OTListIt logfile created on: 5/11/2009 9:44:30 PM - Run 3OTListIt2 by OldTimer - Version 2.0.15.5 Folder = E:\Downloads & Transfers\DownloadsWindows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 6.0.2900.2180)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1023.48 Mb Total Physical Memory | 356.14 Mb Available Physical Memory | 34.80% Memory free2.40 Gb Paging File | 1.86 Gb Available in Paging File | 77.53% Paging File freePaging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 74.52 Gb Total Space | 47.21 Gb Free Space | 63.35% Space Free | Partition Type: NTFSD: Drive not present or media not loadedDrive E: | 596.17 Gb Total Space | 469.79 Gb Free Space | 78.80% Space Free | Partition Type: NTFSF: Drive not present or media not loadedG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loaded Computer Name: RAOLANCurrent User Name: RaolanLogged in as Administrator. Current Boot Mode: NormalScan Mode: Current userOutput = MinimalFile Age = 30 DaysCompany Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)PRC - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)PRC - C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe ()PRC - C:\WINDOWS\system32\WTClient.exe (Tablet Driver)PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)PRC - C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)PRC - C:\Documents and Settings\Raolan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)PRC - C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)PRC - C:\WINDOWS\System32\Drivers\WTSRV.EXE (Tablet Driver)PRC - C:\WINDOWS\system32\WISPTIS.EXE (Microsoft Corporation)PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)PRC - C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe (Sun Microsystems, Inc.)PRC - E:\Downloads & Transfers\Downloads\OTListIt2.exe (OldTimer Tools)PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (Adobe Version Cue CS4 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\system32\ati2sgag.exe ()SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)SRV - (GoogleDesktopManager-022208-143751 [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)SRV - (Macromedia Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)SRV - (npggsvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)SRV - (rpcapd [On_Demand | Stopped]) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)SRV - (WinTabService [Auto | Running]) -- C:\WINDOWS\System32\Drivers\WTSRV.EXE (Tablet Driver) ========== Driver Services (SafeList) ========== DRV - (adfs [Auto | Running]) -- C:\WINDOWS\System32\drivers\adfs.sys (Adobe Systems, Inc.)DRV - (AegisP [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)DRV - (AmdK8 [System | Running]) -- C:\WINDOWS\System32\DRIVERS\AmdK8.sys (Advanced Micro Devices)DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)DRV - (DgiVecp [Auto | Running]) -- C:\WINDOWS\system32\Drivers\DgiVecp.sys (Samsung Electronics Co., Ltd.)DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)DRV - (hamachi [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\hamachi.sys (LogMeIn, Inc.)DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)DRV - (MTsensor [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ASACPI.sys ()DRV - (nm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys (Microsoft Corporation)DRV - (NPF [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)DRV - (nvata [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\nvata.sys (NVIDIA Corporation)DRV - (NVENETFD [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)DRV - (nvnetbus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)DRV - (PTSimBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\PTSimBus.sys (PenTablet Driver)DRV - (PTSimHid [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\PTSimHid.sys (PenTablet Driver)DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)DRV - (RT61 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\RT61.sys (Ralink Technology Inc.)DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys ()DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS (Sony Corporation)DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()DRV - (Tablet2k [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\Tablet2k.sys (Windows ® Server 2003 DDK provider)DRV - (TClass2k [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\TClass2k.sys (Tablet Driver)DRV - (UCTblHid [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\UCTblHid.sys (Tablet Driver)DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"]http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome[/url]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://www.google.com/ie"]http://www.google.com/ie[/url]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [url="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"]http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch[/url]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"]http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home[/url]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = [url="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm[/url]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = [url="http://www.google.com/ie"]http://www.google.com/ie[/url]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.gaiaonline.com/"]http://www.gaiaonline.com/[/url]IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://www.google.com/ie"]http://www.google.com/ie[/url]IE - URLSearchHook: - Reg Error: Key error. File not foundIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "GoogleCOM"FF - prefs.js..browser.search.useDBForOrder: trueFF - prefs.js..browser.startup.homepage: ""FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.1.0.7FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.2FF - prefs.js..extensions.enabledItems: [email protected]:2.22bFF - prefs.js..extensions.enabledItems: [email protected]:1.3.3FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.11FF - prefs.js..extensions.enabledItems: [email protected]:6.0FF - prefs.js..extensions.enabledItems: {2e768a0b-9ee3-4e60-babc-9ff4bc4aacfb}:1.300.66FF - prefs.js..extensions.enabledItems: [email protected]:4.1.0.077FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07FF - prefs.js..extensions.enabledItems: {15756614-ffb8-498b-b961-bce537ea94fe}:0.4FF - prefs.js..extensions.enabledItems: [email protected]:1.0.3FF - prefs.js..extensions.enabledItems: {75CEEE46-9B64-46f8-94BF-54012DE155F0}:0.3.8FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0FF - prefs.js..extensions.enabledItems: {F645A8C9-E969-42D9-B3F3-F325537222FD}:1.1.4FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.1FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.94FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:0.5.9FF - prefs.js..extensions.enabledItems: {75623d5d-4683-402a-b610-ac4bab767c86}:2.0.3FF - prefs.js..extensions.enabledItems: {0df7b3bb-9581-44bb-835f-061a29ec8a46}:2.1.20090406FF - prefs.js..extensions.enabledItems: [email protected]:1.2.4FF - prefs.js..extensions.enabledItems: {0fa2149e-bb2c-4ac2-a8d3-479599819475}:1.5FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10FF - prefs.js..extensions.enabledItems: {6542b200-4374-11dd-ae16-0800200c9a66}:2.0b2FF - prefs.js..extensions.enabledItems: [email protected]:2.028FF - prefs.js..keyword.URL: "http://www.google-searchbar.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=" FF - user.js..browser.search.selectedEngine: "GoogleCOM"FF - user.js..keyword.URL: "http://www.google-searchbar.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=" FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/05 09:15:24 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/05/05 09:15:24 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/01/08 07:11:54 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2009/03/29 17:19:27 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/05 10:42:44 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/05 10:42:44 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS [2009/04/04 14:48:35 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS [2009/04/03 18:38:02 | 00,000,000 | ---D | M] [2008/10/08 16:40:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Extensions[2008/10/08 16:40:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}[2009/05/11 21:33:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions[2009/03/09 17:00:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}[2009/04/08 07:07:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{0df7b3bb-9581-44bb-835f-061a29ec8a46}[2008/11/22 23:10:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{0fa2149e-bb2c-4ac2-a8d3-479599819475}[2009/04/05 06:01:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}[2008/12/01 17:23:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{15756614-ffb8-498b-b961-bce537ea94fe}[2008/10/22 21:38:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{2e768a0b-9ee3-4e60-babc-9ff4bc4aacfb}[2009/04/15 09:34:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}[2009/04/07 18:04:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{6542b200-4374-11dd-ae16-0800200c9a66}[2009/02/20 07:57:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}[2009/04/05 06:01:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}[2008/10/09 09:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}[2008/10/08 18:22:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}[2009/02/20 07:57:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}[2009/04/05 06:01:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}[2008/10/09 09:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\{F645A8C9-E969-42D9-B3F3-F325537222FD}[2009/02/20 07:57:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2009/03/09 17:00:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2008/10/23 21:08:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2009/04/07 17:42:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2008/10/09 09:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2008/11/22 23:10:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2008/10/08 17:08:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\mozilla\Firefox\Profiles\ab58v0xl.default\extensions\[email protected][2008/10/09 20:48:28 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\Raolan\Application Data\Mozilla\FireFox\Profiles\ab58v0xl.default\searchplugins\daemon-search.xml[2009/03/09 17:01:49 | 00,001,898 | ---- | M] () -- C:\Documents and Settings\Raolan\Application Data\Mozilla\FireFox\Profiles\ab58v0xl.default\searchplugins\surf-canyon.xml[2009/05/11 21:33:13 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions[2009/05/05 10:42:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2008/10/08 11:36:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}[2008/10/08 21:16:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}[2009/05/05 10:42:35 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll[2009/05/05 10:42:35 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll[2008/09/25 11:21:16 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml[2008/09/25 11:21:16 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml[2008/09/25 11:21:16 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml[2008/11/16 14:13:18 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml[2009/01/21 20:58:26 | 00,001,307 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google-com.xml[2008/09/25 11:21:16 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml[2008/09/25 11:21:16 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml[2008/09/25 11:21:16 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\HostsO1 - Hosts: 127.0.0.1 localhostO2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe [2009/04/03 19:25:11 | 00,000,000 | ---D | M]O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not foundO2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe [2009/04/03 19:25:11 | 00,000,000 | ---D | M]O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B3535C18-0E70-4D4B-B36B-BBFE139BB144} - Reg Error: Key error. File not foundO3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - Reg Error: Key error. File not foundO3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)O4 - HKLM..\Run: [] File not foundO4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" (Adobe Systems Incorporated)O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE (Adobe Systems Incorporated)O4 - HKLM..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin (Adobe Systems Incorporated)O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (ATI Technologies Inc.)O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)O4 - HKLM..\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe" (CyberLink Corp.)O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)O4 - HKLM..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe" (CyberLink Corp.)O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun ()O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)O4 - HKLM..\Run: [WTClient] WTClient.exe (Tablet Driver)O4 - HKCU..\Run: [amsn] C:\Program Files\aMSN\amsn.exe File not foundO4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKCU..\Run: [DLD.EXE] C:\Program Files\Download Direct\DLD.exe File not foundO4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Raolan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)O4 - HKCU..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" File not foundO4 - HKCU..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab"]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url] (Java Plug-in 1.6.0_07)O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab"]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url] (Java Plug-in 1.6.0_07)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab"]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url] (Java Plug-in 1.6.0_07)O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [url="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab"]http://download.macromedia.com/pub/shockwa...ash/swflash.cab[/url] (Shockwave Flash Object)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{C7BEC962-AA51-4B55-AE56-75FA7F1CAA5E}\\NameServer = 192.168.1.1O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)O24 - Desktop Components:0 (My Current Home Page) - About:HomeO27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)O31 - SafeBoot: AlternateShell - cmd.exeO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2009/04/05 10:03:16 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O33 - MountPoints2\{73fecbfa-944d-11dd-81f3-0015f2574cda}\Shell\AutoRun\command - "" = RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\restor.exeO33 - MountPoints2\{73fecbfa-944d-11dd-81f3-0015f2574cda}\Shell\open\command - "" = RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\restor.exeO34 - HKLM BootExecute: (autocheck) - File not foundO34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [2009/05/11 07:21:38 | 00,004,096 | -H-- | C] () -- C:\Documents and Settings\All Users\Documents\._8science_4assignment_periodictable.doc[2009/05/11 07:21:37 | 00,004,096 | -H-- | C] () -- C:\Documents and Settings\All Users\Documents\._assignment5_science.doc[2009/05/11 07:21:07 | 00,029,184 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\8science_4assignment_periodictable.doc[2009/05/11 07:20:53 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\assignment5_science.doc[2009/05/11 07:12:21 | 00,006,148 | -H-- | C] () -- C:\Documents and Settings\All Users\Documents\.DS_Store[2009/05/11 07:11:51 | 00,004,096 | -H-- | C] () -- C:\Documents and Settings\All Users\Documents\._assignment5_science.docx[2009/05/11 07:11:51 | 00,004,096 | -H-- | C] () -- C:\Documents and Settings\All Users\Documents\._8science_4assignment_periodictable.docx[2009/05/10 07:02:04 | 00,286,208 | ---- | C] () -- C:\micxs1bm.exe[2009/05/09 23:47:36 | 00,001,739 | ---- | C] () -- C:\Documents and Settings\Raolan\Desktop\HijackThis.lnk[2009/05/09 23:47:34 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro[2009/05/08 16:05:13 | 00,102,995 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\assignment5_science.docx[2009/05/08 15:46:31 | 00,002,211 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Pirates of the Caribbean Online's Desktop Galleon.lnk[2009/05/07 10:25:10 | 00,000,605 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Pirates of the Caribbean.lnk[2009/05/03 16:36:08 | 00,000,964 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Pirates of the Caribbean Online.lnk[2009/05/03 16:36:05 | 00,000,000 | ---D | C] -- C:\Program Files\Disney[2009/05/02 21:04:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games[2009/05/02 21:04:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Raolan\Desktop\Tradewinds 2[2009/05/02 21:04:00 | 92,003,866 | ---- | C] () -- C:\Documents and Settings\Raolan\Desktop\Tradewinds 2.zip[2009/04/29 13:12:01 | 00,098,294 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\8science_4assignment_periodictable.docx[2009/04/24 18:48:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Raolan\Desktop\USB Backup[2009/04/19 07:42:59 | 00,000,122 | ---- | C] () -- C:\WINDOWS\WA.INI[2009/04/19 07:42:23 | 00,000,814 | ---- | C] () -- C:\Documents and Settings\Raolan\Desktop\Worms Armageddon New Edition .lnk[2009/04/14 20:56:11 | 00,000,000 | ---D | C] -- C:\Program Files\Persona[2009/04/14 20:53:15 | 00,000,000 | ---D | C] -- C:\Program Files\FlashGet[2009/04/14 07:11:25 | 02,788,381 | ---- | C] (INCA Internet Co., Ltd.) -- C:\WINDOWS\System32\GameMon.des[2009/04/05 10:03:54 | 00,000,040 | ---- | C] () -- C:\WINDOWS\wininit.ini[2009/03/29 17:50:46 | 00,000,014 | ---- | C] () -- C:\WINDOWS\System32\Systemdrv.sys[2009/03/21 08:25:02 | 00,041,808 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll[2008/12/25 08:25:00 | 00,000,081 | ---- | C] () -- C:\WINDOWS\HUMANJAP.INI[2008/12/21 05:16:58 | 00,000,026 | ---- | C] () -- C:\WINDOWS\gale.ini[2008/12/14 13:24:38 | 00,000,325 | ---- | C] () -- C:\WINDOWS\BeatBox.INI[2008/12/14 13:24:37 | 00,000,028 | ---- | C] () -- C:\WINDOWS\Robota.INI[2008/12/14 13:22:21 | 00,000,273 | ---- | C] () -- C:\WINDOWS\musicmaker.INI[2008/12/14 13:13:33 | 00,000,024 | ---- | C] () -- C:\WINDOWS\magix.ini[2008/12/14 13:13:32 | 00,000,919 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini[2008/10/31 19:51:07 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI[2008/10/17 17:24:22 | 00,000,009 | ---- | C] () -- C:\WINDOWS\WINHELP.INI[2008/10/16 15:19:59 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll[2008/10/10 07:15:26 | 00,197,120 | ---- | C] () -- C:\WINDOWS\patchw32.dll[2008/10/09 20:19:30 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys[2008/10/09 20:07:12 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll[2008/10/09 10:41:53 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll[2008/10/08 16:31:45 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\Install6x.dll[2008/10/07 18:49:42 | 00,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI[2008/10/01 19:44:59 | 00,000,067 | ---- | C] () -- C:\WINDOWS\encore_launcher.ini[2008/10/01 19:39:34 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll[2008/10/01 19:28:45 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini[2008/10/01 19:28:43 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll[2008/10/01 19:23:36 | 00,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini[2008/10/01 19:23:33 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys[2008/10/01 19:23:28 | 00,005,700 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini[2008/10/01 19:23:25 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS[2007/04/25 05:31:12 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\ucinst32.dll[2005/08/03 07:24:01 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll[2003/01/07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI[2002/10/30 05:53:26 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\PcHook.DLL[2001/08/23 22:00:00 | 00,011,376 | R--- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys[2001/08/23 22:00:00 | 00,000,801 | ---- | C] () -- C:\WINDOWS\win.ini[2001/08/23 22:00:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI ========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files][3 C:\WINDOWS\*.tmp files][2009/05/11 21:30:24 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Raolan\Local Settings\desktop.ini[2009/05/11 21:30:24 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT[2009/05/11 21:30:20 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2009/05/11 12:42:12 | 00,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1220945662-682003330-1003.job[2009/05/11 12:30:29 | 35,961,689 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm[2009/05/11 12:30:29 | 00,052,945 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg[2009/05/11 07:21:38 | 00,004,096 | -H-- | M] () -- C:\Documents and Settings\All Users\Documents\._assignment5_science.doc[2009/05/11 07:21:38 | 00,004,096 | -H-- | M] () -- C:\Documents and Settings\All Users\Documents\._8science_4assignment_periodictable.doc[2009/05/11 07:21:07 | 00,029,184 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\8science_4assignment_periodictable.doc[2009/05/11 07:20:53 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\assignment5_science.doc[2009/05/11 07:12:21 | 00,006,148 | -H-- | M] () -- C:\Documents and Settings\All Users\Documents\.DS_Store[2009/05/11 07:11:52 | 00,004,096 | -H-- | M] () -- C:\Documents and Settings\All Users\Documents\._assignment5_science.docx[2009/05/11 07:11:52 | 00,004,096 | -H-- | M] () -- C:\Documents and Settings\All Users\Documents\._8science_4assignment_periodictable.docx[2009/05/10 19:49:11 | 00,102,995 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\assignment5_science.docx[2009/05/10 07:02:04 | 00,286,208 | ---- | M] () -- C:\micxs1bm.exe[2009/05/09 23:47:36 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\Raolan\Desktop\HijackThis.lnk[2009/05/08 15:46:31 | 00,002,211 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Pirates of the Caribbean Online's Desktop Galleon.lnk[2009/05/07 10:33:52 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2009/05/07 10:25:10 | 00,000,605 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Pirates of the Caribbean.lnk[2009/05/04 16:20:16 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll[2009/05/04 16:20:15 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys[2009/05/04 16:20:15 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys[2009/05/04 16:20:11 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys[2009/05/03 16:36:08 | 00,000,964 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Pirates of the Caribbean Online.lnk[2009/05/02 20:47:54 | 92,003,866 | ---- | M] () -- C:\Documents and Settings\Raolan\Desktop\Tradewinds 2.zip[2009/04/29 13:12:02 | 00,098,294 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\8science_4assignment_periodictable.docx[2009/04/28 13:37:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job[2009/04/21 15:08:22 | 00,000,801 | ---- | M] () -- C:\WINDOWS\win.ini[2009/04/20 18:07:24 | 00,000,122 | ---- | M] () -- C:\WINDOWS\WA.INI[2009/04/19 07:42:24 | 00,000,814 | ---- | M] () -- C:\Documents and Settings\Raolan\Desktop\Worms Armageddon New Edition .lnk[2009/04/18 08:45:49 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg[2009/04/13 14:49:33 | 00,013,312 | ---- | M] () -- C:\WINDOWS\System32\BASSMOD.dll ========== LOP Check ========== [2009/05/02 21:04:31 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data[2008/10/09 20:22:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}[2009/04/03 18:42:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe[2009/04/03 19:13:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ALM[2009/04/20 07:24:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL[2009/04/11 08:21:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL OCP[2008/10/09 20:21:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple[2008/10/09 20:22:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer[2009/02/08 07:01:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg8[2008/10/08 17:27:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus[2009/03/29 18:25:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink[2008/10/11 15:12:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet[2008/10/09 14:52:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macrovision[2009/04/11 13:24:49 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft[2008/12/16 17:27:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS[2008/11/07 14:52:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS[2009/05/02 21:04:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games[2008/10/08 11:36:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype[2009/03/29 18:14:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp[2009/04/11 08:20:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint[2009/04/20 07:23:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Raolan\Application Data[2009/04/04 17:13:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Adobe[2008/12/05 19:45:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Ambient Design[2008/10/09 20:22:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Apple Computer[2008/10/10 07:18:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Atari[2008/10/01 19:42:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\ATI[2008/10/10 21:20:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\AVGTOOLBAR[2009/05/10 22:00:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Azureus[2009/03/10 07:04:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1[2009/03/29 18:25:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\CyberLink[2008/10/09 20:19:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\DAEMON Tools[2008/10/09 20:31:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1[2009/01/28 06:57:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Download Manager[2009/04/06 19:05:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\dvdcss[2009/04/04 07:15:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\FileZilla[2008/10/09 10:42:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\GlobalSCAPE[2009/04/12 18:23:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Hamachi[2008/12/21 05:16:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Humanbalance[2008/10/01 16:55:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Identities[2008/10/10 07:15:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Leadertech[2009/04/05 10:05:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Macromedia[2009/04/11 13:24:49 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Raolan\Application Data\Microsoft[2009/03/19 21:40:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Mozilla[2008/10/28 16:13:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Multi-Note[2008/10/29 06:52:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\OpenOffice.org[2008/10/08 21:31:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Opera[2008/10/09 14:21:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\PSpad[2009/03/29 17:21:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Real[2009/03/20 19:40:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Safer Networking[2009/05/11 21:42:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Skype[2009/05/11 21:31:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\skypePM[2008/10/17 17:57:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Subversion[2008/10/30 19:46:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Sun[2008/12/13 12:40:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Talkback[2008/12/13 12:40:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Thunderbird[2008/10/17 17:57:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\TortoiseSVN[2008/10/19 10:49:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\vlc[2008/12/27 13:57:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\Winamp[2008/10/08 16:32:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\WinRAR[2008/11/10 20:33:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Raolan\Application Data\yoclient[2009/04/28 13:37:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job[2001/08/23 22:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini[2009/05/11 12:42:12 | 00,000,930 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1220945662-682003330-1003.job[2009/05/11 21:30:24 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== < End of report >