Here is my OTviewIt report:
=====================================================================
OTViewIt logfile created on: 26/08/2008 19:30:23 - Run 3
OTViewIt by OldTimer - Version 1.0.0.12 Folder = C:\Documents and Settings\Alexander\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 74.34% Memory free
3.85 Gb Paging File | 3.45 Gb Available in Paging File | 89.62% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 284.48 Gb Free Space | 76.35% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ASTRIEL
Current User Name: Alexander
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
===== Processes - Non-Microsoft Only =====
[06/26/2007 03:04 PM | 02,165,256 | ---- | M] (Xpertvision, Inc.) - C:\Program Files\XpertVision\TBPANEL.exe
[09/12/2006 09:58 AM | 16,264,192 | R--- | M] (Realtek Semiconductor Corp.) - C:\WINDOWS\RTHDCPL.EXE
[06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[07/30/2008 10:47 AM | 00,289,064 | ---- | M] (Apple Inc.) - C:\Program Files\iTunes\iTunesHelper.exe
[04/23/2007 04:00 AM | 00,692,224 | ---- | M] (Logitech Inc.) - C:\Program Files\Logitech\SetPoint\SetPoint.exe
[04/30/2007 07:43 PM | 03,450,608 | ---- | M] (Stardock) - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
[04/11/2007 03:32 PM | 00,056,080 | ---- | M] (Logitech Inc.) - C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
[07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[12/20/2007 04:23 AM | 00,072,704 | ---- | M] (Autodesk) - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
[07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
[09/29/2006 01:48 PM | 00,065,536 | ---- | M] () - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
[07/23/2007 03:51 AM | 00,155,716 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\nvsvc32.exe
[07/30/2008 10:47 AM | 00,532,264 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
[08/22/2008 10:32 PM | 00,081,922 | ---- | M] () - C:\WINDOWS\system32\wK5Fl26G.exe
[07/03/2008 03:34 AM | 00,307,712 | ---- | M] (Mozilla Corporation) - C:\Program Files\Mozilla Firefox\firefox.exe
[08/26/2008 07:14 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\Alexander\Desktop\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Apple Mobile Device) Apple Mobile Device [Auto | Running]
[07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(Autodesk Licensing Service) Autodesk Licensing Service [Auto | Running]
[12/20/2007 04:23 AM | 00,072,704 | ---- | M] (Autodesk) - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
(Bonjour Service) Bonjour Service [Auto | Running]
[07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[08/04/2004 08:56 AM | 00,224,768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\dmadmin.exe
(FLEXnet Licensing Service) FLEXnet Licensing Service [On_Demand | Stopped]
[10/26/2007 08:38 AM | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(IDriverT) InstallDriver Table Manager [On_Demand | Stopped]
[11/14/2005 02:06 AM | 00,069,632 | ---- | M] (Macrovision Corporation) - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
(iPod Service) iPod Service [On_Demand | Running]
[07/30/2008 10:47 AM | 00,532,264 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
(mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) [Auto | Running]
[09/29/2006 01:48 PM | 00,065,536 | ---- | M] () - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
(NVSvc) NVIDIA Display Driver Service [Auto | Running]
[07/23/2007 03:51 AM | 00,155,716 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\nvsvc32.exe
(0270781219775139mcinstcleanup) McAfee Application Installer Cleanup (0270781219775139) [Auto | Stopped]
[02/23/2008 02:50 PM | 00,309,096 | ---- | M] (McAfee, Inc.) - C:\Documents and Settings\Alexander\Local Settings\Temp\0270781219775139mcinst.exe
===== Driver Services - Non-Microsoft Only =====
(Cardex) Cardex [On_Demand | Stopped]
[03/16/2007 10:11 AM | 00,012,256 | ---- | M] (Windows ® 2000 DDK provider) - C:\WINDOWS\system32\drivers\TBPanel.sys
(dmboot) dmboot [Disabled | Stopped]
[08/04/2004 07:07 AM | 00,799,744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmboot.sys
(dmio) Logical Disk Manager Driver [Boot | Running]
[08/04/2004 07:07 AM | 00,153,344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmio.sys
(dmload) dmload [Boot | Running]
[06/20/2003 01:00 PM | 00,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\drivers\dmload.sys
(GEARAspiWDM) GEARAspiWDM [On_Demand | Running]
[01/29/2008 12:01 PM | 00,016,168 | ---- | M] (GEAR Software Inc.) - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [On_Demand | Running]
[01/07/2005 05:07 PM | 00,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) - C:\WINDOWS\system32\drivers\Hdaudbus.sys
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [On_Demand | Running]
[09/12/2006 12:27 PM | 04,381,184 | R--- | M] (Realtek Semiconductor Corp.) - C:\WINDOWS\system32\drivers\RtkHDAud.sys
(k750bus) Sony Ericsson 750 driver (WDM) [On_Demand | Stopped]
[02/11/2005 12:19 PM | 00,055,216 | ---- | M] (MCCI) - C:\WINDOWS\system32\drivers\k750bus.sys
(k750mdfl) Sony Ericsson 750 USB WMC Modem Filter [On_Demand | Stopped]
[02/11/2005 12:21 PM | 00,006,576 | ---- | M] (MCCI) - C:\WINDOWS\system32\drivers\k750mdfl.sys
(k750mdm) Sony Ericsson 750 USB WMC Modem Drivers [On_Demand | Stopped]
[02/11/2005 12:21 PM | 00,089,872 | ---- | M] (MCCI) - C:\WINDOWS\system32\drivers\k750mdm.sys
(k750mgmt) Sony Ericsson 750 USB WMC Device Management Drivers [On_Demand | Stopped]
[03/13/2006 07:35 PM | 00,081,728 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\k750mgmt.sys
(k750obex) Sony Ericsson 750 USB WMC OBEX Interface Drivers [On_Demand | Stopped]
[03/13/2006 07:35 PM | 00,079,488 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\k750obex.sys
(L8042Kbd) Logitech SetPoint Keyboard Driver [On_Demand | Stopped]
[04/11/2007 03:32 PM | 00,020,496 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\L8042Kbd.sys
(LHidFilt) Logitech SetPoint KMDF HID Filter Driver [On_Demand | Running]
[04/11/2007 03:32 PM | 00,034,832 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LHidFilt.Sys
(LMouFilt) Logitech SetPoint KMDF Mouse Filter Driver [On_Demand | Running]
[04/11/2007 03:32 PM | 00,036,112 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LMouFilt.Sys
(LUsbFilt) Logitech SetPoint KMDF USB Filter [On_Demand | Running]
[04/11/2007 03:33 PM | 00,028,688 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LUsbFilt.sys
(mfehidk) McAfee Inc. mfehidk [Disabled | Running]
File not found - C:\WINDOWS\System32\drivers\mfehidk.sys
(MPFP) MPFP [Disabled | Running]
File not found - C:\WINDOWS\System32\Drivers\Mpfp.sys
(npkcrypt) npkcrypt [Auto | Running]
[11/14/2007 07:01 PM | 00,023,217 | ---- | M] (INCA Internet Co., Ltd.) - C:\Nexon\MapleStory\npkcrypt.sys
(npkcusb) npkcusb [On_Demand | Running]
[08/16/2007 11:04 AM | 00,015,472 | ---- | M] (INCA Internet Co., Ltd.) - C:\Program Files\NEXON\EuropeMapleStory\npkcusb.sys
(nv) nv [On_Demand | Running]
[07/23/2007 03:51 AM | 06,807,328 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\drivers\nv4_mini.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[06/20/2003 01:00 PM | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\system32\drivers\ptilink.sys
(PxHelp20) PxHelp20 [Boot | Running]
[03/08/2007 12:51 AM | 00,043,528 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\PxHelp20.sys
(RTLE8023xp) Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver [On_Demand | Running]
[08/14/2006 02:09 PM | 00,083,200 | R--- | M] (Realtek Semiconductor Corporation ) - C:\WINDOWS\system32\drivers\Rtenicxp.sys
(SCDEmu) SCDEmu [System | Running]
[01/31/2006 01:21 PM | 00,025,900 | ---- | M] (PowerISO Computing, Inc.) - C:\WINDOWS\System32\drivers\scdemu.sys
(se59bus) Sony Ericsson Device 089 driver (WDM) [On_Demand | Stopped]
[09/05/2006 09:07 PM | 00,061,536 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59bus.sys
(se59mdfl) Sony Ericsson Device 089 USB WMC Modem Filter [On_Demand | Stopped]
[09/05/2006 09:07 PM | 00,009,360 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59mdfl.sys
(se59mdm) Sony Ericsson Device 089 USB WMC Modem Driver [On_Demand | Stopped]
[09/05/2006 09:07 PM | 00,097,088 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59mdm.sys
(se59mgmt) Sony Ericsson Device 089 USB WMC Device Management Drivers (WDM) [On_Demand | Stopped]
[09/05/2006 09:08 PM | 00,088,624 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59mgmt.sys
(se59nd5) Sony Ericsson Device 089 USB Ethernet Emulation SEMC59 (NDIS) [On_Demand | Stopped]
[09/05/2006 09:06 PM | 00,018,704 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59nd5.sys
(se59obex) Sony Ericsson Device 089 USB WMC OBEX Interface [On_Demand | Stopped]
[09/05/2006 09:09 PM | 00,086,432 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59obex.sys
(se59unic) Sony Ericsson Device 089 USB Ethernet Emulation SEMC59 (WDM) [On_Demand | Stopped]
[09/05/2006 09:06 PM | 00,090,800 | R--- | M] (MCCI) - C:\WINDOWS\system32\drivers\se59unic.sys
(Secdrv) Secdrv [On_Demand | Stopped]
[06/20/2003 01:00 PM | 00,027,440 | ---- | M] () - C:\WINDOWS\system32\drivers\secdrv.sys
(sptd) sptd [Boot | Running]
[01/14/2008 03:18 AM | 00,685,816 | ---- | M] () - C:\WINDOWS\system32\drivers\sptd.sys
(STV680) USB Dual-mode Camera [On_Demand | Stopped]
[02/11/2002 02:13 PM | 00,119,536 | ---- | M] (STMicroelectronics ) - C:\WINDOWS\system32\drivers\stv680.sys
(STV680m) USB Dual-mode Cameram [On_Demand | Stopped]
[02/11/2002 02:13 PM | 00,009,024 | ---- | M] (STMicroelectronics ) - C:\WINDOWS\system32\drivers\stv680m.sys
(TBPanel) TBPanel [Auto | Running]
[03/16/2007 10:11 AM | 00,012,256 | ---- | M] (Windows ® 2000 DDK provider) - C:\WINDOWS\System32\drivers\TBPanel.sys
(USBAAPL) Apple Mobile USB Driver [On_Demand | Stopped]
[01/15/2008 03:39 AM | 00,030,464 | ---- | M] (Apple, Inc.) - C:\WINDOWS\system32\drivers\usbaapl.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher" = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM | 00,034,672 | ---- | M] (Adobe Systems Incorporated)
"Alcmtr" = ALCMTR.EXE [05/03/2005 11:43 AM | 00,069,632 | R--- | M] (Realtek Semiconductor Corp.)
"AppleSyncNotifier" = C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [07/10/2008 09:47 AM | 00,116,040 | ---- | M] (Apple Inc.)
"Gainward" = C:\Program Files\XpertVision\TBPanel.exe /A [06/26/2007 03:04 PM | 02,165,256 | ---- | M] (Xpertvision, Inc.)
"iTunesHelper" = "C:\Program Files\iTunes\iTunesHelper.exe" [07/30/2008 10:47 AM | 00,289,064 | ---- | M] (Apple Inc.)
"Kernel and Hardware Abstraction Layer" = KHALMNPR.EXE [04/11/2007 03:32 PM | 00,056,080 | ---- | M] (Logitech Inc.)
"NvCplDaemon" = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup [07/23/2007 03:51 AM | 08,466,432 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" = RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit [07/23/2007 03:51 AM | 00,081,920 | ---- | M] (NVIDIA Corporation)
"nwiz" = nwiz.exe /install [07/23/2007 03:51 AM | 01,626,112 | ---- | M] ()
"QuickTime Task" = "C:\Program Files\QuickTime\QTTask.exe" -atboottime [05/27/2008 10:50 AM | 00,413,696 | ---- | M] (Apple Inc.)
"RTHDCPL" = RTHDCPL.EXE [09/12/2006 09:58 AM | 16,264,192 | R--- | M] (Realtek Semiconductor Corp.)
"SkyTel" = SkyTel.EXE [05/16/2006 11:04 AM | 02,879,488 | R--- | M] (Realtek Semiconductor Corp.)
"Sony Ericsson PC Suite" = "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions [04/26/2007 10:45 AM | 00,401,408 | R--- | M] ()
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[Alexander Startup Folder - C:\Documents and Settings\Alexander\Start Menu\Programs\Startup]
[04/30/2007 07:43 PM | 03,450,608 | ---- | M] (Stardock) - C:\Documents and Settings\Alexander\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[04/23/2007 04:00 AM | 00,692,224 | ---- | M] (Logitech Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
HKLM CLSID: (Adobe PDF Link Helper) - [06/11/2008 10:33 PM | 00,075,128 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
HKLM CLSID: (Spybot-S&D IE Protection) - [07/07/2008 09:41 AM | 01,562,448 | ---- | M] (Safer Networking Limited) C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
===== Toolbars =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{0BF43445-2F28-4351-9252-17FE6E806AA0}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
Unable to open key or key not present!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
===== Desktop Components =====
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
===== Lsa Authentication Packages =====
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 08:56 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe [10/18/2007 11:34 AM | 05,724,184 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe [10/02/2007 05:18 PM | 00,304,488 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 08:56 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe [10/13/2004 05:24 PM | 01,694,208 | ---- | M] (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe [08/25/2008 10:15 PM | 00,267,056 | ---- | M] (BitTorrent, Inc.)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe [07/16/2008 10:16 AM | 01,069,712 | ---- | M] (Blizzard Entertainment)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe File not found
"C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe" = C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe [08/04/2004 08:56 AM | 00,768,512 | ---- | M] (Microsoft Corporation)
"C:\Nexon\MapleStory\MapleStory.exe" = C:\Nexon\MapleStory\MapleStory.exe [11/14/2007 06:59 PM | 01,746,466 | ---- | M] (Wizet)
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" = C:\Program Files\Veoh Networks\Veoh\VeohClient.exe File not found
"C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe" = C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe [09/29/2006 03:30 PM | 05,946,368 | ---- | M] (Autodesk, Inc.)
"C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe" = C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe [01/04/2008 04:55 PM | 01,691,648 | ---- | M] (SQUARE ENIX CO., LTD.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe [01/10/2008 07:17 PM | 00,147,456 | ---- | M] (Lime Wire, LLC)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe [10/18/2007 11:34 AM | 05,724,184 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe [10/02/2007 05:18 PM | 00,304,488 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe [07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe [07/30/2008 10:47 AM | 20,252,968 | ---- | M] (Apple Inc.)
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"explorer.exe" - [06/13/2007 11:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 08:56 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 08:56 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10/26/2007 04:36 AM | 08,454,656 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 08:56 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
===== User's Winlogon Settings =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"explorer.exe" - [06/13/2007 11:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
===== Winlogon Notify Settings =====
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
Unable to open key or key not present!
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{34ED32A2-02EA-4D0F-AF02-4956AD18E372}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{5589A793-8EC4-489D-821C-D99BB57A31E8}]
Servers: | Description: Realtek RTL8139/810x Family Fast Ethernet NIC
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{F5537543-2B7F-427D-B61C-DFE8B6D4ADE3}]
Servers: | Description: Sony Ericsson Device 089 USB Ethernet Emulation (NDIS 5)
===== CDRom AutoRun Settings =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
===== Autorun Files on Drives =====
AUTOEXEC.BAT []
[10/19/2007 05:26 PM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
Automap []
[04/20/2008 06:22 PM | ---D | M] C:\Automap [ NTFS ]
===== MountPoints2 =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{19a0f208-28f3-11dd-a881-001966341d0e}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{19a0f208-28f3-11dd-a881-001966341d0e}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/26/2007 04:36 AM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{19a0f208-28f3-11dd-a881-001966341d0e}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{747a6db0-ac26-11dc-a76e-001966341d0e}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{747a6db0-ac26-11dc-a76e-001966341d0e}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/26/2007 04:36 AM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{747a6db0-ac26-11dc-a76e-001966341d0e}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{87a5e79e-8b8d-11dc-a717-001966341d0e}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{87a5e79e-8b8d-11dc-a717-001966341d0e}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/26/2007 04:36 AM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{87a5e79e-8b8d-11dc-a717-001966341d0e}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bcf88345-aa72-11dc-a76a-001966341d0e}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bcf88345-aa72-11dc-a76a-001966341d0e}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/26/2007 04:36 AM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bcf88345-aa72-11dc-a76a-001966341d0e}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbe290d8-6dee-11dd-a925-001966341d0e}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbe290d8-6dee-11dd-a925-001966341d0e}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/26/2007 04:36 AM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbe290d8-6dee-11dd-a925-001966341d0e}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
===== Hosts File =====
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[Files/Folders - Created Within 30 days]
[08/05/2008 12:23 AM | ---D | C] - C:\7c0006c557841ce53b3bc8cb86
[08/26/2008 07:18 PM | -HSD | C] - C:\Config.Msi
[06/10/2008 01:21 AM | 00,135,168 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[06/10/2008 01:21 AM | 00,135,168 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[06/10/2008 02:32 AM | 00,139,264 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[08/06/2008 03:17 AM | 00,016,832 | ---- | C] () - C:\WINDOWS\System32\amcompat.tlb
[08/06/2008 03:17 AM | 00,023,392 | ---- | C] () - C:\WINDOWS\System32\nscompat.tlb
[08/22/2008 06:02 PM | 00,000,000 | ---- | C] () - C:\WINDOWS\System32\cyiOA2ur.exe.a_a
[08/22/2008 08:32 PM | 00,000,000 | ---- | C] () - C:\WINDOWS\System32\wK5Fl26G.exe.a_a
[08/22/2008 10:32 PM | 00,081,922 | ---- | C] () - C:\WINDOWS\System32\wK5Fl26G.exe
[08/23/2008 12:38 AM | 00,081,922 | ---- | C] () - C:\WINDOWS\System32\cyiOA2ur.exe
[3 C:\WINDOWS\*.tmp files]
[03/24/1997 05:42 PM | 00,314,368 | ---- | C] (InstallShield Software Corporation) - C:\WINDOWS\IsUninst.exe
[08/23/2008 01:25 AM | ---D | C] - C:\WINDOWS\ROSE Online Evolution
[08/26/2008 07:28 PM | ---D | C] - C:\WINDOWS\LastGood
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At10.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At11.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At5.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At6.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At7.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At8.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At9.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At29.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At30.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At31.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At32.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At33.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At34.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At35.job
[08/23/2008 04:24 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At12.job
[08/23/2008 08:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At21.job
[08/23/2008 08:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At45.job
[08/23/2008 11:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At36.job
[08/23/2008 12:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At13.job
[08/23/2008 12:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At37.job
[08/24/2008 02:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At27.job
[08/24/2008 02:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At3.job
[08/24/2008 03:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At28.job
[08/24/2008 03:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At4.job
[08/25/2008 09:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At22.job
[08/25/2008 09:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At46.job
[08/25/2008 10:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At23.job
[08/25/2008 10:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At47.job
[08/25/2008 11:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At24.job
[08/25/2008 11:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At48.job
[08/26/2008 01:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At2.job
[08/26/2008 01:00 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At26.job
[08/26/2008 01:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At38.job
[08/26/2008 01:59 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At14.job
[08/26/2008 02:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At15.job
[08/26/2008 02:05 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At39.job
[08/26/2008 03:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At40.job
[08/26/2008 04:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At17.job
[08/26/2008 04:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At41.job
[08/26/2008 04:26 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At16.job
[08/26/2008 05:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At42.job
[08/26/2008 05:27 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At18.job
[08/26/2008 06:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At19.job
[08/26/2008 06:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At43.job
[08/26/2008 07:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At20.job
[08/26/2008 07:00 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At44.job
[08/26/2008 12:11 AM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At25.job
[08/26/2008 12:16 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At1.job
[08/23/2008 10:05 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[08/19/2008 04:25 PM | ---D | C] - C:\Documents and Settings\Alexander\Application Data\GrabIt
[08/25/2008 10:28 PM | 00,014,775 | R--- | C] () - C:\Documents and Settings\Alexander\My Documents\02+-+Shibo.jpg
[08/26/2008 04:16 PM | ---D | C] - C:\Documents and Settings\Alexander\My Documents\LimeWire
[08/26/2008 04:26 PM | ---D | C] - C:\Documents and Settings\Alexander\My Documents\Incomplete
[08/27/2008 01:28 AM | ---D | C] - C:\Documents and Settings\Alexander\My Documents\Emoticons
[08/26/2008 07:18 PM | 00,000,734 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[08/26/2008 07:18 PM | 00,001,729 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[08/26/2008 07:14 PM | 00,812,344 | ---- | C] (Trend Micro Inc.) - C:\Documents and Settings\Alexander\Desktop\HJTInstall.exe
[08/26/2008 07:14 PM | 01,299,968 | ---- | C] (OldTimer Tools) - C:\Documents and Settings\Alexander\Desktop\OTViewIt.exe
[08/26/2008 07:15 PM | 00,001,734 | ---- | C] () - C:\Documents and Settings\Alexander\Desktop\HijackThis.lnk
[08/26/2008 07:16 PM | 35,124,856 | ---- | C] ( ) - C:\Documents and Settings\Alexander\Desktop\AdbeRdr90_en_US.exe
[08/26/2008 07:29 PM | 48,367,896 | ---- | C] (AVG Technologies) - C:\Documents and Settings\Alexander\Desktop\avg_free_stf_en_8_138a1332.exe
[08/26/2008 07:25 PM | 00,001,581 | ---- | C] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk
[08/26/2008 07:18 PM | ---D | C] - C:\Program Files\Common Files\Adobe AIR
[08/04/2008 11:27 PM | ---D | C] - C:\Program Files\iPod
[08/14/2008 01:41 AM | ---D | C] - C:\Program Files\Abe's Oddysee
[08/23/2008 01:25 AM | ---D | C] - C:\Program Files\Triggersoft
[08/23/2008 12:29 AM | ---D | C] - C:\Program Files\Spybot - Search & Destroy
[08/26/2008 01:57 PM | ---D | C] - C:\Program Files\HijackThis
[08/26/2008 07:15 PM | ---D | C] - C:\Program Files\Trend Micro
[Files/Folders - Modified Within 30 days]
[08/05/2008 12:23 AM | ---D | M] - C:\7c0006c557841ce53b3bc8cb86
[08/26/2008 07:15 PM | R--D | M] - C:\Program Files
[08/26/2008 07:18 PM | -HSD | M] - C:\Config.Msi
[08/26/2008 07:25 PM | ---D | M] - C:\WINDOWS
[08/05/2008 12:23 AM | ---D | M] - C:\WINDOWS\System32\drivers\UMDF
[8 C:\WINDOWS\System32\*.tmp files]
[08/05/2008 12:23 AM | RHSD | M] - C:\WINDOWS\System32\dllcache
[08/05/2008 12:25 AM | ---D | M] - C:\WINDOWS\System32\CatRoot
[08/06/2008 03:17 AM | 00,016,832 | ---- | M] () - C:\WINDOWS\System32\amcompat.tlb
[08/06/2008 03:17 AM | 00,023,392 | ---- | M] () - C:\WINDOWS\System32\nscompat.tlb
[08/22/2008 06:02 PM | 00,000,000 | ---- | M] () - C:\WINDOWS\System32\cyiOA2ur.exe.a_a
[08/22/2008 08:32 PM | 00,000,000 | ---- | M] () - C:\WINDOWS\System32\wK5Fl26G.exe.a_a
[08/22/2008 10:32 PM | 00,081,922 | ---- | M] () - C:\WINDOWS\System32\wK5Fl26G.exe
[08/23/2008 01:37 AM | ---D | M] - C:\WINDOWS\System32\CatRoot2
[08/23/2008 12:38 AM | 00,081,922 | ---- | M] () - C:\WINDOWS\System32\cyiOA2ur.exe
[08/25/2008 08:37 PM | 00,002,206 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[08/26/2008 07:28 PM | ---D | M] - C:\WINDOWS\System32\drivers
[3 C:\WINDOWS\*.tmp files]
[08/05/2008 09:01 PM | ---D | M] - C:\WINDOWS\Help
[08/05/2008 12:23 AM | 00,001,355 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08/05/2008 12:23 AM | 00,316,640 | ---- | M] () - C:\WINDOWS\WMSysPr9.prx
[08/11/2008 11:23 PM | -H-D | M] - C:\WINDOWS\inf
[08/23/2008 01:25 AM | ---D | M] - C:\WINDOWS\ROSE Online Evolution
[08/23/2008 05:00 PM | 00,000,675 | ---- | M] () - C:\WINDOWS\win.ini
[08/26/2008 01:41 AM | ---D | M] - C:\WINDOWS\security
[08/26/2008 07:18 PM | -HSD | M] - C:\WINDOWS\Installer
[08/26/2008 07:27 PM | 00,000,558 | ---- | M] () - C:\WINDOWS\DFC.INI
[08/26/2008 07:28 PM | ---D | M] - C:\WINDOWS\LastGood
[08/26/2008 07:28 PM | ---D | M] - C:\WINDOWS\Prefetch
[08/26/2008 07:28 PM | ---D | M] - C:\WINDOWS\system32
[08/26/2008 07:28 PM | ---D | M] - C:\WINDOWS\Temp
[08/26/2008 07:28 PM | --SD | M] - C:\WINDOWS\Tasks
[08/26/2008 12:16 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08/04/2008 11:27 PM | 00,000,284 | ---- | M] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At10.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At11.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At5.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At6.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At7.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At8.job
[08/22/2008 06:02 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At9.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At29.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At30.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At31.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At32.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At33.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At34.job
[08/22/2008 06:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At35.job
[08/23/2008 04:24 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At12.job
[08/23/2008 08:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At21.job
[08/23/2008 08:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At45.job
[08/23/2008 11:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At36.job
[08/23/2008 12:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At13.job
[08/23/2008 12:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At37.job
[08/24/2008 02:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At27.job
[08/24/2008 02:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At3.job
[08/24/2008 03:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At28.job
[08/24/2008 03:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At4.job
[08/25/2008 09:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At22.job
[08/25/2008 09:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At46.job
[08/25/2008 10:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At23.job
[08/25/2008 10:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At47.job
[08/25/2008 11:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At24.job
[08/25/2008 11:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At48.job
[08/26/2008 01:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At2.job
[08/26/2008 01:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At26.job
[08/26/2008 01:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At38.job
[08/26/2008 01:59 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At14.job
[08/26/2008 02:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At15.job
[08/26/2008 02:05 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At39.job
[08/26/2008 03:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At40.job
[08/26/2008 04:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At17.job
[08/26/2008 04:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At41.job
[08/26/2008 04:26 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At16.job
[08/26/2008 05:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At42.job
[08/26/2008 05:27 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At18.job
[08/26/2008 06:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At19.job
[08/26/2008 06:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At43.job
[08/26/2008 07:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At20.job
[08/26/2008 07:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At44.job
[08/26/2008 12:11 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At25.job
[08/26/2008 12:16 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/26/2008 12:16 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At1.job
[08/23/2008 10:05 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[08/26/2008 07:18 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Adobe
[08/27/2008 01:31 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\WLInstaller
[08/27/2008 01:39 AM | --SD | M] - C:\Documents and Settings\All Users\Application Data\Microsoft
[08/19/2008 04:25 PM | ---D | M] - C:\Documents and Settings\Alexander\Application Data\GrabIt
[08/23/2008 04:40 PM | ---D | M] - C:\Documents and Settings\Alexander\Application Data\foobar2000
[08/23/2008 04:51 PM | ---D | M] - C:\Documents and Settings\Alexander\Application Data\Mozilla
[08/23/2008 12:56 AM | ---D | M] - C:\Documents and Settings\Alexander\Application Data\Tibia
[08/26/2008 01:20 AM | ---D | M] - C:\Documents and Settings\Alexander\Application Data\uTorrent
[08/26/2008 04:19 PM | ---D | M] - C:\Documents and Settings\Alexander\Application Data\LimeWire
[08/14/2008 02:27 AM | 01,575,224 | -H-- | M] () - C:\Documents and Settings\Alexander\Local Settings\Application Data\IconCache.db
[08/23/2008 04:47 PM | 00,015,872 | ---- | M] () - C:\Documents and Settings\Alexander\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[08/24/2008 01:16 AM | ---D | M] - C:\Documents and Settings\Alexander\Local Settings\Application Data\Microsoft
[08/26/2008 07:18 PM | ---D | M] - C:\Documents and Settings\Alexander\Local Settings\Application Data\Adobe
[08/14/2008 12:45 AM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\My Software
[08/23/2008 04:38 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\ig
[08/23/2008 04:40 PM | R--D | M] - C:\Documents and Settings\Alexander\My Documents\My Music
[08/23/2008 04:43 PM | R--D | M] - C:\Documents and Settings\Alexander\My Documents\My Received Files
[08/23/2008 04:44 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\Games
[08/23/2008 04:45 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\My Videos
[08/23/2008 04:45 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\Others
[08/23/2008 04:46 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\USB crap
[08/23/2008 04:47 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\743057
[08/23/2008 04:47 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\USB
[08/23/2008 04:49 PM | R--D | M] - C:\Documents and Settings\Alexander\My Documents\My Pictures
[08/25/2008 10:28 PM | 00,014,775 | R--- | M] () - C:\Documents and Settings\Alexander\My Documents\02+-+Shibo.jpg
[08/25/2008 10:54 PM | 00,044,544 | -HS- | M] () - C:\Documents and Settings\Alexander\My Documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
[08/26/2008 04:13 PM | 00,000,596 | ---- | M] () - C:\Documents and Settings\Alexander\My Documents\My Sharing Folders.lnk
[08/26/2008 04:16 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\LimeWire
[08/26/2008 04:19 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\Downloads
[08/26/2008 04:26 PM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\Incomplete
[08/27/2008 01:28 AM | ---D | M] - C:\Documents and Settings\Alexander\My Documents\Emoticons
[08/26/2008 07:18 PM | 00,000,734 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[08/26/2008 07:18 PM | 00,001,729 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[08/21/2008 08:20 PM | 00,200,192 | -HS- | M] () - C:\Documents and Settings\Alexander\Desktop\Thumbs.db
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
[08/26/2008 07:14 PM | 00,812,344 | ---- | M] (Trend Micro Inc.) - C:\Documents and Settings\Alexander\Desktop\HJTInstall.exe
[08/26/2008 07:14 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\Alexander\Desktop\OTViewIt.exe
[08/26/2008 07:15 PM | 00,001,734 | ---- | M] () - C:\Documents and Settings\Alexander\Desktop\HijackThis.lnk
[08/26/2008 07:16 PM | 35,124,856 | ---- | M] ( ) - C:\Documents and Settings\Alexander\Desktop\AdbeRdr90_en_US.exe
[08/26/2008 07:29 PM | 48,367,896 | ---- | M] (AVG Technologies) - C:\Documents and Settings\Alexander\Desktop\avg_free_stf_en_8_138a1332.exe
[08/26/2008 07:25 PM | 00,001,581 | ---- | M] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk
[08/26/2008 07:18 PM | ---D | M] - C:\Program Files\Common Files\Adobe
[08/26/2008 07:18 PM | ---D | M] - C:\Program Files\Common Files\Adobe AIR
[08/27/2008 01:38 AM | -HSD | M] - C:\Program Files\Common Files\WindowsLiveInstaller
[08/27/2008 01:39 AM | ---D | M] - C:\Program Files\Common Files\Microsoft Shared
< End of report >
Edited by Alleluia, 26 August 2008 - 12:29 PM.