OTListIt logfile created on: 7/05/2009 6:15:58 a.m. - Run 1
OTListIt2 by OldTimer - Version 2.0.15.3 Folder = C:\Documents and Settings\Owner\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00001409 | Country: New Zealand | Language: ENZ | Date Format: d/MM/yyyy
502.42 Mb Total Physical Memory | 22.75 Mb Available Physical Memory | 4.53% Memory free
1.20 Gb Paging File | 0.56 Gb Available in Paging File | 46.45% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 34.09 Gb Free Space | 60.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-7048B5969
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\VerbAce Research\VerbAce-Pro\VerbAce-Pro.exe (VerbAce Research)
PRC - C:\Program Files\BandwidthMeter\BandwidthMeter.exe (Senh Liu)
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe (Logitech Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\WISPTIS.EXE (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\My Documents\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (btwdins [Disabled | Stopped]) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmi [Disabled | Stopped]) -- C:\Program Files\HPQ\SHARED\HPQWMI.exe (Hewlett-Packard Development Company, L.P.)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LVPrcSrv [Auto | Running]) -- c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVSrvLauncher [Auto | Stopped]) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (Nero BackItUp Scheduler 4.0 [Auto | Stopped]) -- File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Disabled | Stopped]) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SharedAccessNetDDE [Auto | Stopped]) -- File not found
SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Disabled | Stopped]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WLSetupSvc [Disabled | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (YahooAUService [Auto | Running]) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ========== DRV - (Aavmker4 [System | Running]) -- C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (aswFsBlk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (btaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CAMCAUD [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (CAMCHALA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CnxEtP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\CnxEtP.sys (Conexant Systems, Inc.)
DRV - (CnxEtU [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\CnxEtU.sys (Conexant Systems, Inc.)
DRV - (CnxTgNP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\CnxTgNP.sys (Conexant Systems, Inc.)
DRV - (CnxTgNW [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\CnxTgNW.sys (Conexant Systems, Inc.)
DRV - (eabfiltr [System | Running]) -- C:\WINDOWS\system32\drivers\EABFiltr.sys (Hewlett-Packard Company)
DRV - (eabusb [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\eabusb.sys (Hewlett-Packard Company)
DRV - (HPZid412 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (LVcKap [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys ()
DRV - (LVMVDrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (nmwcd [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\OVCD.sys (Microsoft Corporation)
DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (w29n51 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\w29n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.c...rch/search.htmlIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo....e...-8&fr=b1ie7IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/16 16:07:55 | 00,000,000 | ---D | M]
O1 HOSTS File: (0 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart (Google)
O4 - HKLM..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" (Yahoo! Inc)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VerbAce-Pro Startup Agent.lnk = C:\Program Files\VerbAce Research\VerbAce-Pro\VerbAce-Pro.exe (VerbAce Research)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Bandwidth Meter.lnk = C:\Program Files\BandwidthMeter\BandwidthMeter.exe (Senh Liu)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: ImTranslator - C:\PROGRA~1\SMARTL~1\IMTRAN~1\startup.html ()
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.micros...ntent/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://www4.snapfish...fishActivia.cab (Snapfish Activia)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1233384622468 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6}
http://fdl.msn.com/p...t/msnchat45.cab (MSN Chat Control 4.5)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\System32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/22 08:21:31 | 00,000,100 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{4d14687c-0724-11de-9d1d-00064f239f9f}\Shell\AutoRun\command - "" = D:\System\DriveGuard\DriveProtect.exe -- File not found
O33 - MountPoints2\{4d14687c-0724-11de-9d1d-00064f239f9f}\Shell\Explore\Command - "" = D:\System\DriveGuard\DriveProtect.exe -- File not found
O33 - MountPoints2\{4d14687c-0724-11de-9d1d-00064f239f9f}\Shell\Open\Command - "" = D:\System\DriveGuard\DriveProtect.exe -- File not found
O33 - MountPoints2\{4e7a8ac8-01ec-11db-9aca-806d6172696f}\Shell\play\command - "" = C:\Program Files\InterVideo\WinDVD\WinDVD.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ========== [17 C:\WINDOWS\System32\*.tmp files]
[4 C:\Documents and Settings\Owner\Desktop\*.tmp files]
[2009/05/07 06:14:51 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\My Documents\OTListIt2.exe
[2009/05/06 22:32:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\portal
[2009/05/06 03:09:56 | 00,000,682 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Orkut Cute.lnk
[2009/05/06 03:09:56 | 00,000,677 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Mudanças Orkut Cute.lnk
[2009/05/06 03:09:53 | 00,000,000 | ---D | C] -- C:\Program Files\Orkut Cute 9.4.42
[2009/05/06 02:58:08 | 01,040,384 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\libeay32.dll
[2009/05/06 02:58:08 | 00,196,608 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\System32\ssleay32.dll
[2009/05/06 02:58:08 | 00,196,608 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\ssleay32.dll
[2009/05/06 02:58:07 | 01,040,384 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\System32\libeay32.dll
[2009/05/06 02:56:47 | 05,241,116 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\OrkutCute_setup.zip
[2009/05/04 19:36:23 | 00,015,151 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Tera Mera Ki Rishta 2009 ~ Pdvd Rip ~Team IcTV.torrent
[2009/05/04 18:49:18 | 00,022,016 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\KITCHEN STAFF.xls
[2009/05/02 22:55:05 | 00,109,884 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\leave rules.pdf
[2009/05/01 21:10:29 | 00,820,866 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\FINAL_Mar_2009_GAM_CAE_Roundtable_Report.pdf
[2009/05/01 15:58:38 | 00,014,288 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\[EXD] Meri_Padosan_1CD_PDVD_RIP_DUS_monstorlove.torrent
[2009/05/01 15:23:49 | 00,981,618 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\1.bmp
[2009/04/30 13:06:41 | 02,577,778 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Buddy_Pad.pdf
[2009/04/30 01:00:58 | 00,018,630 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\VisaCard-Gold_Stmt_3004091044.xls
[2009/04/29 23:37:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\cv
[2009/04/29 16:24:24 | 00,002,244 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2009/04/29 16:18:35 | 00,000,926 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-562591055-839522115-1003.job
[2009/04/28 17:41:41 | 00,028,672 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\CAMBRO(1).xls
[2009/04/28 09:35:54 | 00,485,972 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\chandan_ticket.JPG
[2009/04/28 09:31:23 | 05,458,432 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\chandan_ticket.doc
[2009/04/28 09:29:57 | 06,787,614 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\chandan_ticket.tif
[2009/04/28 00:36:31 | 38,145,536 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\IIA_test_-_Part_I.doc
[2009/04/27 15:34:42 | 14,906,536 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\06 Track 6.mp3
[2009/04/23 18:47:12 | 00,022,016 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\DAS.doc
[2009/04/22 19:43:26 | 00,406,463 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\dbrd.JPG
[2009/04/17 08:25:58 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/04/16 16:05:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/04/16 16:05:33 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/04/16 16:05:13 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/04/16 16:04:16 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2009/04/16 16:04:16 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/04/16 16:04:16 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/04/16 16:04:16 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll
[2009/04/16 16:04:16 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/04/16 16:04:16 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2009/04/16 16:04:16 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/04/16 16:04:15 | 00,000,000 | ---D | C] -- C:\b546075d49fa0a34d02c0f613114
[2009/04/16 15:46:32 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/16 15:46:31 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/16 15:46:31 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/16 15:46:31 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/16 15:46:31 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe
[2009/04/16 15:46:30 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/16 15:46:30 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/16 15:46:30 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/16 15:46:29 | 00,714,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/16 11:08:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Gleim
[2009/04/16 11:06:26 | 00,000,749 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Gleim's CPA Test Prep 2009.lnk
[2009/04/16 10:52:27 | 00,879,238 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Study Unit 18.pdf
[2009/04/16 10:52:01 | 00,235,092 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Study Unit 1.pdf
[2009/04/16 07:55:57 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp4res.dll
[2009/04/16 07:55:53 | 01,203,922 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/16 07:55:52 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/13 09:36:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\torrent7
[2009/04/11 12:39:05 | 03,530,064 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\The_Essential_Handbook_of_Internal_Auditing.pdf
[2009/04/08 23:14:35 | 00,000,812 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2009/04/08 23:14:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/03/12 19:32:55 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/03/12 19:32:48 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/03/12 19:32:48 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/03/12 19:32:47 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/03/12 19:32:44 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/03/12 19:32:44 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/02/24 18:56:21 | 00,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2009/02/24 18:56:14 | 00,000,032 | ---- | C] () -- C:\WINDOWS\Vocab.ini
[2009/02/09 12:11:20 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/02/06 11:25:43 | 00,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008/10/29 21:06:29 | 00,005,592 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2008/06/29 12:41:06 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfmonnt.dll
[2008/06/29 12:41:04 | 00,000,164 | ---- | C] () -- C:\WINDOWS\System32\psconv.ini
[2008/05/08 15:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\muveeapp.INI
[2008/03/25 02:25:38 | 00,000,233 | -H-- | C] () -- C:\WINDOWS\gvac.sys
[2006/12/22 12:32:48 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2006/12/22 12:30:42 | 01,683,232 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/07/16 03:36:34 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/07/09 06:27:10 | 00,000,045 | ---- | C] () -- C:\WINDOWS\Twacker.ini
[2006/07/09 06:27:09 | 00,000,045 | ---- | C] () -- C:\WINDOWS\lifeview.ini
[2006/06/22 07:27:03 | 00,015,669 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/12/23 04:28:28 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2004/08/04 17:30:00 | 00,000,742 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 17:30:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/01/07 08:35:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/13 11:31:26 | 00,014,385 | ---- | C] () -- C:\WINDOWS\TW561a.ini
[2002/05/15 15:59:04 | 00,000,607 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 10:48:00 | 00,000,597 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 06:26:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
========== Files - Modified Within 30 Days ========== [17 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[4 C:\Documents and Settings\Owner\Desktop\*.tmp files]
[2009/05/07 06:15:10 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\My Documents\OTListIt2.exe
[2009/05/07 04:59:57 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/07 04:59:42 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/07 04:59:37 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Local Settings\desktop.ini
[2009/05/07 04:59:34 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/07 04:59:33 | 52,689,7152 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/06 22:34:52 | 00,000,521 | ---- | M] () -- C:\hpfr3420.xml
[2009/05/06 21:32:17 | 00,018,944 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Copy of Expense_reimbursement_claim_format.xls
[2009/05/06 17:45:00 | 00,000,364 | ---- | M] () -- C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1214828046.job
[2009/05/06 17:24:35 | 00,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-562591055-839522115-1003.job
[2009/05/06 03:17:24 | 00,000,682 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Orkut Cute.lnk
[2009/05/06 03:17:24 | 00,000,677 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Mudanças Orkut Cute.lnk
[2009/05/06 03:17:14 | 05,241,116 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\OrkutCute_setup.zip
[2009/05/06 03:03:08 | 00,000,589 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ADSL Uninstall.LNK
[2009/05/06 03:03:06 | 00,000,583 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ADSL Wizard.LNK
[2009/05/06 02:58:08 | 01,040,384 | ---- | M] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\System32\libeay32.dll
[2009/05/06 02:58:08 | 01,040,384 | ---- | M] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\libeay32.dll
[2009/05/06 02:58:08 | 00,196,608 | ---- | M] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\System32\ssleay32.dll
[2009/05/06 02:58:08 | 00,196,608 | ---- | M] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\ssleay32.dll
[2009/05/05 02:09:23 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/04 19:36:36 | 00,015,151 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Tera Mera Ki Rishta 2009 ~ Pdvd Rip ~Team IcTV.torrent
[2009/05/04 18:57:59 | 00,022,016 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\KITCHEN STAFF.xls
[2009/05/03 23:57:43 | 00,028,160 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\gd.doc
[2009/05/03 00:04:05 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/05/02 22:55:05 | 00,109,884 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\leave rules.pdf
[2009/05/01 21:10:33 | 00,820,866 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\FINAL_Mar_2009_GAM_CAE_Roundtable_Report.pdf
[2009/05/01 19:52:51 | 00,001,024 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\pdfdoc2.dll
[2009/05/01 15:58:58 | 00,014,288 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\[EXD] Meri_Padosan_1CD_PDVD_RIP_DUS_monstorlove.torrent
[2009/05/01 15:24:30 | 00,981,618 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\1.bmp
[2009/05/01 00:48:36 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\staff list.xls
[2009/04/30 13:06:46 | 02,577,778 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Buddy_Pad.pdf
[2009/04/30 01:01:00 | 00,018,630 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\VisaCard-Gold_Stmt_3004091044.xls
[2009/04/29 16:24:24 | 00,002,244 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2009/04/29 16:00:13 | 00,028,672 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\CAMBRO(1).xls
[2009/04/28 09:35:55 | 00,485,972 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\chandan_ticket.JPG
[2009/04/28 09:31:25 | 05,458,432 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\chandan_ticket.doc
[2009/04/28 09:29:57 | 06,787,614 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\chandan_ticket.tif
[2009/04/28 09:23:53 | 00,059,904 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Research Assistant.doc
[2009/04/28 00:57:14 | 38,145,536 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\IIA_test_-_Part_I.doc
[2009/04/27 23:32:38 | 01,606,064 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\googletalk-setup.exe
[2009/04/27 15:45:15 | 14,906,536 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\06 Track 6.mp3
[2009/04/26 12:09:58 | 00,026,624 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\nikhil.doc
[2009/04/26 11:24:28 | 00,097,792 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\NIKHIL BAVEJA particulars.doc
[2009/04/24 21:41:22 | 00,000,589 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\My Sharing Folders.lnk
[2009/04/24 20:23:28 | 00,022,016 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\DAS.doc
[2009/04/24 12:05:08 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2009/04/24 12:05:08 | 00,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2009/04/24 12:01:40 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2009/04/24 12:01:40 | 00,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2009/04/22 19:43:26 | 00,406,463 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\dbrd.JPG
[2009/04/21 18:49:01 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/04/16 18:32:35 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2009/04/16 18:32:35 | 00,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2009/04/16 18:30:49 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2009/04/16 18:30:49 | 00,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2009/04/16 17:17:30 | 00,521,942 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/16 17:17:30 | 00,441,692 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/16 17:17:30 | 00,071,462 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/16 17:12:41 | 00,307,600 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/16 16:22:38 | 00,000,742 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/16 15:19:23 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/04/16 11:06:26 | 00,000,749 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Gleim's CPA Test Prep 2009.lnk
[2009/04/16 10:52:28 | 00,879,238 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Study Unit 18.pdf
[2009/04/16 10:52:01 | 00,235,092 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Study Unit 1.pdf
[2009/04/11 12:55:56 | 03,530,064 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\The_Essential_Handbook_of_Internal_Auditing.pdf
[2009/04/08 23:14:35 | 00,000,812 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
========== LOP Check ========== [2009/04/08 23:52:41 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2006/06/22 07:19:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2006/06/22 07:24:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/22 10:27:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2009/02/09 16:47:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/02/07 15:45:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gleim
[2008/05/07 01:37:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2006/06/22 07:48:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hpqwmi
[2006/06/22 07:42:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/01/15 17:02:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logitech
[2008/08/25 19:39:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/05 14:45:38 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/07/25 12:35:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2006/06/22 07:32:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/02/06 14:30:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nero
[2008/06/21 00:52:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/03/30 14:30:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2008/06/30 17:50:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/07/05 10:01:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/06/26 22:40:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/04/09 11:31:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/04/16 11:08:15 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Owner\Application Data
[2008/06/21 04:07:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Adobe
[2009/04/21 23:53:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\AdobeUM
[2006/06/22 07:24:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Apple Computer
[2009/03/22 15:19:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Azureus
[2009/05/06 21:02:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\BitTorrent
[2008/06/02 08:40:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\BitZipper
[2009/02/09 16:48:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DAEMON Tools
[2009/02/09 17:04:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DAEMON Tools Lite
[2009/02/09 16:48:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DAEMON Tools Pro
[2006/09/05 17:24:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Datalayer
[2009/05/07 06:19:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DNA
[2009/02/06 20:22:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Ectaco
[2008/07/09 01:47:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\FreeCall
[2009/04/16 11:08:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Gleim
[2009/02/18 02:39:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Help
[2009/03/08 21:45:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\HTML Executable
[2006/06/22 06:47:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Identities
[2006/06/30 07:59:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
[2006/07/08 11:24:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Lavasoft
[2006/09/05 17:25:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Leadertech
[2006/06/30 03:22:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Macromedia
[2008/08/25 19:39:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/03/12 19:34:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Media Player Classic
[2009/05/06 22:19:30 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Owner\Application Data\Microsoft
[2008/05/08 15:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\muvee Technologies
[2009/02/06 13:46:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Nero
[2008/05/07 02:02:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Nokia
[2006/09/05 17:08:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PC Suite
[2009/03/30 20:59:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Real
[2009/04/08 10:16:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Skype
[2008/12/17 14:56:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Snapfish
[2006/06/22 08:23:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Sonic
[2006/08/06 02:33:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Sun
[2009/03/08 16:13:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Uniblue
[2009/04/01 20:25:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\uTorrent
[2008/07/07 02:55:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\vlc
[2008/07/06 02:34:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\WinRAR
[2009/04/10 17:46:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Yahoo!
[2004/08/04 17:30:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/05/06 17:45:00 | 00,000,364 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1214828046.job
[2009/05/06 17:24:35 | 00,000,926 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-562591055-839522115-1003.job
[2009/05/05 02:09:23 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/05/07 04:59:42 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\My Documents\noname:SummaryInformation
< End of report >