat [2009/07/25 10:49:29 | 00,066,564 | ---- | M] () -- I:\WINDOWS\System32\perfc009.dat [2009/07/25 10:45:04 | 00,000,006 | -H-- | M] () -- I:\WINDOWS\tasks\SA.DAT [2009/07/25 10:44:59 | 00,002,048 | --S- | M] () -- I:\WINDOWS\bootstat.dat [2009/07/25 10:40:33 | 03,227,274 | -H-- | M] () -- I:\Documents and Settings\User\Local Settings\Application Data\IconCache.db [2009/07/25 10:40:08 | 00,513,536 | ---- | M] (OldTimer Tools) -- I:\Documents and Settings\User\Desktop\OTL.exe [2009/07/25 10:37:19 | 00,462,508 | ---- | M] () -- I:\Documents and Settings\User\Desktop\RootRepeal.zip [2009/07/25 10:34:04 | 00,000,808 | ---- | M] () -- I:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/07/25 10:34:00 | 00,000,652 | ---- | M] () -- I:\Documents and Settings\User\Desktop\NTREGOPT.lnk [2009/07/25 10:34:00 | 00,000,633 | ---- | M] () -- I:\Documents and Settings\User\Desktop\ERUNT.lnk [2009/07/25 10:29:25 | 00,791,393 | ---- | M] (Lars Hederer ) -- I:\Documents and Settings\User\Desktop\erunt_setup.exe [2009/07/25 10:28:51 | 00,021,504 | ---- | M] (Doug Knox) -- I:\Documents and Settings\User\Desktop\SysRestorePoint.exe [2009/07/25 10:28:31 | 00,265,216 | ---- | M] (OldTimer Tools) -- I:\Documents and Settings\User\Desktop\TFC.exe [2009/07/25 10:23:32 | 00,002,671 | ---- | M] () -- I:\WINDOWS\swn32reg.dll [2009/07/25 10:23:27 | 00,000,000 | ---- | M] () -- I:\WINDOWS\ssprb32wl.dll [2009/07/25 10:23:27 | 00,000,000 | ---- | M] () -- I:\WINDOWS\sspra32wl.dll [2009/07/25 10:23:27 | 00,000,000 | ---- | M] () -- I:\WINDOWS\sp32snwl.dll [2009/07/25 09:50:41 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- I:\Documents and Settings\User\Desktop\HJTInstall.exe [2009/07/25 09:04:58 | 00,001,192 | ---- | M] () -- I:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1292428093-725345543-1004.job [2009/07/25 08:30:22 | 00,001,901 | ---- | M] () -- I:\Documents and Settings\All Users\Desktop\VIPRE.lnk [2009/07/25 08:28:32 | 14,286,592 | ---- | M] (Sunbelt Software ) -- I:\Documents and Settings\User\Desktop\vipre.exe [2009/07/25 08:09:20 | 03,775,176 | ---- | M] (Malwarebytes Corporation ) -- I:\Documents and Settings\User\Desktop\mbam-setup.exe [2009/07/25 08:05:15 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- I:\Documents and Settings\User\Desktop\spybotsd162.exe [2009/07/24 23:50:06 | 00,001,374 | ---- | M] () -- I:\WINDOWS\System32\wpa.dbl [2009/07/19 21:50:21 | 00,001,174 | ---- | M] () -- I:\WINDOWS\win.ini [2009/07/19 21:50:21 | 00,000,219 | ---- | M] () -- I:\WINDOWS\system.ini [2009/07/19 21:35:31 | 00,245,760 | ---- | M] () -- I:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/07/19 20:43:52 | 00,001,374 | ---- | M] () -- I:\WINDOWS\imsins.BAK [2009/07/19 19:59:56 | 00,000,012 | ---- | M] () -- I:\WINDOWS\Showtime1.ini [2009/07/19 19:33:55 | 00,037,264 | ---- | M] () -- I:\Documents and Settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2009/07/17 17:06:33 | 00,000,433 | ---- | M] () -- I:\My Documents.lnk [2009/07/14 15:47:14 | 06,111,232 | ---- | M] ( ) -- I:\WINDOWS\sspro.exe [2009/07/14 15:42:56 | 00,753,664 | ---- | M] (Systems Integration 2) -- I:\WINDOWS\svcwinra.exe [2009/07/12 14:36:21 | 00,194,568 | ---- | M] () -- I:\WINDOWS\System32\FNTCACHE.DAT [color=#E56717]========== LOP Check ==========[/color] [2009/07/25 08:32:07 | 00,000,000 | RH-D | M] -- I:\Documents and Settings\All Users\Application Data [2006/11/02 13:53:40 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Avg7 [2006/07/13 17:30:57 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\BVRP Software [2008/05/25 16:00:08 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\logs [2007/06/24 14:35:52 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Macrovision [2007/03/01 08:52:43 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\MSN6 [2009/07/25 07:31:12 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Rpeawf [2009/07/19 19:35:42 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Rphtsf [2007/11/08 21:34:03 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\TEMP [2008/12/22 12:33:32 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\TomTom [2006/09/22 09:56:07 | 00,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Trymedia [2009/07/25 08:32:12 | 00,000,000 | -H-D | M] -- I:\Documents and Settings\User\Application Data [2008/05/19 22:41:28 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\.BitTornado [2007/08/04 10:17:22 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\BearShare [2006/07/13 12:20:15 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\Interact Commerce [2006/08/07 14:27:26 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\Leadertech [2008/06/15 13:03:32 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\LimeWire [2007/06/01 17:35:49 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\MSN6 [2007/06/18 20:44:27 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\Opera [2008/12/22 12:33:12 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\TomTom [2006/11/16 16:47:05 | 00,000,000 | ---D | M] -- I:\Documents and Settings\User\Application Data\XnView [2003/03/31 05:00:00 | 00,000,065 | RH-- | M] () -- I:\WINDOWS\Tasks\desktop.ini [2009/07/25 09:04:58 | 00,001,192 | ---- | M] () -- I:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1292428093-725345543-1004.job [2009/07/25 10:45:04 | 00,000,006 | -H-- | M] () -- I:\WINDOWS\Tasks\SA.DAT [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 480 bytes -> I:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF < End of report >