OTL logfile created on: 2009-10-27 2:23:30 AM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = D:\Documents and Settings\junlong.tan.2008\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.96 Gb Available Physical Memory | 98.05% Memory free
4.00 Gb Paging File | 3.91 Gb Available in Paging File | 97.75% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 40.00 Gb Total Space | 26.34 Gb Free Space | 65.84% Space Free | Partition Type: NTFS
Drive D: | 70.01 Gb Total Space | 6.26 Gb Free Space | 8.94% Space Free | Partition Type: NTFS
Drive E: | 122.87 Gb Total Space | 11.82 Gb Free Space | 9.62% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 3.68 Gb Total Space | 0.58 Gb Free Space | 15.74% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JUNLONGTAN2008
Current User Name: junlong.tan.2008
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2009-10-27 02:22:42 | 00,521,728 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\junlong.tan.2008\Desktop\OTL.exe
PRC - [2009-09-11 00:08:45 | 00,908,280 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-09-08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) -- D:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009-09-08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- D:\Program Files\iPod\bin\iPodService.exe
PRC - [2009-08-28 11:27:42 | 26,784,939 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2009-08-06 17:51:54 | 00,613,128 | ---- | M] (
http://tortoisesvn.net) -- D:\Program Files\TortoiseSVN\bin\TSVNCache.exe
PRC - [2009-07-26 16:44:34 | 03,883,856 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2009-07-25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-07-14 02:51:28 | 06,591,104 | ---- | M] () -- D:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
PRC - [2009-05-29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009-05-21 14:01:02 | 17,881,600 | ---- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\RTHDCPL.EXE
PRC - [2009-04-16 13:36:36 | 24,264,488 | R--- | M] (Skype Technologies S.A.) -- D:\Program Files\Skype\Phone\Skype.exe
PRC - [2009-03-16 18:47:48 | 00,077,360 | R--- | M] (Skype Technologies) -- D:\Program Files\Skype\Plugin Manager\skypePM.exe
PRC - [2009-03-11 05:22:16 | 03,581,680 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2009-02-06 18:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009-02-06 17:07:48 | 00,027,512 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008-10-25 11:44:34 | 00,031,072 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008-10-21 10:41:04 | 00,462,848 | ---- | M] () -- D:\Program Files\Verudium\Verudium USB Network Server\NPW\NPWService.exe
PRC - [2008-07-26 08:48:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe
PRC - [2008-04-14 10:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Explorer.EXE
PRC - [2008-01-29 17:38:31 | 00,583,048 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007-11-16 12:42:24 | 01,024,000 | ---- | M] (Synaptics, Inc.) -- D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2007-09-25 16:10:50 | 02,007,088 | ---- | M] (FlashGet.com) -- D:\Program Files\FlashGet\FlashGet.exe
PRC - [2007-08-08 00:08:40 | 00,094,208 | ---- | M] () -- D:\Program Files\ATKGFNEX\GFNEXSrv.exe
PRC - [2007-07-03 10:48:02 | 07,708,672 | ---- | M] () -- D:\Program Files\ATKOSD2\ATKOSD2.exe
PRC - [2007-06-29 15:44:06 | 00,225,280 | ---- | M] () -- D:\Program Files\ATK Hotkey\Hcontrol.exe
PRC - [2007-06-28 17:40:12 | 00,090,112 | ---- | M] () -- D:\Program Files\ATK Hotkey\WDC.exe
PRC - [2007-06-26 16:23:38 | 00,851,968 | ---- | M] (ATK) -- D:\Program Files\ASUS\Splendid\ACMON.exe
PRC - [2007-05-23 16:56:14 | 02,420,736 | ---- | M] () -- D:\Program Files\ATK Hotkey\ATKOSD.exe
PRC - [2007-05-22 16:57:26 | 02,756,608 | ---- | M] (TOSHIBA CORPORATION.) -- D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2007-04-26 14:53:38 | 00,274,432 | ---- | M] (TOSHIBA CORPORATION.) -- D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
PRC - [2007-04-17 13:39:42 | 00,077,824 | ---- | M] () -- D:\Program Files\ATK Hotkey\KBFiltr.exe
PRC - [2007-03-04 11:29:34 | 00,677,408 | ---- | M] (Infineon Technologies AG) -- D:\WINDOWS\System32\ifxspmgt.exe
PRC - [2007-02-28 22:32:30 | 00,140,832 | ---- | M] (Infineon Technologies AG) -- D:\WINDOWS\System32\IfxPsdSv.exe
PRC - [2007-02-28 22:12:50 | 00,849,440 | ---- | M] (Infineon Technologies AG) -- D:\WINDOWS\System32\ifxtcs.exe
PRC - [2007-02-27 20:21:08 | 00,278,528 | ---- | M] (TOSHIBA CORPORATION.) -- D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2007-02-25 21:55:18 | 00,125,048 | ---- | M] (TOSHIBA CORPORATION) -- D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2007-01-10 01:29:32 | 00,108,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2006-07-26 18:01:06 | 00,090,112 | ---- | M] (ASUSTeK Computer Inc.) -- D:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
PRC - [2006-01-23 23:14:10 | 00,069,632 | ---- | M] (TOSHIBA CORPORATION.) -- D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2005-07-06 15:43:42 | 00,155,648 | ---- | M] (ASUSTeK) -- D:\WINDOWS\System32\ACEngSvr.exe
========== Win32 Services (SafeList) ========== SRV - [2009-09-09 01:33:34 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca30aa80f8cfa6 [Auto | Stopped])
SRV - [2009-09-09 01:32:33 | 00,194,032 | ---- | M] (Google) -- D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Stopped])
SRV - [2009-09-08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- D:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2009-07-14 02:51:28 | 06,591,104 | ---- | M] () -- D:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe -- (MySQL41 [Auto | Running])
SRV - [2009-05-29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009-03-10 22:29:59 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008-11-04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2008-10-25 11:44:08 | 00,065,888 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2008-10-21 10:41:04 | 00,462,848 | ---- | M] () -- D:\Program Files\Verudium\Verudium USB Network Server\NPW\NPWService.exe -- (NPWService [Auto | Running])
SRV - [2008-08-07 21:42:12 | 01,251,720 | ---- | M] () -- D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC [On_Demand | Stopped])
SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008-07-26 08:48:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008-07-18 13:13:20 | 00,053,760 | ---- | M] (Hewlett-Packard) -- D:\WINDOWS\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008-07-18 13:13:20 | 00,044,032 | ---- | M] (Hewlett-Packard) -- D:\WINDOWS\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
SRV - [2008-04-14 10:42:04 | 00,038,400 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008-01-29 17:38:31 | 00,583,048 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service [Auto | Stopped])
SRV - [2007-09-12 18:27:24 | 02,999,664 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate [On_Demand | Stopped])
SRV - [2007-08-08 00:08:40 | 00,094,208 | ---- | M] () -- D:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv [Auto | Running])
SRV - [2007-03-04 11:29:34 | 00,677,408 | ---- | M] (Infineon Technologies AG) -- D:\WINDOWS\System32\ifxspmgt.exe -- (IFXSpMgtSrv [Auto | Running])
SRV - [2007-02-28 22:32:30 | 00,140,832 | ---- | M] (Infineon Technologies AG) -- D:\WINDOWS\System32\IfxPsdSv.exe -- (PersonalSecureDriveService [Auto | Running])
SRV - [2007-02-28 22:12:50 | 00,849,440 | ---- | M] (Infineon Technologies AG) -- D:\WINDOWS\System32\ifxtcs.exe -- (IFXTCS [Auto | Running])
SRV - [2007-02-25 21:55:18 | 00,125,048 | ---- | M] (TOSHIBA CORPORATION) -- D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service [Auto | Running])
SRV - [2007-01-12 23:10:58 | 00,049,248 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost [On_Demand | Stopped])
SRV - [2007-01-10 01:29:32 | 00,108,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (LiveUpdate Notice Ex [Auto | Running])
SRV - [2007-01-10 01:29:32 | 00,108,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (CLTNetCnService [Auto | Running])
SRV - [2007-01-10 01:29:32 | 00,108,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr [Auto | Running])
SRV - [2007-01-10 01:29:32 | 00,108,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr [Auto | Running])
SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006-10-18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Modules (SafeList) ========== MOD - [2009-10-27 02:22:42 | 00,521,728 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\junlong.tan.2008\Desktop\OTL.exe
MOD - [2008-07-22 10:53:50 | 00,530,004 | ---- | M] (Stardock Corporation) -- D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll
MOD - [2008-04-26 16:14:24 | 00,028,740 | ---- | M] (Stardock.Net, Inc) -- D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll
MOD - [2008-04-26 16:14:22 | 00,042,672 | ---- | M] (Stardock.Net, Inc) -- D:\WINDOWS\System32\wbsys.dll
MOD - [2008-04-14 10:42:52 | 01,054,208 | R--- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
MOD - [2007-05-19 00:13:08 | 00,053,329 | ---- | M] (www.flashget.com) -- D:\Program Files\FlashGet\fgmgr.dll
MOD - [2007-04-24 15:22:12 | 00,112,400 | ---- | M] () -- D:\Program Files\Stardock\ObjectDock\DockShellHook.dll
MOD - [2004-08-04 20:00:00 | 00,014,848 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\serwvdrv.dll
MOD - [2004-08-04 20:00:00 | 00,013,312 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\umdmxfrm.dll
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/igIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 58 29 47 57 AB 1D CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.com/ig"FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems:
[email protected]:1.01
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090525
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:0.0.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.38
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-09-02 03:00:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\
[email protected]: D:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-02-10 13:16:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009-10-25 02:04:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009-10-26 18:52:44 | 00,000,000 | ---D | M]
[2009-02-10 11:16:46 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Extensions
[2009-02-10 11:16:46 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-10-27 01:40:02 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions
[2009-10-26 18:53:19 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
[2009-06-06 22:54:57 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009-08-18 00:13:29 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009-10-26 18:53:19 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2009-08-18 00:13:29 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-10-26 21:32:01 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\mozilla\Firefox\Profiles\l5l3eztb.default\extensions\
[email protected][2009-10-27 01:00:10 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions
[2009-09-11 00:08:46 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-03-23 19:27:54 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009-02-10 13:16:40 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009-06-01 17:58:43 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009-08-17 22:15:50 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009-09-11 00:08:44 | 00,023,544 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-09-11 00:08:44 | 00,137,208 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-07-25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009-02-06 12:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009-09-11 00:08:45 | 00,065,016 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006-10-26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009-02-27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- D:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008-09-11 03:56:44 | 00,144,960 | ---- | M] (RealNetworks, Inc.) -- D:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009-09-27 12:57:51 | 00,159,744 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008-09-11 03:37:54 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- D:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009-08-17 01:19:46 | 00,001,394 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009-08-17 01:19:46 | 00,002,193 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009-08-17 01:19:46 | 00,001,534 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009-08-17 01:19:46 | 00,002,344 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009-08-17 01:19:46 | 00,002,371 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-08-17 01:19:46 | 00,001,178 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009-08-17 01:19:46 | 00,000,792 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (686 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Program Files\FlashGet\jccatch.dll (www.flashget.com)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - D:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\Program Files\FlashGet\getflash.dll (www.flashget.com)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - D:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O4 - HKLM..\Run: [ACMON] D:\Program Files\ASUS\Splendid\ACMON.exe (ATK)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATKHOTKEY] D:\Program Files\ATK Hotkey\Hcontrol.exe ()
O4 - HKLM..\Run: [ATKOSD2] D:\Program Files\ATKOSD2\ATKOSD2.exe ()
O4 - HKLM..\Run: [ccApp] D:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Flashget] D:\Program Files\FlashGet\FlashGet.exe (FlashGet.com)
O4 - HKLM..\Run: [GrooveMonitor] D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMEKRMIG6.1] D:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [MSConfig] D:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] D:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Power_Gear] D:\Program Files\ASUS\Power4 Gear\BatteryLife.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [QuickTime Task] D:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] D:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [Google Update] D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [msnmsgr] D:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Skype] D:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKCU..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\ObjectDock Plus.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O4 - Startup: D:\Documents and Settings\junlong.tan.2008\Start Menu\Programs\Startup\Dropbox.lnk = D:\Documents and Settings\junlong.tan.2008\Application Data\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download All with FlashGet - D:\Program Files\FlashGet\jc_all.htm ()
O8 - Extra context menu item: &Download with FlashGet - D:\Program Files\FlashGet\jc_link.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - D:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download Link Using Mega Manager... - D:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - D:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Verudium\Verudium USB Network Server\NPW\NPWprint.dll (Elite Silicon Technology Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: edu.sg ([*.smu] * in Local intranet)
O15 - HKCU\..Trusted Domains: edu.sg ([*.smuconnect] * in Local intranet)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.aka...vex-2.2.4.2.cab (DLM Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zon...1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 202.156.1.58 202.156.1.48 218.186.1.38
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = student.smu.edu.sg
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - D:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - D:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - D:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (D:\WINDOWS\system32\wbsys.dll) - D:\WINDOWS\System32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WBSrv: DllName - D:\Program Files\Stardock\Object Desktop\WindowBlinds\WBSrv.dll - D:\Program Files\Stardock\Object Desktop\WindowBlinds\WBSrv.dll (Stardock Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - D:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-11 05:42:20 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ========== [2009-10-26 18:52:36 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Real
[2009-10-26 18:52:36 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Real
[2009-10-26 18:52:36 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\Real
[2009-10-20 12:26:30 | 00,000,000 | ---D | C] -- D:\Program Files\Heroes of Newerth
[2009-10-26 18:52:34 | 00,000,000 | ---D | C] -- D:\Program Files\iPhone Tunnel Suite 2.7 BETA
[2009-10-27 02:23:59 | 00,472,064 | ---- | C] ( ) -- D:\Documents and Settings\junlong.tan.2008\Desktop\RootRepeal.exe
[2009-10-27 02:22:39 | 00,521,728 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\junlong.tan.2008\Desktop\OTL.exe
[2009-10-27 00:25:11 | 00,000,000 | ---D | C] -- D:\SDFix
[2009-10-27 00:22:26 | 00,271,872 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\junlong.tan.2008\Desktop\TFC.exe
[2009-10-26 21:30:58 | 00,000,000 | ---D | C] -- D:\WINDOWS\BDOSCAN8
[2009-10-26 20:36:52 | 00,212,480 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWXCACLS.exe
[2009-10-26 20:36:52 | 00,161,792 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWREG.exe
[2009-10-26 20:36:52 | 00,136,704 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWSC.exe
[2009-10-26 20:36:52 | 00,031,232 | ---- | C] (NirSoft) -- D:\WINDOWS\NIRCMD.exe
[2009-10-26 20:35:16 | 00,000,000 | ---D | C] -- D:\WINDOWS\ERDNT
[2009-10-26 20:34:31 | 00,000,000 | ---D | C] -- D:\Qoobox
[2009-10-26 18:52:44 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\Desktop\SE Project
[2009-10-26 18:52:44 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\Desktop\New Folder (2)
[2009-10-26 18:52:23 | 00,000,000 | ---D | C] -- D:\Config.Msi
[2009-10-25 02:25:16 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\My Documents\eXtreme Movie Manager 7
[2009-10-25 02:04:39 | 00,287,744 | ---- | C] (Kristal StudioDFileDescription) -- D:\WINDOWS\System32\divxa32.acm
[2009-10-25 02:04:39 | 00,118,784 | ---- | C] (fccHandler) -- D:\WINDOWS\System32\ac3acm.acm
[2009-10-20 19:48:41 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\Desktop\Comms
[2009-10-20 18:28:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\Desktop\Photoshop Brushes
[2009-10-20 12:27:01 | 00,000,000 | ---D | C] -- D:\Documents and Settings\junlong.tan.2008\My Documents\Heroes of Newerth
[2009-03-12 01:06:57 | 00,168,192 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\GenHC.sys
[2008-11-25 16:57:48 | 00,027,136 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\GenBus.sys
[2008-08-08 04:19:21 | 00,005,632 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\kbfiltr.sys
========== Files - Modified Within 14 Days ========== [2009-10-27 02:24:17 | 00,000,000 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\settings.dat
[2009-10-27 02:24:01 | 00,472,064 | ---- | M] ( ) -- D:\Documents and Settings\junlong.tan.2008\Desktop\RootRepeal.exe
[2009-10-27 02:22:42 | 00,521,728 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\junlong.tan.2008\Desktop\OTL.exe
[2009-10-27 02:11:00 | 00,001,022 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-818368676-931757178-618671499-35043UA.job
[2009-10-27 01:41:00 | 00,000,906 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009-10-27 01:41:00 | 00,000,902 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009-10-27 01:23:14 | 00,047,104 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Win32kDiag.exe
[2009-10-27 01:14:32 | 00,000,669 | ---- | M] () -- D:\WINDOWS\win.ini
[2009-10-27 01:14:32 | 00,000,227 | ---- | M] () -- D:\WINDOWS\system.ini
[2009-10-27 00:58:17 | 00,195,241 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml
[2009-10-27 00:46:50 | 00,002,262 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2009-10-27 00:46:38 | 00,000,868 | ---- | M] () -- D:\WINDOWS\tasks\Google Software Updater.job
[2009-10-27 00:46:14 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2009-10-27 00:46:12 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2009-10-27 00:46:08 | 32,204,26752 | -HS- | M] () -- D:\hiberfil.sys
[2009-10-27 00:41:34 | 00,000,686 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\HOSTS
[2009-10-27 00:22:28 | 00,271,872 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\junlong.tan.2008\Desktop\TFC.exe
[2009-10-27 00:22:12 | 01,529,241 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\SDFix.exe
[2009-10-26 23:17:34 | 02,716,271 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\lastlove261009.zip
[2009-10-26 20:33:37 | 03,436,986 | R--- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\ComboFix.exe
[2009-10-26 20:09:55 | 00,147,456 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\catchme.exe
[2009-10-26 19:17:49 | 00,001,590 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Heroes of Newerth.lnk
[2009-10-26 11:11:02 | 00,000,970 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-818368676-931757178-618671499-35043Core.job
[2009-10-25 20:08:39 | 00,240,247 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Project v8.xlsm
[2009-10-25 17:31:14 | 00,229,338 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Project v6.xlsm
[2009-10-25 16:34:12 | 00,203,065 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Seo Heng.xlsm
[2009-10-25 15:24:13 | 00,220,297 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Copy of combined.xlsm
[2009-10-25 12:00:02 | 00,000,314 | ---- | M] () -- D:\WINDOWS\tasks\Security Platform Backup Schedule.job
[2009-10-25 06:11:34 | 00,077,312 | ---- | M] () -- D:\WINDOWS\MBR.exe
[2009-10-23 18:20:42 | 00,194,126 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\My file.xlsm
[2009-10-23 18:20:38 | 00,032,751 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Book1.xlsm
[2009-10-20 23:10:42 | 00,010,544 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\My Documents\Good afternoon ladies and gentlemen.docx
[2009-10-20 22:37:03 | 00,000,284 | ---- | M] () -- D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-10-19 22:38:54 | 00,011,311 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\My Documents\Book1.xlsx
[2009-10-19 18:06:53 | 00,000,025 | ---- | M] () -- D:\WINDOWS\popcinfot.dat
[2009-10-19 18:05:10 | 00,043,520 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-19 03:08:10 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK
[2009-10-15 20:21:20 | 00,009,829 | ---- | M] () -- D:\Documents and Settings\junlong.tan.2008\My Documents\lala.xlsx
[2009-10-15 03:09:54 | 00,522,480 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-15 03:09:54 | 00,456,872 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2009-10-15 03:09:54 | 00,075,612 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
========== Files - No Company Name ==========[2009-10-27 01:23:14 | 00,047,104 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Win32kDiag.exe
[2009-10-27 00:46:08 | 32,204,26752 | -HS- | C] () -- D:\hiberfil.sys
[2009-10-27 00:20:49 | 01,529,241 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\SDFix.exe
[2009-10-26 23:17:30 | 02,716,271 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\lastlove261009.zip
[2009-10-26 20:36:52 | 00,236,544 | ---- | C] () -- D:\WINDOWS\PEV.exe
[2009-10-26 20:36:52 | 00,098,816 | ---- | C] () -- D:\WINDOWS\sed.exe
[2009-10-26 20:36:52 | 00,080,412 | ---- | C] () -- D:\WINDOWS\grep.exe
[2009-10-26 20:36:52 | 00,077,312 | ---- | C] () -- D:\WINDOWS\MBR.exe
[2009-10-26 20:36:52 | 00,068,096 | ---- | C] () -- D:\WINDOWS\zip.exe
[2009-10-26 20:33:05 | 03,436,986 | R--- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\ComboFix.exe
[2009-10-26 20:09:53 | 00,147,456 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\catchme.exe
[2009-10-26 19:17:49 | 00,001,590 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Heroes of Newerth.lnk
[2009-10-25 18:38:29 | 00,240,247 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Project v8.xlsm
[2009-10-25 16:37:17 | 00,229,338 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Project v6.xlsm
[2009-10-25 15:30:15 | 00,203,065 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Seo Heng.xlsm
[2009-10-25 02:04:39 | 00,000,414 | ---- | C] () -- D:\WINDOWS\System32\lame_acm.xml
[2009-10-23 18:21:52 | 00,220,297 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Copy of combined.xlsm
[2009-10-23 12:07:28 | 00,194,126 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\My file.xlsm
[2009-10-20 23:10:39 | 00,010,544 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\My Documents\Good afternoon ladies and gentlemen.docx
[2009-10-19 22:48:31 | 00,032,751 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Desktop\Book1.xlsm
[2009-10-19 21:17:06 | 00,011,311 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\My Documents\Book1.xlsx
[2009-10-19 18:06:52 | 00,000,025 | ---- | C] () -- D:\WINDOWS\popcinfot.dat
[2009-10-15 20:16:47 | 00,009,829 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\My Documents\lala.xlsx
[2009-10-03 14:42:12 | 00,000,096 | ---- | C] () -- D:\WINDOWS\WirelessFTP.INI
[2009-09-27 13:02:05 | 00,180,224 | ---- | C] () -- D:\WINDOWS\System32\QTCF.dll
[2009-09-03 11:21:41 | 00,043,212 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\ModelerExeDebug.txt
[2009-08-17 18:21:21 | 00,004,767 | ---- | C] () -- D:\WINDOWS\Irremote.ini
[2009-07-25 02:48:11 | 00,073,728 | ---- | C] () -- D:\WINDOWS\System32\scard.dll
[2009-06-21 01:22:45 | 00,000,262 | ---- | C] () -- D:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009-05-12 22:37:26 | 00,168,448 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll
[2009-05-12 22:37:20 | 00,795,648 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2009-05-12 22:37:20 | 00,130,048 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll
[2009-05-12 22:37:19 | 03,596,288 | ---- | C] () -- D:\WINDOWS\System32\qt-dx331.dll
[2009-05-12 22:37:15 | 00,084,480 | ---- | C] () -- D:\WINDOWS\System32\ff_vfw.dll
[2009-05-12 22:37:15 | 00,000,547 | ---- | C] () -- D:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-04-21 14:59:46 | 00,000,600 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Application Data\winscp.rnd
[2009-03-25 02:05:49 | 00,598,016 | ---- | C] () -- D:\WINDOWS\System32\ImageProcess.dll
[2009-03-25 02:05:06 | 00,131,072 | ---- | C] () -- D:\WINDOWS\System32\TransSaveStatus.dll
[2009-03-18 02:03:24 | 00,087,552 | ---- | C] () -- D:\WINDOWS\System32\cpwmon2k.dll
[2009-03-11 04:51:14 | 00,000,081 | ---- | C] () -- D:\WINDOWS\WB.ini
[2009-03-05 19:13:07 | 00,717,296 | ---- | C] () -- D:\WINDOWS\System32\drivers\sptd.sys
[2009-03-03 15:40:41 | 00,000,050 | ---- | C] () -- D:\WINDOWS\MegaManager.INI
[2009-03-03 12:18:04 | 00,073,728 | ---- | C] () -- D:\WINDOWS\System32\RtNicProp32.dll
[2009-02-21 08:25:20 | 00,691,592 | ---- | C] () -- D:\WINDOWS\System32\OGACheckControl.DLL
[2009-02-19 22:39:49 | 02,463,976 | ---- | C] () -- D:\WINDOWS\System32\NPSWF32.dll
[2009-02-12 14:31:28 | 00,000,229 | ---- | C] () -- D:\WINDOWS\hpbafd.ini
[2009-02-10 17:50:16 | 00,043,520 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-02-10 12:20:25 | 00,078,392 | ---- | C] () -- D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009-02-10 10:57:44 | 00,000,271 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2009-01-05 15:44:10 | 00,000,453 | ---- | C] () -- D:\WINDOWS\bdoscandellang.ini
[2008-10-20 16:20:26 | 03,726,706 | -H-- | C] () -- D:\Documents and Settings\junlong.tan.2008\Local Settings\Application Data\IconCache.db
[2008-10-20 16:19:21 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\junlong.tan.2008\Application Data\desktop.ini
[2008-08-20 23:13:42 | 00,000,000 | ---- | C] () -- D:\WINDOWS\tosOBEX.INI
[2008-08-12 14:51:20 | 00,000,754 | ---- | C] () -- D:\WINDOWS\WORDPAD.INI
[2008-08-08 05:09:38 | 00,005,760 | ---- | C] () -- D:\WINDOWS\System32\drivers\ATKACPI.sys
[2008-08-08 04:35:19 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users\Application Data\desktop.ini
[2008-08-08 04:17:55 | 01,769,984 | ---- | C] () -- D:\WINDOWS\System32\drivers\snp2uvc.sys
[2008-08-08 04:17:55 | 00,028,160 | ---- | C] () -- D:\WINDOWS\System32\drivers\sncduvc.sys
[2008-08-08 04:07:23 | 00,016,480 | ---- | C] () -- D:\WINDOWS\System32\rixdicon.dll
[2008-08-08 03:16:36 | 01,724,416 | ---- | C] () -- D:\WINDOWS\System32\nvwdmcpl.dll
[2008-08-08 03:16:36 | 01,101,824 | ---- | C] () -- D:\WINDOWS\System32\nvwimg.dll
[2008-08-08 03:16:36 | 00,466,944 | ---- | C] () -- D:\WINDOWS\System32\nvshell.dll
[2008-08-08 03:16:35 | 01,499,136 | ---- | C] () -- D:\WINDOWS\System32\nview.dll
[2008-08-08 03:09:22 | 00,286,720 | ---- | C] () -- D:\WINDOWS\System32\nvnt4cpl.dll
[2007-09-27 10:51:02 | 00,020,698 | ---- | C] () -- D:\WINDOWS\System32\idxcntrs.ini
[2007-09-27 10:48:48 | 00,030,628 | ---- | C] () -- D:\WINDOWS\System32\gsrvctr.ini
[2007-09-27 10:48:28 | 00,031,698 | ---- | C] () -- D:\WINDOWS\System32\gthrctr.ini
[2006-12-05 13:05:04 | 00,114,688 | ---- | C] () -- D:\WINDOWS\System32\TosBtAcc.dll
[2005-07-22 21:30:18 | 00,065,536 | ---- | C] () -- D:\WINDOWS\System32\TosCommAPI.dll
[2004-08-04 20:00:00 | 00,000,669 | ---- | C] () -- D:\WINDOWS\win.ini
[2004-08-04 20:00:00 | 00,000,227 | ---- | C] () -- D:\WINDOWS\system.ini
========== LOP Check ========== [2009-10-26 18:52:36 | 00,000,000 | RH-D | M] -- D:\Documents and Settings\All Users\Application Data
[2009-03-17 23:02:58 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009-02-10 11:15:13 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009-09-15 22:44:31 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009-04-08 02:27:46 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009-03-12 02:01:00 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ALM
[2009-08-17 20:38:33 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\createpart
[2009-04-01 18:37:03 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\CyberLink
[2009-03-06 16:54:36 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009-08-17 20:39:07 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\deletepart
[2009-08-17 18:59:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\explauncher
[2009-03-11 22:01:49 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\FLEXnet
[2009-09-03 10:58:06 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\IBM
[2008-08-08 05:30:08 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Infineon
[2009-08-17 18:59:31 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\launcher
[2009-08-17 20:37:01 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\mergeparts
[2009-04-26 17:18:09 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009-02-10 19:16:45 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\MySQL
[2009-08-26 03:06:21 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\PopCap Games
[2009-08-17 18:59:35 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\redistpart
[2009-03-18 16:28:35 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009-10-26 18:52:36 | 00,000,000 | RH-D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data
[2009-06-01 17:54:58 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\BSplayer PRO
[2009-03-06 17:01:45 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\DAEMON Tools Lite
[2009-02-09 11:04:15 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Download Manager
[2009-10-27 00:59:24 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Dropbox
[2009-03-02 22:03:53 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Megaupload
[2009-03-16 20:56:09 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Mp3tag
[2009-10-24 22:02:01 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\MySQL
[2009-02-12 10:13:02 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Notepad++
[2009-08-24 23:33:52 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Subversion
[2009-10-19 03:00:25 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Thinstall
[2009-09-25 18:02:27 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\TortoiseSVN
[2009-09-11 11:48:08 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\U3
[2009-06-21 01:24:45 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Ventrilo
[2009-02-10 12:25:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Windows Desktop Search
[2009-02-10 17:51:40 | 00,000,000 | ---D | M] -- D:\Documents and Settings\junlong.tan.2008\Application Data\Windows Search
[2009-10-20 22:37:03 | 00,000,284 | ---- | M] () -- D:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004-08-04 20:00:00 | 00,000,065 | RH-- | M] () -- D:\WINDOWS\Tasks\desktop.ini
[2009-10-27 00:46:38 | 00,000,868 | ---- | M] () -- D:\WINDOWS\Tasks\Google Software Updater.job
[2009-10-27 01:41:00 | 00,000,902 | ---- | M] () -- D:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009-10-27 01:41:00 | 00,000,906 | ---- | M] () -- D:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009-10-26 11:11:02 | 00,000,970 | ---- | M] () -- D:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-818368676-931757178-618671499-35043Core.job
[2009-10-27 02:11:00 | 00,001,022 | ---- | M] () -- D:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-818368676-931757178-618671499-35043UA.job
[2009-10-27 00:46:14 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\Tasks\SA.DAT
[2009-10-25 12:00:02 | 00,000,314 | ---- | M] () -- D:\WINDOWS\Tasks\Security Platform Backup Schedule.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %SYSTEMDRIVE%\eventlog.dll /s /md5 >[eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008-04-14 10:41:54 | 00,056,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\ERDNT\cache\eventlog.dll
[eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008-04-14 10:41:54 | 00,056,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\eventlog.dll
[eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008-04-14 10:41:54 | 00,056,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\eventlog.dll
< %SYSTEMDRIVE%\scecli.dll /s /md5 >[scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008-04-14 10:42:06 | 00,181,248 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\ERDNT\cache\scecli.dll
[scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008-04-14 10:42:06 | 00,181,248 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\scecli.dll
[scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008-04-14 10:42:06 | 00,181,248 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\scecli.dll
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >[netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008-04-14 10:42:02 | 00,407,040 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\ERDNT\cache\netlogon.dll
[netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008-04-14 10:42:02 | 00,407,040 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\netlogon.dll
[netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008-04-14 10:42:02 | 00,407,040 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\netlogon.dll
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 > < %SYSTEMDRIVE%\sceclt.dll /s /md5 > < %SYSTEMDRIVE%\ntelogon.dll /s /md5 > < %SYSTEMDRIVE%\logevent.dll /s /md5 > < %SYSTEMDRIVE%\iaStor.sys /s /md5 >[iastor.sys : MD5=309C4D86D989FB1FCF64BD30DC81C51B] -> [2008-05-06 07:13:54 | 00,874,240 | ---- | M] (Intel Corporation) -- D:\WINDOWS\NLDRV\001\iastor.sys
[iastor.sys : MD5=E5A0034847537EAEE3C00349D5C34C5F] -> [2008-05-06 07:14:24 | 00,308,248 | ---- | M] (Intel Corporation) -- D:\WINDOWS\NLDRV\002\iastor.sys
[iaStor.sys : MD5=E5A0034847537EAEE3C00349D5C34C5F] -> [2007-09-29 23:03:12 | 00,308,248 | ---- | M] (Intel Corporation) -- D:\WINDOWS\System32\drivers\iaStor.sys
[iaStor.sys : MD5=E5A0034847537EAEE3C00349D5C34C5F] -> [2008-05-06 07:14:24 | 00,308,248 | ---- | M] (Intel Corporation) -- D:\WINDOWS\System32\ReinstallBackups\0001\DriverFiles\iaStor.sys
< %SYSTEMDRIVE%\nvstor.sys /s /md5 > < %SYSTEMDRIVE%\atapi.sys /s /md5 >[atapi.sys : MD5=9F3A2F5AA6875C72BF062C712CFA2674] -> [2008-04-14 08:10:32 | 00,096,512 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\drivers\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 > < %SYSTEMDRIVE%\viasraid.sys /s /md5 >< End of report >