Egwene,
Thank you so much for your time, it is really appreciated.
Here are the logs you asked for:
OTMoveItExplorer killed successfully
File/Folder C:\WINDOWS\system32\smart.dll.tmp not found.
File/Folder C:\WINDOWS\system32\LoveFly.dll not found.
File/Folder C:\WINDOWS\system32\smart.dll not found.
< purity >
< emptytemp >
File delete failed. C:\DOCUME~1\Robb\LOCALS~1\Temp\Perflib_Perfdata_698.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8940665f4.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~894066a22.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8ca5c839c.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8ca5c87b3.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8cab84eb3.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8cab85925.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8cb49fcc9.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8cb4a012f.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8d0953134.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cch~8d09539b5.htp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_9b4.dat scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08262008_181703
Files moved on Reboot...
File C:\DOCUME~1\Robb\LOCALS~1\Temp\Perflib_Perfdata_698.dat not found!
File C:\WINDOWS\temp\cch~8940665f4.htp not found!
File C:\WINDOWS\temp\cch~894066a22.htp not found!
File C:\WINDOWS\temp\cch~8ca5c839c.htp not found!
File C:\WINDOWS\temp\cch~8ca5c87b3.htp not found!
File C:\WINDOWS\temp\cch~8cab84eb3.htp not found!
File C:\WINDOWS\temp\cch~8cab85925.htp not found!
File C:\WINDOWS\temp\cch~8cb49fcc9.htp not found!
File C:\WINDOWS\temp\cch~8cb4a012f.htp not found!
File C:\WINDOWS\temp\cch~8d0953134.htp not found!
File C:\WINDOWS\temp\cch~8d09539b5.htp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_9b4.dat not found!
OTViewItOTViewIt logfile created on: 8/26/2008 6:31:49 PM - Run 1
OTViewIt by OldTimer - Version 1.0.0.12 Folder = C:\Documents and Settings\Robb\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 601.15 Mb Available Physical Memory | 58.74% Memory free
2.40 Gb Paging File | 2.08 Gb Available in Paging File | 86.84% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 110.96 Gb Free Space | 72.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ROB
Current User Name: Robb
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
===== Processes - Non-Microsoft Only =====
[02/06/2007 05:45 PM | 00,109,344 | ---- | M] (Logitech Inc.) - c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
[07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[07/29/2008 08:20 PM | 00,206,088 | ---- | M] (Kaspersky Lab) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
[07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
[08/26/2008 06:06 PM | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre6\bin\jqs.exe
[03/24/2008 07:52 PM | 00,155,716 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\nvsvc32.exe
[01/04/2007 05:38 PM | 00,024,652 | ---- | M] (Viewpoint Corporation) - C:\Program Files\Viewpoint\Common\ViewpointService.exe
[02/06/2004 10:56 PM | 00,041,025 | ---- | M] (GEMTEKS) - C:\Program Files\Linksys Wireless AG USB Wireless Network Monitor\WLService.exe
[09/17/2004 11:07 AM | 02,563,072 | ---- | M] (Cisco Linksys Corporation) - C:\Program Files\Linksys Wireless AG USB Wireless Network Monitor\WUSB54AG.exe
[12/06/2002 05:07 PM | 00,617,984 | ---- | M] () - C:\Program Files\ASUS\Asus Probe\AsusProb.exe
[11/15/2004 06:20 AM | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.) - C:\WINDOWS\SOUNDMAN.EXE
[02/05/2005 09:36 PM | 00,360,448 | ---- | M] () - C:\Program Files\Browser MOUSE\mouse32a.exe
[02/05/2005 09:35 PM | 00,375,296 | ---- | M] () - C:\Program Files\Muiltmedia keyboard utility\1.3\KBDAP32A.EXE
[08/26/2008 06:06 PM | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre6\bin\jusched.exe
[07/30/2008 10:47 AM | 00,289,064 | ---- | M] (Apple Inc.) - C:\Program Files\iTunes\iTunesHelper.exe
[06/14/2004 04:16 PM | 00,045,056 | ---- | M] () - C:\Program Files\Linksys Wireless AG USB Wireless Network Monitor\InfoMyCa.exe
[02/08/2007 01:12 AM | 00,488,984 | ---- | M] (Logitech Inc.) - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[02/08/2007 01:13 AM | 00,774,168 | ---- | M] () - C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
[07/29/2008 08:20 PM | 00,206,088 | ---- | M] (Kaspersky Lab) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
[06/12/2008 02:38 AM | 00,034,672 | ---- | M] (Adobe Systems Incorporated) - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[03/25/2008 04:21 PM | 00,050,528 | ---- | M] (AOL LLC) - C:\Program Files\AIM6\aim6.exe
[05/17/2008 11:51 PM | 00,289,088 | ---- | M] (BitTorrent, Inc.) - C:\Program Files\DNA\btdna.exe
[02/06/2007 05:43 PM | 00,252,704 | ---- | M] (Logitech Inc.) - C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
[07/30/2008 10:47 AM | 00,532,264 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
[05/25/2007 01:16 PM | 00,042,032 | ---- | M] (AOL LLC) - C:\Program Files\AIM6\aolsoftware.exe
[02/08/2007 01:12 AM | 00,230,936 | ---- | M] (Logitech Inc.) - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
[08/26/2008 06:31 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\Robb\Desktop\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Apple Mobile Device) Apple Mobile Device [Auto | Running]
[07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(AVP) Kaspersky Anti-Virus [Auto | Running]
[07/29/2008 08:20 PM | 00,206,088 | ---- | M] (Kaspersky Lab) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
(Bonjour Service) Bonjour Service [Auto | Running]
[07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
(CLTNetCnService) Symantec Lic NetConnect service [Auto | Stopped]
File not found - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(dlbu_device) dlbu_device [On_Demand | Stopped]
[10/25/2004 05:13 PM | 00,421,888 | ---- | M] (Dell) - C:\WINDOWS\system32\dlbucoms.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[08/04/2004 08:00 AM | 00,224,768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\dmadmin.exe
(IDriverT) InstallDriver Table Manager [On_Demand | Stopped]
[04/04/2005 12:41 AM | 00,069,632 | ---- | M] (Macrovision Corporation) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
(iPod Service) iPod Service [On_Demand | Running]
[07/30/2008 10:47 AM | 00,532,264 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
(JavaQuickStarterService) Java Quick Starter [Auto | Running]
[08/26/2008 06:06 PM | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre6\bin\jqs.exe
(LVPrcSrv) Process Monitor [Auto | Running]
[02/06/2007 05:45 PM | 00,109,344 | ---- | M] (Logitech Inc.) - c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(LVSrvLauncher) LVSrvLauncher [Auto | Stopped]
[02/06/2007 05:47 PM | 00,105,248 | ---- | M] (Logitech Inc.) - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
(NVSvc) NVIDIA Display Driver Service [Auto | Running]
[03/24/2008 07:52 PM | 00,155,716 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\nvsvc32.exe
(Viewpoint Manager Service) Viewpoint Manager Service [Auto | Running]
[01/04/2007 05:38 PM | 00,024,652 | ---- | M] (Viewpoint Corporation) - C:\Program Files\Viewpoint\Common\ViewpointService.exe
(WUSB54AG) WUSB54AG [Auto | Running]
[02/06/2004 10:56 PM | 00,041,025 | ---- | M] (GEMTEKS) - C:\Program Files\Linksys Wireless AG USB Wireless Network Monitor\WLService.exe
===== Driver Services - Non-Microsoft Only =====
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [On_Demand | Running]
[11/17/2004 07:05 AM | 02,297,664 | ---- | M] (Realtek Semiconductor Corp.) - C:\WINDOWS\system32\drivers\ALCXWDM.SYS
(AmdK8) AMD Processor Driver [System | Running]
[03/09/2005 04:53 PM | 00,036,352 | ---- | M] (Advanced Micro Devices) - C:\WINDOWS\system32\drivers\AmdK8.sys
(ASInsHelp) ASInsHelp [Auto | Running]
[03/10/2004 03:31 PM | 00,003,328 | ---- | M] () - C:\WINDOWS\system32\drivers\AsInsHelp32.sys
(AsIO) AsIO [System | Running]
[10/14/2004 05:52 AM | 00,004,962 | R--- | M] () - C:\WINDOWS\system32\drivers\AsIO.sys
(aslm75) aslm75 [System | Running]
[04/22/1997 11:16 AM | 00,006,272 | ---- | M] () - C:\WINDOWS\system32\drivers\ASLM75.SYS
(dmboot) dmboot [Disabled | Stopped]
[08/04/2004 08:00 AM | 00,799,744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmboot.sys
(dmio) dmio [Disabled | Stopped]
[08/04/2004 08:00 AM | 00,153,344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmio.sys
(dmload) dmload [Disabled | Stopped]
[08/04/2004 08:00 AM | 00,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\drivers\dmload.sys
(FilterService) UVC Filter Service [On_Demand | Running]
[02/03/2007 02:32 PM | 00,022,560 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\lvuvcflt.sys
(GEARAspiWDM) GEARAspiWDM [On_Demand | Running]
[01/29/2008 12:01 PM | 00,016,168 | ---- | M] (GEAR Software Inc.) - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
(hamachi) Hamachi Network Interface [On_Demand | Running]
[09/24/2006 07:54 PM | 00,010,345 | ---- | M] (Applied Networking Inc.) - C:\WINDOWS\system32\drivers\hamachi.sys
(kl1) kl1 [Boot | Running]
[07/21/2008 06:34 PM | 00,121,872 | ---- | M] (Kaspersky Lab) - C:\WINDOWS\system32\drivers\kl1.sys
(klbg) Kaspersky Lab Boot Guard Driver [Boot | Running]
[01/29/2008 06:29 PM | 00,032,784 | ---- | M] (Kaspersky Lab) - C:\WINDOWS\system32\drivers\klbg.sys
(KLIF) Kaspersky Lab Driver [System | Running]
[08/22/2008 05:48 PM | 00,213,008 | ---- | M] (Kaspersky Lab) - C:\WINDOWS\system32\drivers\klif.sys
(klim5) Kaspersky Anti-Virus NDIS Filter [On_Demand | Running]
[04/30/2008 06:06 PM | 00,024,592 | ---- | M] (Kaspersky Lab) - C:\WINDOWS\system32\drivers\klim5.sys
(LVcKap) Logitech AEC Driver [On_Demand | Running]
[02/06/2007 05:42 PM | 01,691,808 | ---- | M] () - C:\WINDOWS\system32\drivers\Lvckap.sys
(LVMVDrv) Logitech Machine Vision Engine Loader [On_Demand | Running]
[02/06/2007 05:44 PM | 01,964,064 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\LVMVdrv.sys
(lvpopflt) Logitech POP Suppression Filter [On_Demand | Running]
[02/03/2007 02:30 PM | 01,507,232 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\lvpopflt.sys
(LVPr2Mon) Logitech LVPr2Mon Driver [On_Demand | Running]
[02/06/2007 05:45 PM | 00,025,632 | ---- | M] () - C:\WINDOWS\system32\drivers\LVPr2Mon.sys
(LVUSBSta) Logitech USB Monitor Filter [On_Demand | Running]
[02/03/2007 02:32 PM | 00,041,504 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\LVUSBSta.sys
(LVUVC) QuickCam for Notebooks Deluxe(UVC) [On_Demand | Running]
[02/03/2007 02:32 PM | 01,939,360 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\lvuvc.sys
(MDC8021X) AEGIS Protocol (IEEE 802.1x) v2.3.1.9 [Auto | Running]
[07/09/2006 10:46 AM | 00,015,781 | ---- | M] (Meetinghouse Data Communications) - C:\WINDOWS\system32\drivers\mdc8021x.sys
(mgau) mgau [On_Demand | Stopped]
[08/17/2001 08:50 AM | 00,320,384 | ---- | M] (Matrox Graphics Inc.) - C:\WINDOWS\system32\drivers\mgaum.sys
(motmodem) Motorola USB CDC ACM Driver [On_Demand | Stopped]
[05/04/2007 04:54 PM | 00,022,528 | ---- | M] (Motorola) - C:\WINDOWS\system32\drivers\motmodem.sys
(MTsensor) ATK0110 ACPI UTILITY [On_Demand | Running]
[08/12/2004 10:56 PM | 00,005,810 | R--- | M] () - C:\WINDOWS\system32\drivers\ASACPI.sys
(NPPTNT2) NPPTNT2 [System | Running]
[01/04/2005 02:43 PM | 00,004,682 | ---- | M] (INCA Internet Co., Ltd.) - C:\WINDOWS\system32\npptNT2.sys
(nv) nv [On_Demand | Running]
[03/24/2008 07:52 PM | 06,547,872 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\drivers\nv4_mini.sys
(nvata) nvata [Boot | Running]
[05/17/2005 05:45 AM | 00,092,800 | R--- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\drivers\nvata.sys
(PciCon) PciCon [On_Demand | Stopped]
File not found - D:\PciCon.sys
(PRISM_A02) Linksys Wireless A/G USB Network Adapter Service [On_Demand | Running]
[10/13/2004 03:37 AM | 00,379,456 | R--- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\WUSB54AG.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[08/04/2004 08:00 AM | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\system32\drivers\ptilink.sys
(Secdrv) Secdrv [Auto | Running]
[11/13/2007 06:25 AM | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) - C:\WINDOWS\system32\drivers\secdrv.sys
(zntport) NTPort Library Driver [Auto | Stopped]
File not found - C:\WINDOWS\system32\zntport.sys
(GTNDIS5) GTNDIS5 NDIS Protocol Driver [On_Demand | Running]
[09/25/2003 11:15 PM | 00,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) - C:\WINDOWS\system32\GTNDIS5.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher" = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM | 00,034,672 | ---- | M] (Adobe Systems Incorporated)
"AppleSyncNotifier" = C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.)
"ASUS Probe" = C:\Program Files\ASUS\Asus Probe\AsusProb.exe [12/06/2002 05:07 PM | 00,617,984 | ---- | M] ()
"AVP" = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [07/29/2008 08:20 PM | 00,206,088 | ---- | M] (Kaspersky Lab)
"FLMK08KB" = C:\Program Files\Muiltmedia keyboard utility\1.3\MMKEYBD.EXE [02/05/2005 09:35 PM | 00,207,360 | ---- | M] ()
"FLMOFFICE4DMOUSE" = C:\Program Files\Browser MOUSE\mouse32a.exe [02/05/2005 09:36 PM | 00,360,448 | ---- | M] ()
"IPHSend" = C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe [02/17/2006 12:59 PM | 00,124,520 | ---- | M] (America Online, Inc.)
"iTunesHelper" = "C:\Program Files\iTunes\iTunesHelper.exe" [07/30/2008 10:47 AM | 00,289,064 | ---- | M] (Apple Inc.)
"LogitechCommunicationsManager" = "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [02/08/2007 01:12 AM | 00,488,984 | ---- | M] (Logitech Inc.)
"LogitechQuickCamRibbon" = "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide [02/08/2007 01:13 AM | 00,774,168 | ---- | M] ()
"MyCA" = C:\Program Files\Linksys Wireless AG USB Wireless Network Monitor\InvokeSvc3.exe [04/19/2004 09:19 AM | 00,024,576 | ---- | M] ()
"NvCplDaemon" = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [03/24/2008 07:52 PM | 13,524,992 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [03/24/2008 07:52 PM | 00,086,016 | ---- | M] (NVIDIA Corporation)
"nwiz" = nwiz.exe /install [03/24/2008 07:52 PM | 01,626,112 | ---- | M] ()
"QuickTime Task" = "C:\Program Files\QuickTime\QTTask.exe" -atboottime [05/27/2008 10:50 AM | 00,413,696 | ---- | M] (Apple Inc.)
"SoundMan" = SOUNDMAN.EXE [11/15/2004 06:20 AM | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" = "C:\Program Files\Java\jre6\bin\jusched.exe" [08/26/2008 06:06 PM | 00,144,792 | ---- | M] (Sun Microsystems, Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6" = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp [03/25/2008 04:21 PM | 00,050,528 | ---- | M] (AOL LLC)
"BitTorrent DNA" = "C:\Program Files\DNA\btdna.exe" [05/17/2008 11:51 PM | 00,289,088 | ---- | M] (BitTorrent, Inc.)
"Miro" = C:\Program Files\Participatory Culture Foundation\Miro\Miro.exe File not found
"MsnMsgr" = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[Robb Startup Folder - C:\Documents and Settings\Robb\Start Menu\Programs\Startup]
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (Adobe PDF Reader Link Helper) - [06/11/2008 10:33 PM | 00,061,816 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
HKLM CLSID: (Adobe PDF Link Helper) - [06/11/2008 10:33 PM | 00,075,128 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
HKLM CLSID: (IEVkbdBHO Class) - [07/29/2008 08:21 PM | 00,062,728 | ---- | M] (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (Java Plug-In SSV Helper) - [08/26/2008 06:06 PM | 00,320,920 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
HKLM CLSID: (Java Plug-In 2 SSV Helper) - [08/26/2008 06:06 PM | 00,034,816 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jp2ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
HKLM CLSID: (JQSIEStartDetectorImpl Class) - [08/26/2008 06:06 PM | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
===== Toolbars =====
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - File not found C:\RECYCLER\S-1-5-21-1715567821-823518204-725345543-1004\Dc124\GoogleToolbar2.dll
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{C4069E3A-68F1-403E-B40E-20066696354B}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (&Yahoo! Toolbar) - File not found Reg Error: Key does not exist or could not be opened.
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
"NoDrives" = 0
"NoViewOnDrive" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
===== Desktop Components =====
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls]
"C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll" - [07/29/2008 08:22 PM | 00,079,112 | ---- | M] (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\mzvkbd.dll
"C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll" - [07/29/2008 08:22 PM | 00,079,112 | ---- | M] (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\mzvkbd3.dll
===== Lsa Authentication Packages =====
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 08:00 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe File not found
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 08:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 08:00 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe [11/03/2006 03:17 AM | 00,010,800 | ---- | M] (AOL LLC)
"C:\Program Files\Common Files\AOL\1140277105\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1140277105\ee\aolsoftware.exe [04/20/2006 01:10 PM | 00,050,792 | ---- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1140277105\ee\aim6.exe" = C:\Program Files\Common Files\AOL\1140277105\ee\aim6.exe [05/19/2006 01:44 PM | 00,050,768 | ---- | M] (America Online, Inc.)
"C:\Westwood\RA2\game.exe" = C:\Westwood\RA2\game.exe File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe File not found
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 08:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe File not found
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe [05/17/2008 11:51 PM | 00,289,088 | ---- | M] (BitTorrent, Inc.)
"C:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe" = C:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe File not found
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe [07/16/2008 05:44 PM | 01,069,712 | ---- | M] (Blizzard Entertainment)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe [03/25/2008 04:21 PM | 00,050,528 | ---- | M] (AOL LLC)
"C:\StubInstaller.exe" = C:\StubInstaller.exe File not found
"C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe [08/04/2004 08:00 AM | 00,042,496 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe [07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe [07/30/2008 10:47 AM | 20,252,968 | ---- | M] (Apple Inc.)
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06/13/2007 06:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 08:00 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 08:00 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 08:00 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
===== User's Winlogon Settings =====
===== Winlogon Notify Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
"DllName" = C:\WINDOWS\system32\klogon.dll [07/29/2008 08:21 PM | 00,218,376 | ---- | M] (Kaspersky Lab)
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{1EC92998-AF80-4847-96A9-7DB42957C33B}]
Servers: | Description: Wireless A/G USB Network Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{38009AF0-761A-4DAF-A7DD-4D8A46A92EF5}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{543E562E-90B9-4957-A9F9-B52B09087B94}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{712438DE-F504-4018-A13E-EDC94EA4DAE0}]
Servers: | Description: Wireless A/G USB Network Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{AC5EB3E2-BE7F-49F1-8E7B-E21A86EAFBB6}]
Servers: | Description: Wireless A/G USB Network Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{D828029D-C935-4554-B58B-4A047BEE6CE7}]
Servers: | Description: 1394 Net Adapter
===== CDRom AutoRun Settings =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
===== Autorun Files on Drives =====
AUTOEXEC.BAT []
[02/05/2005 08:41 PM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
===== MountPoints2 =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell]
"" = Shell01
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\AutoRun]
"Extended" =
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\AutoRun\command]
"" = E:\Autorun.exe File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Shell00]
"" = Start Ceedo
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Shell00\Command]
"" = E:\Autorun.exe File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Shell01]
"" = Open Ceedo Action Window
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Shell01\Command]
"" = E:\Autorun.exe File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Shell02]
"" = Uninstall Ceedo
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ab52e7e-d75f-11dc-aeb7-e852d2f94ee1}\Shell\Shell02\Command]
"" = E:\Autorun.exe File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{250561d5-d21e-11da-abd0-00121795629c}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{250561d5-d21e-11da-abd0-00121795629c}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{250561d5-d21e-11da-abd0-00121795629c}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f887863-2eff-11dc-ad7c-00121795629c}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f887863-2eff-11dc-ad7c-00121795629c}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f887863-2eff-11dc-ad7c-00121795629c}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3fb9318f-d4d8-11db-ad48-00121795629c}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3fb9318f-d4d8-11db-ad48-00121795629c}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3fb9318f-d4d8-11db-ad48-00121795629c}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a2ae3675-d6fb-11da-abd9-00121795629c}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a2ae3675-d6fb-11da-abd9-00121795629c}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a2ae3675-d6fb-11da-abd9-00121795629c}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0716041-3351-11dd-af45-00121795629c}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0716041-3351-11dd-af45-00121795629c}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0716041-3351-11dd-af45-00121795629c}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0716041-3351-11dd-af45-00121795629c}\Shell\AutoRun]
"Extended" =
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0716041-3351-11dd-af45-00121795629c}\Shell\AutoRun\command]
"" = setupSNK.exe
===== Hosts File =====
HOSTS File = (909 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[Files/Folders - Created Within 30 days]
[08/26/2008 06:15 PM | -HSD | C] - C:\Config.Msi
[08/26/2008 06:17 PM | ---D | C] - C:\_OTMoveIt
[02/03/2007 02:30 PM | 01,507,232 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\drivers\lvpopflt.sys
[02/03/2007 02:32 PM | 00,022,560 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\drivers\lvuvcflt.sys
[02/03/2007 02:32 PM | 00,041,504 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\drivers\LVUSBSta.sys
[02/03/2007 02:32 PM | 01,939,360 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\drivers\lvuvc.sys
[07/29/2008 08:20 PM | 00,024,774 | ---- | C] () - C:\WINDOWS\System32\drivers\klopp.dat
[08/22/2008 05:48 PM | 00,087,855 | ---- | C] () - C:\WINDOWS\System32\drivers\klick.dat
[08/22/2008 05:48 PM | 00,213,008 | ---- | C] (Kaspersky Lab) - C:\WINDOWS\System32\drivers\klif.sys
[08/22/2008 05:59 PM | 00,096,976 | ---- | C] () - C:\WINDOWS\System32\drivers\klin.dat
[08/26/2008 06:17 PM | 00,015,836 | -HS- | C] () - C:\WINDOWS\System32\drivers\fidbox.idx
[08/26/2008 06:17 PM | 01,888,800 | -HS- | C] () - C:\WINDOWS\System32\drivers\fidbox.dat
[08/26/2008 06:18 PM | 00,000,000 | ---- | C] () - C:\WINDOWS\System32\drivers\lvuvc.hs
[08/26/2008 06:31 PM | 00,002,284 | -HS- | C] () - C:\WINDOWS\System32\drivers\fidbox2.idx
[08/26/2008 06:31 PM | 00,352,288 | -HS- | C] () - C:\WINDOWS\System32\drivers\fidbox2.dat
[7 C:\WINDOWS\System32\*.tmp files]
[02/03/2007 01:01 PM | 00,013,398 | R--- | C] () - C:\WINDOWS\System32\Repository.reg
[02/03/2007 02:29 PM | 00,129,824 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\lvci1051.dll
[02/03/2007 02:29 PM | 00,264,992 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\lvcodec2.dll
[02/03/2007 02:32 PM | 00,215,840 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\LVUI2.dll
[02/03/2007 02:32 PM | 00,527,136 | R--- | C] (Logitech Inc.) - C:\WINDOWS\System32\LVUI2RC.dll
[02/03/2007 12:59 PM | 00,050,127 | R--- | C] () - C:\WINDOWS\System32\lvcoinst.ini
[07/29/2008 08:21 PM | 00,218,376 | ---- | C] (Kaspersky Lab) - C:\WINDOWS\System32\klogon.dll
[08/26/2008 03:52 PM | ---D | C] - C:\WINDOWS\System32\CatRoot_bak
[08/26/2008 06:06 PM | 00,139,264 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[08/26/2008 06:06 PM | 00,139,264 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[08/26/2008 06:06 PM | 00,143,360 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[08/26/2008 06:06 PM | 00,410,976 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\deploytk.dll
[5 C:\WINDOWS\*.tmp files]
[08/21/2008 01:39 AM | ---D | C] - C:\WINDOWS\ERDNT
[08/20/2008 11:03 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Logishrd
[08/20/2008 11:03 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Logitech
[08/22/2008 04:47 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[08/22/2008 05:10 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[08/26/2008 06:13 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Adobe
[08/26/2008 06:29 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[08/20/2008 05:43 PM | ---D | C] - C:\Documents and Settings\Robb\Application Data\Help
[08/20/2008 12:36 AM | ---D | C] - C:\Documents and Settings\Robb\Application Data\Viewpoint
[08/20/2008 05:43 PM | ---D | C] - C:\Documents and Settings\Robb\Local Settings\Application Data\Help
[08/06/2008 10:24 PM | 00,001,604 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[08/08/2008 02:54 PM | 00,002,137 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[08/20/2008 11:03 PM | 00,001,801 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Logitech QuickCam.lnk
[08/26/2008 06:13 PM | 00,001,729 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[08/26/2008 06:15 PM | 00,000,734 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[08/05/2008 12:23 AM | 00,023,382 | ---- | C] () - C:\Documents and Settings\Robb\Desktop\041808_1734.jpg
[08/06/2008 10:18 PM | 63,530,280 | ---- | C] (Apple Inc.) - C:\Documents and Settings\Robb\Desktop\iTunesSetup.exe
[08/21/2008 01:34 AM | 00,050,688 | ---- | C] (Atribune.org) - C:\Documents and Settings\Robb\Desktop\ATF_Cleaner.exe
[08/21/2008 02:03 AM | 00,001,734 | ---- | C] () - C:\Documents and Settings\Robb\Desktop\HijackThis.lnk
[08/21/2008 05:09 PM | 00,005,566 | ---- | C] () - C:\Documents and Settings\Robb\Desktop\Kaspersky Online Scan.html
[08/22/2008 04:46 PM | 33,138,928 | ---- | C] (Kaspersky Lab) - C:\Documents and Settings\Robb\Desktop\kav8.0.0.454en.exe
[08/26/2008 06:01 PM | 00,291,840 | ---- | C] (OldTimer Tools) - C:\Documents and Settings\Robb\Desktop\OTMoveIt2.exe
[08/26/2008 06:11 PM | 35,124,856 | ---- | C] ( ) - C:\Documents and Settings\Robb\Desktop\AdbeRdr90_en_US.exe
[08/26/2008 06:31 PM | 01,299,968 | ---- | C] (OldTimer Tools) - C:\Documents and Settings\Robb\Desktop\OTViewIt.exe
[08/20/2008 11:09 PM | ---D | C] - C:\Program Files\Common Files\LogiShrd
[08/26/2008 06:13 PM | ---D | C] - C:\Program Files\Common Files\Adobe
[08/26/2008 06:14 PM | ---D | C] - C:\Program Files\Common Files\Adobe AIR
[08/04/2008 02:17 PM | ---D | C] - C:\Program Files\Sun
[08/06/2008 10:24 PM | ---D | C] - C:\Program Files\Bonjour
[08/06/2008 10:42 PM | ---D | C] - C:\Program Files\MSECACHE
[08/06/2008 10:42 PM | ---D | C] - C:\Program Files\Windows Installer Clean Up
[08/07/2008 12:52 AM | ---D | C] - C:\Program Files\Apple Software Update
[08/20/2008 11:03 PM | ---D | C] - C:\Program Files\Logitech
[08/21/2008 02:03 AM | ---D | C] - C:\Program Files\Trend Micro
[08/22/2008 05:10 PM | ---D | C] - C:\Program Files\Spybot - Search & Destroy
[08/22/2008 05:48 PM | ---D | C] - C:\Program Files\Kaspersky Lab
[Files/Folders - Modified Within 30 days]
[08/22/2008 02:17 PM | ---D | M] - C:\N360_BACKUP
[08/22/2008 06:42 PM | ---D | M] - C:\temp
[08/22/2008 07:17 PM | -HSD | M] - C:\System Volume Information
[08/23/2008 11:29 AM | R--D | M] - C:\Program Files
[08/26/2008 06:17 PM | ---D | M] - C:\_OTMoveIt
[08/26/2008 06:18 PM | 10,732,70784 | -HS- | M] () - C:\hiberfil.sys
[08/26/2008 06:18 PM | -HSD | M] - C:\Config.Msi
[08/26/2008 06:28 PM | ---D | M] - C:\WINDOWS
[08/22/2008 01:49 PM | 00,260,784 | RH-- | M] () - C:\WINDOWS\System32\drivers\etc\Hosts.bak
[08/22/2008 02:41 PM | 00,000,909 | ---- | M] () - C:\WINDOWS\System32\drivers\etc\Hosts
[07/29/2008 08:20 PM | 00,024,774 | ---- | M] () - C:\WINDOWS\System32\drivers\klopp.dat
[08/22/2008 02:02 PM | ---D | M] - C:\WINDOWS\System32\drivers\etc
[08/22/2008 05:48 PM | 00,087,855 | ---- | M] () - C:\WINDOWS\System32\drivers\klick.dat
[08/22/2008 05:48 PM | 00,213,008 | ---- | M] (Kaspersky Lab) - C:\WINDOWS\System32\drivers\klif.sys
[08/22/2008 05:59 PM | 00,096,976 | ---- | M] () - C:\WINDOWS\System32\drivers\klin.dat
[08/26/2008 06:17 PM | 00,015,836 | -HS- | M] () - C:\WINDOWS\System32\drivers\fidbox.idx
[08/26/2008 06:17 PM | 01,888,800 | -HS- | M] () - C:\WINDOWS\System32\drivers\fidbox.dat
[08/26/2008 06:18 PM | 00,000,000 | ---- | M] () - C:\WINDOWS\System32\drivers\lvuvc.hs
[08/26/2008 06:31 PM | 00,002,284 | -HS- | M] () - C:\WINDOWS\System32\drivers\fidbox2.idx
[08/26/2008 06:31 PM | 00,352,288 | -HS- | M] () - C:\WINDOWS\System32\drivers\fidbox2.dat
[7 C:\WINDOWS\System32\*.tmp files]
[07/29/2008 08:21 PM | 00,218,376 | ---- | M] (Kaspersky Lab) - C:\WINDOWS\System32\klogon.dll
[08/06/2008 10:22 PM | ---D | M] - C:\WINDOWS\System32\DRVSTORE
[08/22/2008 02:41 PM | 00,004,178 | ---- | M] () - C:\WINDOWS\System32\tmp.reg
[08/22/2008 05:59 PM | ---D | M] - C:\WINDOWS\System32\drivers
[08/22/2008 07:17 PM | ---D | M] - C:\WINDOWS\System32\Restore
[08/26/2008 03:52 PM | ---D | M] - C:\WINDOWS\System32\CatRoot_bak
[08/26/2008 06:06 PM | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javacpl.cpl
[08/26/2008 06:06 PM | 00,139,264 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[08/26/2008 06:06 PM | 00,139,264 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[08/26/2008 06:06 PM | 00,143,360 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[08/26/2008 06:06 PM | 00,410,976 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\deploytk.dll
[08/26/2008 06:19 PM | ---D | M] - C:\WINDOWS\System32\CatRoot2
[08/26/2008 06:19 PM | RHSD | M] - C:\WINDOWS\System32\dllcache
[08/26/2008 06:21 PM | ---D | M] - C:\WINDOWS\System32\CatRoot
[08/26/2008 06:29 PM | 00,002,422 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[08/26/2008 06:29 PM | 00,169,882 | ---- | M] () - C:\WINDOWS\System32\nvapps.xml
[5 C:\WINDOWS\*.tmp files]
[08/06/2008 10:43 PM | ---D | M] - C:\WINDOWS\Downloaded Installations
[08/07/2008 12:52 AM | --SD | M] - C:\WINDOWS\Tasks
[08/17/2008 04:05 PM | 00,000,624 | ---- | M] () - C:\WINDOWS\win.ini
[08/17/2008 04:07 PM | ---D | M] - C:\WINDOWS\ie7updates
[08/17/2008 04:10 PM | 00,001,374 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08/17/2008 04:10 PM | -H-D | M] - C:\WINDOWS\$hf_mig$
[08/20/2008 11:03 PM | ---D | M] - C:\WINDOWS\WinSxS
[08/20/2008 11:08 PM | ---D | M] - C:\WINDOWS\twain_32
[08/21/2008 01:39 AM | ---D | M] - C:\WINDOWS\ERDNT
[08/21/2008 12:50 PM | ---D | M] - C:\WINDOWS\system
[08/26/2008 03:27 PM | ---D | M] - C:\WINDOWS\Help
[08/26/2008 03:32 PM | ---D | M] - C:\WINDOWS\Debug
[08/26/2008 03:52 PM | -H-D | M] - C:\WINDOWS\inf
[08/26/2008 06:06 PM | ---D | M] - C:\WINDOWS\Prefetch
[08/26/2008 06:15 PM | -HSD | M] - C:\WINDOWS\Installer
[08/26/2008 06:18 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08/26/2008 06:18 PM | ---D | M] - C:\WINDOWS\system32
[08/26/2008 06:31 PM | ---D | M] - C:\WINDOWS\Temp
[08/26/2008 06:18 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/26/2008 09:55 AM | 00,000,284 | ---- | M] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/20/2008 11:03 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Logishrd
[08/20/2008 11:03 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Logitech
[08/21/2008 02:06 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\TEMP
@Alternate Data Stream - 498 bytes -> %AllUsersProfile%\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 98 bytes -> %AllUsersProfile%\Application Data\TEMP:DFC5A2B2
[08/22/2008 04:47 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[08/22/2008 05:10 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[08/23/2008 11:29 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Ulead Systems
[08/23/2008 11:30 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Symantec
[08/26/2008 06:13 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Adobe
[08/26/2008 06:29 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[08/20/2008 05:43 PM | ---D | M] - C:\Documents and Settings\Robb\Application Data\Help
[08/20/2008 12:36 AM | ---D | M] - C:\Documents and Settings\Robb\Application Data\Viewpoint
[08/21/2008 02:07 AM | ---D | M] - C:\Documents and Settings\Robb\Application Data\SUPERAntiSpyware.com
[08/26/2008 06:17 PM | ---D | M] - C:\Documents and Settings\Robb\Application Data\DNA
[08/02/2008 02:25 PM | 00,076,520 | ---- | M] () - C:\Documents and Settings\Robb\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[08/07/2008 11:11 AM | ---D | M] - C:\Documents and Settings\Robb\Local Settings\Application Data\Apple Computer
[08/20/2008 05:43 PM | ---D | M] - C:\Documents and Settings\Robb\Local Settings\Application Data\Help
[08/22/2008 05:10 PM | 06,957,160 | -H-- | M] () - C:\Documents and Settings\Robb\Local Settings\Application Data\IconCache.db
[08/23/2008 12:25 AM | ---D | M] - C:\Documents and Settings\Robb\Local Settings\Application Data\Microsoft
[08/26/2008 06:13 PM | ---D | M] - C:\Documents and Settings\Robb\Local Settings\Application Data\Adobe
[08/22/2008 04:52 PM | ---D | M] - C:\Documents and Settings\All Users\Documents\Symantec
[08/20/2008 11:10 PM | R--D | M] - C:\Documents and Settings\Robb\My Documents\My Pictures
[08/20/2008 11:10 PM | R--D | M] - C:\Documents and Settings\Robb\My Documents\My Videos
[08/26/2008 03:40 PM | ---D | M] - C:\Documents and Settings\Robb\My Documents\English
[08/06/2008 10:24 PM | 00,001,604 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[08/08/2008 02:54 PM | 00,002,137 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[08/20/2008 11:03 PM | 00,001,801 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Logitech QuickCam.lnk
[08/26/2008 06:13 PM | 00,001,729 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[08/26/2008 06:15 PM | 00,000,734 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[08/05/2008 12:23 AM | 00,023,382 | ---- | M] () - C:\Documents and Settings\Robb\Desktop\041808_1734.jpg
[08/06/2008 10:18 PM | 63,530,280 | ---- | M] (Apple Inc.) - C:\Documents and Settings\Robb\Desktop\iTunesSetup.exe
[08/06/2008 10:32 PM | 00,002,495 | ---- | M] () - C:\Documents and Settings\Robb\Desktop\Microsoft Office Excel 2003.lnk
[08/21/2008 01:34 AM | 00,050,688 | ---- | M] (Atribune.org) - C:\Documents and Settings\Robb\Desktop\ATF_Cleaner.exe
[08/21/2008 02:03 AM | 00,001,734 | ---- | M] () - C:\Documents and Settings\Robb\Desktop\HijackThis.lnk
[08/21/2008 05:09 PM | 00,005,566 | ---- | M] () - C:\Documents and Settings\Robb\Desktop\Kaspersky Online Scan.html
[08/22/2008 02:43 PM | ---D | M] - C:\Documents and Settings\Robb\Desktop\SmitfraudFix
[08/22/2008 04:46 PM | 33,138,928 | ---- | M] (Kaspersky Lab) - C:\Documents and Settings\Robb\Desktop\kav8.0.0.454en.exe
[08/26/2008 06:01 PM | 00,291,840 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\Robb\Desktop\OTMoveIt2.exe
[08/26/2008 06:11 PM | 35,124,856 | ---- | M] ( ) - C:\Documents and Settings\Robb\Desktop\AdbeRdr90_en_US.exe
[08/26/2008 06:31 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\Robb\Desktop\OTViewIt.exe
[08/20/2008 11:09 PM | ---D | M] - C:\Program Files\Common Files\LogiShrd
[08/21/2008 02:07 AM | ---D | M] - C:\Program Files\Common Files\Wise Installation Wizard
[08/23/2008 11:29 AM | ---D | M] - C:\Program Files\Common Files\Ulead Systems
[08/23/2008 11:30 AM | ---D | M] - C:\Program Files\Common Files\Symantec Shared
[08/26/2008 06:13 PM | ---D | M] - C:\Program Files\Common Files\Adobe
[08/26/2008 06:14 PM | ---D | M] - C:\Program Files\Common Files\Adobe AIR
< End of report >
Edited by Rob L, 26 August 2008 - 04:37 PM.