OTViewIt.Txt
OTViewIt logfile created on: 9/1/2008 10:01:53 PM - Run 1
OTViewIt by OldTimer - Version 1.0.1.7 Folder = C:\Documents and Settings\blogan\Desktop
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.36 Mb Total Physical Memory | 233.18 Mb Available Physical Memory | 22.97% Memory free
2.40 Gb Paging File | 1.57 Gb Available in Paging File | 65.45% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 54.64 Gb Free Space | 73.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BLOGAN4
Current User Name: blogan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
===== Processes - Non-Microsoft Only =====
[06/03/2005 01:25 AM | 00,086,016 | ---- | M] (Intel Corporation) - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
[06/03/2005 01:28 AM | 00,372,809 | ---- | M] (Intel Corporation ) - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
[09/06/2007 01:28 PM | 00,110,592 | ---- | M] (Apple, Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[11/20/2006 09:55 PM | 00,348,160 | ---- | M] (Juniper Networks) - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
[02/13/2004 11:47 AM | 00,155,648 | ---- | M] (Dell Inc) - C:\Program Files\Dell\OpenManage\Client\Iap.exe
[01/27/2006 06:01 PM | 00,075,328 | ---- | M] (PatchLink Corporation) - C:\Program Files\PatchLink\Update Agent\GravitixService.exe
[06/03/2005 01:25 AM | 00,139,264 | ---- | M] (Intel Corporation) - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
[09/27/2006 09:33 PM | 00,116,464 | ---- | M] (symantec) - C:\Program Files\Symantec AntiVirus\SavRoam.exe
[06/25/2004 06:15 PM | 00,045,056 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
[05/31/2005 10:46 PM | 00,401,408 | ---- | M] (Intel Corporation) - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[06/03/2005 01:26 AM | 00,245,760 | ---- | M] (Intel) - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
[03/04/2005 11:26 AM | 00,606,208 | ---- | M] () - C:\Program Files\Dell\QuickSet\quickset.exe
[02/06/2003 02:41 PM | 00,028,672 | ---- | M] (Dell - Advanced Desktop Engineering) - C:\WINDOWS\system32\DSentry.exe
[06/03/2005 01:31 AM | 00,385,024 | ---- | M] (Intel Corporation) - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
[01/27/2006 06:02 PM | 00,419,392 | ---- | M] (PatchLink Corporation) - C:\Program Files\PatchLink\Update Agent\pddm.exe
[10/31/2005 11:05 AM | 00,278,528 | ---- | M] (Walt Disney Internet Group) - C:\Program Files\DIGStream\digstream.exe
[10/31/2005 11:18 AM | 00,101,888 | ---- | M] (Walt Disney Internet Group) - C:\Program Files\ESPNRunTime\DIGServices.exe
[11/23/2002 02:15 AM | 00,631,362 | ---- | M] (Logitech Inc.) - C:\Program Files\Logitech\iTouch\iTouch.exe
[11/08/2002 05:50 AM | 00,019,968 | ---- | M] (Logitech Inc.) - C:\WINDOWS\LOGI_MWX.EXE
[07/19/2005 06:06 PM | 00,077,824 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\hkcmd.exe
[07/19/2005 06:10 PM | 00,114,688 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\igfxpers.exe
[07/19/2005 06:06 PM | 00,159,744 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\igfxsrvc.exe
[01/24/2006 09:55 AM | 02,633,728 | ---- | M] (LaCie Group) - C:\Program Files\LaCie\Backup Software\LacieBackup.exe
[08/18/2008 06:41 PM | 01,832,272 | RHS- | M] (Safer Networking Limited) - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[07/26/2005 12:35 PM | 00,091,672 | R--- | M] (Logitech ) - C:\Program Files\Logitech\Harmony Remote\HarmonyClient.exe
===== Win32 Services - Non-Microsoft Only =====
(Apple Mobile Device) Apple Mobile Device [Auto | Running]
[09/06/2007 01:28 PM | 00,110,592 | ---- | M] (Apple, Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(dsNcService) Juniper Network Connect Service [Auto | Running]
[11/20/2006 09:55 PM | 00,348,160 | ---- | M] (Juniper Networks) - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
(EvtEng) EvtEng [Auto | Running]
[06/03/2005 01:25 AM | 00,086,016 | ---- | M] (Intel Corporation) - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(Iap) Iap [Auto | Running]
[02/13/2004 11:47 AM | 00,155,648 | ---- | M] (Dell Inc) - C:\Program Files\Dell\OpenManage\Client\Iap.exe
(PatchLink Update) PatchLink Update [Auto | Running]
[01/27/2006 06:01 PM | 00,075,328 | ---- | M] (PatchLink Corporation) - C:\Program Files\PatchLink\Update Agent\GravitixService.exe
(Pml Driver HPZ12) Pml Driver HPZ12 [Auto | Stopped]
File not found - C:\WINDOWS\system32\HPZipm12.exe
(RegSrvc) RegSrvc [Auto | Running]
[06/03/2005 01:25 AM | 00,139,264 | ---- | M] (Intel Corporation) - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
(S24EventMonitor) Spectrum24 Event Monitor [Auto | Running]
[06/03/2005 01:28 AM | 00,372,809 | ---- | M] (Intel Corporation ) - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
(SavRoam) SavRoam [Auto | Running]
[09/27/2006 09:33 PM | 00,116,464 | ---- | M] (symantec) - C:\Program Files\Symantec AntiVirus\SavRoam.exe
(WLTRYSVC) WLTRYSVC [Auto | Running]
[06/25/2004 06:15 PM | 00,045,056 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
===== Driver Services - Non-Microsoft Only =====
(APPDRV) APPDRV [System | Running]
[08/18/2004 02:53 PM | 00,016,128 | ---- | M] (Dell Inc) - C:\WINDOWS\system32\drivers\APPDRV.SYS
(dsNcAdpt) Juniper Network Connect Adapter [On_Demand | Running]
[11/20/2006 09:55 PM | 00,023,552 | ---- | M] (Juniper Networks) - C:\WINDOWS\system32\drivers\dsNcAdpt.sys
(GTIPCI21) GTIPCI21 [On_Demand | Running]
[05/03/2004 04:26 PM | 00,080,384 | ---- | M] (Texas Instruments) - C:\WINDOWS\system32\drivers\gtipci21.sys
(ialm) ialm [On_Demand | Running]
[07/19/2005 06:34 PM | 01,049,180 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\ialmnt5.sys
(itchfltr) iTouch Keyboard Filter [On_Demand | Running]
[11/14/2002 10:15 PM | 00,012,640 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\itchfltr.sys
(IWCA) Intel Wireless Connection Agent Miniport for Win XP [On_Demand | Running]
[08/12/2004 08:44 AM | 00,234,496 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\iwca.sys
(LCcfltr) Logitech USB Filter Driver [On_Demand | Stopped]
[11/08/2002 05:50 AM | 00,014,156 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LCCFLTR.SYS
(LHidFlt2) Logitech HID/USB Mouse Filter Driver [On_Demand | Stopped]
[11/08/2002 05:50 AM | 00,023,838 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LHIDFLT2.SYS
(LHidUsb) Logitech USB Receiver device driver [On_Demand | Stopped]
[11/08/2002 05:50 AM | 00,041,420 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\Lhidusb.sys
(LMouFlt2) Logitech Mouse Class Filter Driver [On_Demand | Stopped]
[11/08/2002 05:50 AM | 00,070,238 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\lmouflt2.sys
(ncvcp) Network Connect Virtual Com Port [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\nsvcp.sys
(OMCI) OMCI WDM Device Driver [System | Running]
[02/13/2004 11:46 AM | 00,017,153 | ---- | M] (Dell Inc) - C:\WINDOWS\system32\drivers\omci.sys
(RimVSerPort) RIM Virtual Serial Port v2 [On_Demand | Running]
[06/30/2006 04:10 PM | 00,026,752 | R--- | M] (Research in Motion Ltd) - C:\WINDOWS\system32\drivers\RimSerial.sys
(s24trans) WLAN Transport [Auto | Running]
[05/03/2005 07:03 AM | 00,011,354 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\s24trans.sys
(SbcpHid) SbcpHid [System | Running]
[08/23/2001 03:00 PM | 00,022,400 | ---- | M] () - C:\WINDOWS\system32\drivers\SbcpHid.sys
(Secdrv) Secdrv [On_Demand | Stopped]
[08/29/2002 06:00 AM | 00,027,440 | ---- | M] () - C:\WINDOWS\system32\drivers\secdrv.sys
(UIUSys) Conexant Setup API [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\UIUSys.sys
========== Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"" = File not found
"Apoint" = C:\Program Files\Apoint\Apoint.exe [09/13/2004 11:33 AM | 00,155,648 | ---- | M] (Alps Electric Co., Ltd.)
"ATIPTA" = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [10/06/2004 09:10 PM | 00,344,064 | ---- | M] (ATI Technologies, Inc.)
"AVG7_CC" = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP [04/19/2008 06:31 PM | 00,579,584 | ---- | M] (GRISOFT, s.r.o.)
"ccApp" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [07/19/2006 08:26 PM | 00,052,896 | ---- | M] (Symantec Corporation)
"Dell QuickSet" = C:\Program Files\Dell\QuickSet\quickset.exe [03/04/2005 11:26 AM | 00,606,208 | ---- | M] ()
"DIGStream" = C:\Program Files\DIGStream\digstream.exe [10/31/2005 11:05 AM | 00,278,528 | ---- | M] (Walt Disney Internet Group)
"DVDLauncher" = "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [04/26/2004 09:04 AM | 00,053,248 | ---- | M] (CyberLink Corp.)
"DVDSentry" = C:\WINDOWS\system32\DSentry.exe [02/06/2003 02:41 PM | 00,028,672 | ---- | M] (Dell - Advanced Desktop Engineering)
"HP Software Update" = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [02/19/2006 02:41 AM | 00,049,152 | ---- | M] (Hewlett-Packard Development Company, L.P.)
"HPDJ Taskbar Utility" = C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe [01/13/2006 02:46 AM | 00,196,608 | ---- | M] (HP)
"HPHmon03" = C:\WINDOWS\system32\hphmon03.exe [01/13/2006 02:46 AM | 00,311,296 | ---- | M] (Hewlett-Packard)
"igfxhkcmd" = C:\WINDOWS\system32\hkcmd.exe [07/19/2005 06:06 PM | 00,077,824 | ---- | M] (Intel Corporation)
"igfxpers" = C:\WINDOWS\system32\igfxpers.exe [07/19/2005 06:10 PM | 00,114,688 | ---- | M] (Intel Corporation)
"igfxtray" = C:\WINDOWS\system32\igfxtray.exe [07/19/2005 06:09 PM | 00,094,208 | ---- | M] (Intel Corporation)
"IntelWireless" = C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless [06/03/2005 01:31 AM | 00,385,024 | ---- | M] (Intel Corporation)
"IntelZeroConfig" = C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [05/31/2005 10:46 PM | 00,401,408 | ---- | M] (Intel Corporation)
"iTunesHelper" = "C:\Program Files\iTunes\iTunesHelper.exe" [09/26/2007 02:42 PM | 00,267,064 | ---- | M] (Apple Inc.)
"Logitech Utility" = Logi_MwX.Exe [11/08/2002 05:50 AM | 00,019,968 | ---- | M] (Logitech Inc.)
"PDDM" = C:\PROGRAM FILES\PATCHLINK\UPDATE AGENT\pddm.exe [01/27/2006 06:02 PM | 00,419,392 | ---- | M] (PatchLink Corporation)
"QuickTime Task" = "C:\Program Files\QuickTime\QTTask.exe" -atboottime [06/29/2007 06:24 AM | 00,286,720 | ---- | M] (Apple Inc.)
"UpdateManager" = "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r [01/07/2004 01:01 AM | 00,110,592 | ---- | M] (Sonic Solutions)
"vptray" = C:\PROGRA~1\SYMANT~1\VPTray.exe [09/27/2006 09:33 PM | 00,125,168 | ---- | M] (Symantec Corporation)
"zBrowser Launcher" = C:\Program Files\Logitech\iTouch\iTouch.exe [11/23/2002 02:15 AM | 00,631,362 | ---- | M] (Logitech Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaCie Backup" = C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background [01/24/2006 09:55 AM | 02,633,728 | ---- | M] (LaCie Group)
"No Adware No Spyware" = C:\Program Files\NoAdware.com\No Adware No Spyware\NoAdware.exe [03/14/2007 10:56 AM | 00,884,736 | ---- | M] (NoAdware.com)
"SpybotSD TeaTimer" = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [08/18/2008 06:41 PM | 01,832,272 | RHS- | M] (Safer Networking Limited)
"updateMgr" = "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 [03/30/2006 04:45 PM | 00,313,472 | ---- | M] (Adobe Systems Incorporated)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run" = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE [10/24/2007 09:57 AM | 00,219,136 | ---- | M] (GRISOFT, s.r.o.)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run" = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE [10/24/2007 09:57 AM | 00,219,136 | ---- | M] (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run" = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE [10/24/2007 09:57 AM | 00,219,136 | ---- | M] (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run" = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE [10/24/2007 09:57 AM | 00,219,136 | ---- | M] (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-21-12604286-1649964785-1244796221-24336\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaCie Backup" = C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background [01/24/2006 09:55 AM | 02,633,728 | ---- | M] (LaCie Group)
"No Adware No Spyware" = C:\Program Files\NoAdware.com\No Adware No Spyware\NoAdware.exe [03/14/2007 10:56 AM | 00,884,736 | ---- | M] (NoAdware.com)
"SpybotSD TeaTimer" = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [08/18/2008 06:41 PM | 01,832,272 | RHS- | M] (Safer Networking Limited)
"updateMgr" = "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 [03/30/2006 04:45 PM | 00,313,472 | ---- | M] (Adobe Systems Incorporated)
[HKEY_USERS\S-1-5-21-12604286-1649964785-1244796221-24336\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
========== Startup Folders ==========
[adm_cwheeloc Startup Folder - C:\Documents and Settings\adm_cwheeloc\Start Menu\Programs\Startup]
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[09/24/2005 02:05 AM | 00,029,696 | ---- | M] (Adobe Systems Incorporated) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[02/19/2006 04:21 AM | 00,288,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[03/26/2007 10:08 AM | 00,169,472 | ---- | M] (Logitech) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
[07/26/2005 12:35 PM | 00,091,672 | R--- | M] (Logitech ) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Harmony Remote.lnk = C:\Program Files\Logitech\Harmony Remote\HarmonyClient.exe
[blogan Startup Folder - C:\Documents and Settings\blogan\Start Menu\Programs\Startup]
[Default User Startup Folder - C:\Documents and Settings\Default User\Start Menu\Programs\Startup]
[outlaw Startup Folder - C:\Documents and Settings\outlaw\Start Menu\Programs\Startup]
[outlaw.OUTLAWXP Startup Folder - C:\Documents and Settings\outlaw.OUTLAWXP\Start Menu\Programs\Startup]
========== BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
HKLM CLSID: (Yahoo! Toolbar Helper) - [10/26/2006 12:28 PM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (Adobe PDF Reader Link Helper) - [01/12/2006 09:38 PM | 00,063,128 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
HKLM CLSID: (Spybot-S&D IE Protection) - [07/07/2008 09:41 AM | 01,562,448 | ---- | M] (Safer Networking Limited) C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
HKLM CLSID: (DriveLetterAccess) - [08/13/2004 01:05 AM | 00,118,842 | ---- | M] (Sonic Solutions) C:\WINDOWS\system32\dla\tfswshx.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [11/10/2005 02:22 PM | 00,184,423 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
========== Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{8E718888-423F-11D2-876E-00A0C9082467}"
HKLM CLSID: (&Radio) - [08/29/2002 06:00 AM | 00,842,268 | ---- | M] () C:\WINDOWS\system32\msdxm.ocx
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - [10/26/2006 12:28 PM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - [10/26/2006 12:28 PM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_USERS\S-1-5-21-12604286-1649964785-1244796221-24336\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - [10/26/2006 12:28 PM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
========== AppInit_Dlls ==========
========== HKLM Security Providers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders]
"msapsspc.dll schannel.dll digest.dll msnsspc.dll" - File not found
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [08/29/2002 06:00 AM | 01,004,032 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/29/2002 06:00 AM | 00,022,016 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/29/2002 06:00 AM | 00,504,320 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [08/29/2002 06:00 AM | 08,336,384 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/29/2002 06:00 AM | 00,268,288 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
========== User's Winlogon Settings ==========
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DllName" = C:\WINDOWS\system32\ati2evxx.dll [10/06/2004 10:09 PM | 00,090,112 | ---- | M] (ATI Technologies Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
"DllName" = C:\WINDOWS\system32\igfxdev.dll [07/19/2005 06:05 PM | 00,135,168 | ---- | M] (Intel Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
"DllName" = C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [05/31/2005 10:46 PM | 00,110,592 | ---- | M] (Intel Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
"DllName" = C:\WINDOWS\system32\NavLogon.dll [09/27/2006 09:33 PM | 00,043,760 | ---- | M] (Symantec Corporation)
========== Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
Unable to open key or key not present!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
"DisableCAD" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"NoDispBackgroundPage" = 0
"NoDispScrSavPage" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-21-12604286-1649964785-1244796221-24336\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-21-12604286-1649964785-1244796221-24336\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"NoDispBackgroundPage" = 0
"NoDispScrSavPage" = 0
========== Lsa Authentication Packages ==========
========== Lsa Security Packages ==========
========== Desktop Components ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
========== Safeboot Options ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
========== Disabled MsConfig Items ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
"system.ini" = 0
"win.ini" = 0
"bootini" = 0
"services" = 0
"startup" = 0
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT [ | PATH %path%;C:\PROGRAM FILES\SWIFT | ]
[08/07/2006 03:48 PM | 00,000,038 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{00a7a1f3-7681-11db-b4ef-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0bf36a7e-1db9-11db-b4d1-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d369b95-8a98-11db-b4f8-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ef87f45-8a37-11db-b4f7-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{28be54c9-3e60-11db-b4e1-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{47f9c186-f446-11db-aa0d-0010c69e9ed7}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6d7c0417-cfee-11db-b530-0010c69e9ed7}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6d7c041a-cfee-11db-b530-0010c69e9ed7}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6db50987-6e8d-11db-b4eb-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{72d762c8-05ee-11db-b4c6-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{80540ca8-b55b-11db-b514-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{807ce0c4-015b-11dc-aa10-0010c69e9ed7}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8d8f9352-e662-11da-b4af-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2059bf9-2b90-11db-b4d4-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b92412b5-8eae-11db-b4fa-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0a3ded2-db8d-11da-b4a8-00123ffabcb0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d22a2055-521e-11db-b4e2-0013ce073db0}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3730eb6-9cd2-11da-b499-0010c69e9ed7}\Shell]
"" = None
========== DNS Name Servers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{A40F97F5-979D-40BD-9F6A-A1766A1A0AE4}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{AC3C26A4-36A1-49D4-828A-50CEF1DA8269}]
Servers: | Description: Broadcom NetXtreme 57xx Gigabit Controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{AC91D8CB-44C8-4391-9F66-9676F83CE04E}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{B0C08F2B-F46F-467A-9C81-CDE4F5ED70E4}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{EF068FF2-5910-4578-BB27-1A2E6F29AD97}]
Servers: | Description: Intel® PRO/Wireless 2200BG Network Connection
========== Hosts File ==========
HOSTS File = (260782 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.1001-search.info
127.0.0.1 1001-search.info
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
127.0.0.1 www.136136.net
127.0.0.1 136136.net
========== Files/Folders - Created Within 90 days ==========
[08/27/2008 09:22 AM | ---D | C] - C:\VundoFix Backups
[09/01/2008 11:20 AM | ---D | C] - C:\rsit
[08/21/2008 01:28 PM | 00,007,369 | ---- | C] () - C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[08/21/2008 01:28 PM | 00,007,382 | ---- | C] () - C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[08/21/2008 01:28 PM | 00,008,574 | ---- | C] () - C:\WINDOWS\System32\dllcache\IASNT4.CAT
[08/21/2008 01:28 PM | 00,010,881 | ---- | C] () - C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[08/21/2008 01:28 PM | 00,013,608 | ---- | C] () - C:\WINDOWS\System32\dllcache\IMS.CAT
[08/21/2008 01:28 PM | 00,014,031 | ---- | C] () - C:\WINDOWS\System32\dllcache\MSJDBC.CAT
[08/21/2008 01:28 PM | 00,021,281 | ---- | C] () - C:\WINDOWS\System32\dllcache\XMLDSOC.CAT
[08/21/2008 01:28 PM | 00,022,151 | ---- | C] () - C:\WINDOWS\System32\dllcache\TCLASSES.CAT
[08/21/2008 01:28 PM | 00,022,399 | ---- | C] () - C:\WINDOWS\System32\dllcache\mediactr.cat
[08/21/2008 01:28 PM | 00,031,405 | ---- | C] () - C:\WINDOWS\System32\dllcache\FP4.CAT
[08/21/2008 01:28 PM | 00,037,484 | ---- | C] () - C:\WINDOWS\System32\dllcache\MW770.CAT
[08/21/2008 01:28 PM | 00,052,311 | ---- | C] () - C:\WINDOWS\System32\dllcache\DX3.CAT
[08/21/2008 01:28 PM | 00,056,081 | ---- | C] () - C:\WINDOWS\System32\dllcache\DAJAVAC.CAT
[08/21/2008 01:28 PM | 00,093,044 | ---- | C] () - C:\WINDOWS\System32\dllcache\tabletpc.cat
[08/21/2008 01:28 PM | 00,390,168 | ---- | C] () - C:\WINDOWS\System32\dllcache\WFC.CAT
[08/21/2008 01:28 PM | 00,399,645 | ---- | C] () - C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[08/21/2008 01:28 PM | 00,451,856 | ---- | C] () - C:\WINDOWS\System32\dllcache\NT5INF.CAT
[08/21/2008 01:28 PM | 00,657,548 | ---- | C] () - C:\WINDOWS\System32\dllcache\CLASSES.CAT
[08/21/2008 01:28 PM | 00,797,189 | ---- | C] () - C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[08/21/2008 01:28 PM | 01,086,182 | ---- | C] () - C:\WINDOWS\System32\dllcache\NTPRINT.CAT
[08/21/2008 01:28 PM | 02,049,999 | ---- | C] () - C:\WINDOWS\System32\dllcache\NT5.CAT
[08/21/2008 01:29 PM | 00,024,661 | ---- | C] (Perle Systems Ltd.) - C:\WINDOWS\System32\dllcache\spxcoins.dll
[08/21/2008 01:39 PM | 00,272,896 | ---- | C] (Cinematronics) - C:\WINDOWS\System32\dllcache\pinball.exe
[08/21/2008 01:41 PM | 00,004,639 | ---- | C] () - C:\WINDOWS\System32\dllcache\mplayer2.exe
[08/21/2008 01:42 PM | 00,028,672 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\isrdbg32.dll
[08/21/2008 01:42 PM | 00,348,160 | ---- | C] () - C:\WINDOWS\System32\dllcache\msinfo.dll
[08/21/2008 01:46 PM | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esucmd.dll
[08/21/2008 01:46 PM | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esunid.dll
[08/21/2008 01:46 PM | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) - C:\WINDOWS\System32\dllcache\cap7146.sys
[08/21/2008 01:46 PM | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esuimgd.dll
[08/21/2008 01:46 PM | 00,094,208 | ---- | C] () - C:\WINDOWS\System32\dllcache\fpencode.dll
[08/21/2008 01:46 PM | 00,173,568 | ---- | C] () - C:\WINDOWS\System32\dllcache\chtskf.dll
[08/21/2008 01:47 PM | 00,059,392 | ---- | C] () - C:\WINDOWS\System32\dllcache\imscinst.exe
[08/21/2008 01:47 PM | 00,108,827 | ---- | C] () - C:\WINDOWS\System32\dllcache\hanja.lex
[08/21/2008 01:47 PM | 00,134,339 | ---- | C] () - C:\WINDOWS\System32\dllcache\imekr.lex
[08/21/2008 01:47 PM | 00,196,666 | ---- | C] () - C:\WINDOWS\System32\dllcache\imjpinst.exe
[08/21/2008 01:47 PM | 01,158,818 | ---- | C] () - C:\WINDOWS\System32\dllcache\korwbrkr.lex
[08/21/2008 01:47 PM | 13,463,552 | ---- | C] () - C:\WINDOWS\System32\dllcache\hwxjpn.dll
[08/21/2008 01:48 PM | 00,026,624 | ---- | C] (Ricoh Co., Ltd.) - C:\WINDOWS\System32\dllcache\rw330ext.dll
[08/21/2008 01:48 PM | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) - C:\WINDOWS\System32\dllcache\rwia001.dll
[08/21/2008 01:48 PM | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) - C:\WINDOWS\System32\dllcache\rwia330.dll
[08/21/2008 01:48 PM | 00,175,104 | ---- | C] () - C:\WINDOWS\System32\dllcache\pintlcsa.dll
[6 C:\WINDOWS\System32\*.tmp files]
[08/19/2008 12:08 PM | 00,010,752 | ---- | C] ( ) - C:\WINDOWS\System32\md5.dll
[08/19/2008 12:08 PM | 00,011,012 | ---- | C] () - C:\WINDOWS\System32\threadapi.tlb
[08/19/2008 12:08 PM | 00,089,088 | ---- | C] (Ariad Software) - C:\WINDOWS\System32\ProgressBar4.ocx
[08/19/2008 12:08 PM | 00,265,753 | ---- | C] (Ariad Software) - C:\WINDOWS\System32\AS-Exp2.ocx
[08/19/2008 12:08 PM | 00,423,784 | ---- | C] (Xceed Software Inc (450) 442-2626
[email protected] www.xceedsoft.com) - C:\WINDOWS\System32\XceedBkp.dll
[08/19/2008 12:08 PM | 01,140,472 | ---- | C] (Infragistics, Inc.) - C:\WINDOWS\System32\IGUltraGrid20.ocx
[08/19/2008 12:08 PM | 02,267,368 | ---- | C] (Adobe Systems, Inc.) - C:\WINDOWS\System32\Flash.ocx
[08/21/2008 01:29 PM | 00,024,661 | ---- | C] (Perle Systems Ltd.) - C:\WINDOWS\System32\spxcoins.dll
[08/21/2008 01:42 PM | 00,028,672 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\isrdbg32.dll
[08/21/2008 01:44 PM | 00,025,065 | ---- | C] () - C:\WINDOWS\System32\wmpscheme.xml
[08/21/2008 01:58 PM | 00,135,168 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\igfxres.dll
[08/24/2008 11:58 AM | 00,000,001 | ---- | C] () - C:\WINDOWS\System32\mp7arc.dat
[08/27/2008 05:56 PM | ---D | C] - C:\WINDOWS\System32\bits
[08/29/2008 10:57 AM | 00,176,235 | ---- | C] () - C:\WINDOWS\System32\Primomonnt.dll
[6 C:\WINDOWS\*.tmp files]
[06/03/2008 10:32 PM | 01,558,280 | ---- | C] (XMLAuthor Inc.) - C:\WINDOWS\screengenie.scr
[08/21/2008 01:42 PM | 00,000,749 | RH-- | C] () - C:\WINDOWS\WindowsShell.Manifest
[08/21/2008 01:44 PM | 00,299,552 | ---- | C] () - C:\WINDOWS\WMSysPrx.prx
[08/21/2008 01:54 PM | ---D | C] - C:\WINDOWS\Prefetch
[08/21/2008 12:23 AM | 00,000,245 | ---- | C] () - C:\WINDOWS\tmp7404078.bat
[08/27/2008 03:48 PM | ---D | C] - C:\WINDOWS\ERDNT
[08/29/2008 10:57 AM | ---D | C] - C:\WINDOWS\PrimoPDF4
[08/18/2008 08:29 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\WLInstaller
[08/21/2008 12:03 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[08/27/2008 03:50 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[08/27/2008 03:50 PM | ---D | C] - C:\Documents and Settings\blogan\Application Data\Malwarebytes
[08/26/2008 02:35 PM | ---D | C] - C:\Documents and Settings\blogan\Local Settings\Application Data\Downloaded Installations
[06/03/2008 10:47 PM | 00,003,456 | ---- | C] () - C:\Documents and Settings\blogan\My Documents\Fly I.aup
[06/03/2008 10:47 PM | ---D | C] - C:\Documents and Settings\blogan\My Documents\Fly I_data
[06/03/2008 10:52 PM | 00,002,399 | ---- | C] () - C:\Documents and Settings\blogan\My Documents\Fly II.aup
[06/03/2008 10:52 PM | ---D | C] - C:\Documents and Settings\blogan\My Documents\Fly II_data
[08/26/2008 02:35 PM | 00,927,744 | ---- | C] () - C:\Documents and Settings\blogan\My Documents\2008 FFL DRAFT.doc
[08/26/2008 03:53 PM | 00,182,272 | ---- | C] () - C:\Documents and Settings\blogan\My Documents\TOP 100 Fantasy Football Cheat Sheet Key.doc
[08/18/2008 08:33 AM | 00,001,827 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Windows Live Messenger .lnk
[08/24/2008 11:27 AM | 00,000,899 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk
[08/25/2008 02:50 PM | 00,000,793 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[08/25/2008 02:50 PM | 00,000,793 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Ad-Watch.lnk
[08/26/2008 02:36 PM | 00,001,940 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Draft Analyzer.lnk
[08/27/2008 03:50 PM | 00,000,696 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[06/03/2008 10:29 PM | 12,569,040 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\cinemaforge.exe
[06/03/2008 10:33 PM | 00,001,597 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\CinemaForge App.lnk
[06/03/2008 10:38 PM | 00,000,630 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\Audacity.lnk
[06/03/2008 10:38 PM | 02,228,534 | ---- | C] ( ) - C:\Documents and Settings\blogan\Desktop\audacity-win-1.2.6.exe
[06/03/2008 10:52 PM | 11,628,588 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\Fly II.wav
[06/03/2008 11:00 PM | 19,586,092 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\Fly I.wav
[08/19/2008 12:08 PM | 00,000,805 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\No Adware No Spyware.lnk
[08/26/2008 01:49 PM | 15,083,520 | ---- | C] (Safer Networking Limited ) - C:\Documents and Settings\blogan\Desktop\spybotsd160.exe
[08/26/2008 01:53 PM | 03,195,984 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\spybotsd_includes.exe
[08/26/2008 01:58 PM | 00,000,933 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\Spybot - Search & Destroy.lnk
[08/26/2008 10:23 AM | 00,001,869 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\rgfix25439.reg
[08/27/2008 01:40 PM | 00,001,734 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\HijackThis.lnk
[08/27/2008 03:45 PM | 00,791,393 | ---- | C] (Lars Hederer ) - C:\Documents and Settings\blogan\Desktop\erunt_setup.exe
[08/27/2008 03:46 PM | 00,000,592 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\ERUNT.lnk
[08/27/2008 03:46 PM | 00,000,611 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\NTREGOPT.lnk
[08/27/2008 03:49 PM | 00,128,368 | ---- | C] (Digital River) - C:\Documents and Settings\blogan\Desktop\Download_mbam-setup.exe
[08/27/2008 09:38 AM | 00,096,978 | ---- | C] (Business Information Solutions) - C:\Documents and Settings\blogan\Desktop\Burn CDs & DVDs with RecordNow! Plus.lnk
[08/29/2008 10:54 AM | 11,121,848 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\FreewarePrimoSetup.exe
[08/29/2008 11:00 AM | 00,353,112 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\Ballantyne Elementary Annual Ca[1].pdf
[09/01/2008 11:19 AM | 00,025,088 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\Malwarebytes LOG.doc
[09/01/2008 11:19 AM | 00,304,189 | ---- | C] () - C:\Documents and Settings\blogan\Desktop\RSIT.exe
[08/20/2008 10:18 PM | 00,001,730 | ---- | C] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[08/18/2008 08:30 AM | -HSD | C] - C:\Program Files\Common Files\WindowsLiveInstaller
[08/25/2008 02:48 PM | ---D | C] - C:\Program Files\Common Files\Wise Installation Wizard
[08/27/2008 03:49 PM | ---D | C] - C:\Program Files\Common Files\Download Manager
[06/03/2008 10:33 PM | ---D | C] - C:\Program Files\CinemaForge
[06/03/2008 10:38 PM | ---D | C] - C:\Program Files\Audacity
[08/18/2008 08:29 AM | ---D | C] - C:\Program Files\Windows Live
[08/19/2008 12:08 PM | ---D | C] - C:\Program Files\NoAdware.com
[08/20/2008 10:18 AM | ---D | C] - C:\Program Files\Enigma Software Group
[08/21/2008 12:03 AM | ---D | C] - C:\Program Files\Spybot - Search & Destroy
[08/26/2008 02:35 PM | ---D | C] - C:\Program Files\Draft Analyzer
[08/27/2008 01:40 PM | ---D | C] - C:\Program Files\Trend Micro
[08/27/2008 03:46 PM | ---D | C] - C:\Program Files\ERUNT
[08/27/2008 03:50 PM | ---D | C] - C:\Program Files\Malwarebytes' Anti-Malware
[08/29/2008 10:57 AM | ---D | C] - C:\Program Files\activePDF
========== Files - Modified Within 90 days ==========
[08/21/2008 01:37 PM | 00,000,211 | -HS- | M] () - C:\boot.ini
[08/19/2008 12:17 PM | 00,000,732 | ---- | M] () - C:\WINDOWS\System32\drivers\etc\hosts.20080821-000815.backup
[08/21/2008 12:08 AM | 00,260,782 | R--- | M] () - C:\WINDOWS\System32\drivers\etc\hosts
[6 C:\WINDOWS\System32\*.tmp files]
[08/21/2008 01:40 PM | 00,023,348 | ---- | M] () - C:\WINDOWS\System32\emptyregdb.dat
[08/21/2008 01:44 PM | 00,025,065 | ---- | M] () - C:\WINDOWS\System32\wmpscheme.xml
[08/21/2008 01:50 PM | 00,000,288 | ---- | M] () - C:\WINDOWS\System32\$winnt$.inf
[08/21/2008 01:52 PM | 00,157,736 | ---- | M] () - C:\WINDOWS\System32\FNTCACHE.DAT
[08/21/2008 01:56 PM | 00,063,386 | ---- | M] () - C:\WINDOWS\System32\perfc009.dat
[08/21/2008 01:56 PM | 00,404,206 | ---- | M] () - C:\WINDOWS\System32\perfh009.dat
[08/21/2008 01:56 PM | 00,475,330 | ---- | M] () - C:\WINDOWS\System32\PerfStringBackup.INI
[08/24/2008 04:23 PM | 00,016,832 | ---- | M] () - C:\WINDOWS\System32\amcompat.tlb
[08/24/2008 04:23 PM | 00,023,392 | ---- | M] () - C:\WINDOWS\System32\nscompat.tlb
[08/24/2008 11:58 AM | 00,000,001 | ---- | M] () - C:\WINDOWS\System32\mp7arc.dat
[09/01/2008 06:03 PM | 00,002,228 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[6 C:\WINDOWS\*.tmp files]
[08/18/2008 03:22 PM | 00,640,960 | ---- | M] () - C:\WINDOWS\setupapi.old
[08/21/2008 01:29 PM | 00,000,275 | ---- | M] () - C:\WINDOWS\system.ini
[08/21/2008 01:42 PM | 00,000,749 | RH-- | M] () - C:\WINDOWS\WindowsShell.Manifest
[08/21/2008 01:44 PM | 00,004,161 | ---- | M] () - C:\WINDOWS\ODBCINST.INI
[08/21/2008 01:44 PM | 00,299,552 | ---- | M] () - C:\WINDOWS\WMSysPrx.prx
[08/21/2008 01:45 PM | 00,000,768 | ---- | M] () - C:\WINDOWS\win.ini
[08/21/2008 01:51 PM | 00,004,382 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08/21/2008 12:23 AM | 00,000,245 | ---- | M] () - C:\WINDOWS\tmp7404078.bat
[08/24/2008 04:21 PM | 00,316,640 | ---- | M] () - C:\WINDOWS\WMSysPr9.prx
[08/29/2008 10:57 AM | 00,000,310 | ---- | M] () - C:\WINDOWS\primopdf.ini
[09/01/2008 05:17 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08/26/2008 11:37 AM | 00,000,284 | ---- | M] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[09/01/2008 05:19 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[09/01/2008 05:39 PM | 00,000,330 | -H-- | M] () - C:\WINDOWS\tasks\MP Scheduled Scan.job
[08/21/2008 01:28 PM | 00,000,062 | -HS- | M] () - C:\Documents and Settings\All Users\Application Data\desktop.ini
[08/21/2008 01:57 PM | 00,022,368 | ---- | M] () - C:\Documents and Settings\blogan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[08/26/2008 10:39 AM | 03,770,706 | -H-- | M] () - C:\Documents and Settings\blogan\Local Settings\Application Data\IconCache.db
[08/21/2008 01:28 PM | 00,000,062 | -HS- | M] () - C:\Documents and Settings\All Users\Documents\desktop.ini
[06/03/2008 10:47 PM | 00,003,456 | ---- | M] () - C:\Documents and Settings\blogan\My Documents\Fly I.aup
[06/03/2008 10:52 PM | 00,002,399 | ---- | M] () - C:\Documents and Settings\blogan\My Documents\Fly II.aup
[08/26/2008 02:35 PM | 00,927,744 | ---- | M] () - C:\Documents and Settings\blogan\My Documents\2008 FFL DRAFT.doc
[08/26/2008 03:53 PM | 00,182,272 | ---- | M] () - C:\Documents and Settings\blogan\My Documents\TOP 100 Fantasy Football Cheat Sheet Key.doc
[08/19/2008 11:38 AM | 00,002,341 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[08/19/2008 11:41 AM | 00,001,604 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[08/24/2008 11:27 AM | 00,000,899 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk
[08/25/2008 02:50 PM | 00,000,793 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[08/25/2008 02:50 PM | 00,000,793 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Ad-Watch.lnk
[08/26/2008 02:36 PM | 00,001,940 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Draft Analyzer.lnk
[08/27/2008 06:36 PM | 00,001,827 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Windows Live Messenger .lnk
[09/01/2008 10:24 AM | 00,000,696 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[06/03/2008 10:29 PM | 12,569,040 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\cinemaforge.exe
[06/03/2008 10:34 PM | 00,001,597 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\CinemaForge App.lnk
[06/03/2008 10:38 PM | 00,000,630 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\Audacity.lnk
[06/03/2008 10:38 PM | 02,228,534 | ---- | M] ( ) - C:\Documents and Settings\blogan\Desktop\audacity-win-1.2.6.exe
[06/03/2008 10:53 PM | 11,628,588 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\Fly II.wav
[06/03/2008 11:00 PM | 19,586,092 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\Fly I.wav
[08/19/2008 12:08 PM | 00,000,805 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\No Adware No Spyware.lnk
[08/26/2008 01:49 PM | 15,083,520 | ---- | M] (Safer Networking Limited ) - C:\Documents and Settings\blogan\Desktop\spybotsd160.exe
[08/26/2008 01:53 PM | 03,195,984 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\spybotsd_includes.exe
[08/26/2008 01:58 PM | 00,000,933 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\Spybot - Search & Destroy.lnk
[08/26/2008 10:22 AM | 00,001,869 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\rgfix25439.reg
[08/27/2008 01:40 PM | 00,001,734 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\HijackThis.lnk
[08/27/2008 03:45 PM | 00,791,393 | ---- | M] (Lars Hederer ) - C:\Documents and Settings\blogan\Desktop\erunt_setup.exe
[08/27/2008 03:46 PM | 00,000,592 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\ERUNT.lnk
[08/27/2008 03:46 PM | 00,000,611 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\NTREGOPT.lnk
[08/27/2008 03:49 PM | 00,128,368 | ---- | M] (Digital River) - C:\Documents and Settings\blogan\Desktop\Download_mbam-setup.exe
[08/27/2008 09:38 AM | 00,096,978 | ---- | M] (Business Information Solutions) - C:\Documents and Settings\blogan\Desktop\Burn CDs & DVDs with RecordNow! Plus.lnk
[08/29/2008 10:54 AM | 11,121,848 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\FreewarePrimoSetup.exe
[08/29/2008 11:00 AM | 00,353,112 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\Ballantyne Elementary Annual Ca[1].pdf
[09/01/2008 11:19 AM | 00,025,088 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\Malwarebytes LOG.doc
[09/01/2008 11:19 AM | 00,304,189 | ---- | M] () - C:\Documents and Settings\blogan\Desktop\RSIT.exe
[08/21/2008 01:44 PM | 00,000,084 | -HS- | M] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
< End of report >