OTL logfile created on: 7/20/2010 2:05:21 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\debbie\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,013.00 Mb Total Physical Memory | 502.00 Mb Available Physical Memory | 50.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 66.38 Gb Free Space | 89.11% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OFFICE
Current User Name: debbie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/07/20 14:03:42 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\debbie\Desktop\OTL.exe
PRC - [2010/07/07 20:06:56 | 000,864,112 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/07/07 20:06:55 | 001,352,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/10 06:58:32 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2010/06/10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2010/02/17 16:52:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2010/02/17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/01/23 10:46:14 | 000,203,280 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2007/10/11 19:03:10 | 000,029,984 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
PRC - [2004/08/04 06:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ========== MOD - [2010/07/20 14:03:42 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\debbie\Desktop\OTL.exe
MOD - [2009/01/23 10:46:18 | 000,013,840 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2004/08/04 06:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/07/07 20:06:55 | 001,352,832 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/06/10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2010/02/24 13:16:08 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2010/02/17 16:52:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2010/02/17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009/01/23 10:46:14 | 000,203,280 | ---- | M] () [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
========== Driver Services (SafeList) ========== DRV - [2010/07/07 20:07:14 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/04/14 12:50:14 | 000,385,536 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2010/02/17 16:52:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2010/02/17 16:52:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2010/02/17 16:52:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2010/02/17 16:52:10 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/07/16 12:32:26 | 000,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)
DRV - [2007/04/16 21:16:26 | 005,760,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007/04/13 20:33:34 | 000,254,872 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel®
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co...=en&source=iglkIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/07/20 11:27:19 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010/07/20 11:17:26 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - Startup: C:\Documents and Settings\debbie\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/06/27 19:49:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{3bd29c4e-857d-11df-8ec3-001d098a43e0}\Shell\AutoRun\command - "" = F:\Setup_FlipShare.exe -- File not found
O33 - MountPoints2\{3bd29c4e-857d-11df-8ec3-001d098a43e0}\Shell\Setup FlipShare\command - "" = F:\Setup_FlipShare.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 90 Days ========== [2010/07/20 14:03:31 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\debbie\Desktop\OTL.exe
[2010/07/20 12:07:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Desktop\gmer
[2010/07/20 11:57:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Desktop\tdsskiller
[2010/07/20 11:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Desktop\GooredFix Backups
[2010/07/20 11:45:46 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\debbie\Desktop\GooredFix.exe
[2010/07/20 11:17:14 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/07/20 11:16:10 | 000,520,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\debbie\Desktop\OTM.exe
[2010/07/20 11:14:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/20 11:14:08 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/07/20 10:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/20 07:27:19 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\debbie\IECompatCache
[2010/07/19 10:30:25 | 000,157,712 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/07/18 20:17:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\Malwarebytes
[2010/07/18 20:17:44 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/18 20:17:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/18 20:17:42 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/18 20:17:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 18:11:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Local Settings\Application Data\Apple
[2010/07/17 17:04:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010/07/10 18:11:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2010/07/07 20:07:47 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/07/06 15:10:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Local Settings\Application Data\Adobe
[2010/07/06 15:06:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010/07/06 15:06:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/07/06 15:06:09 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/07/01 09:52:23 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/06/29 11:50:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\Apple Computer
[2010/06/29 11:50:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Local Settings\Application Data\Apple Computer
[2010/06/29 11:49:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Local Settings\Application Data\Scansoft
[2010/06/29 11:35:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/06/29 11:35:47 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/06/29 11:35:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/06/29 11:34:32 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/06/29 11:34:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/06/29 11:34:16 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/06/29 11:33:37 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/06/29 11:33:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/06/29 11:33:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010/06/29 08:45:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010/06/29 08:44:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2010/06/29 08:44:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/06/29 08:42:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2010/06/29 08:42:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Local Settings\Application Data\Microsoft Help
[2010/06/29 08:41:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010/06/29 08:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2010/06/29 08:41:41 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/06/29 08:38:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\U3
[2010/06/29 08:26:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\BrFaxRx
[2010/06/29 08:26:48 | 000,073,728 | ---- | C] (Brother Industories Ltd. P&S Company) -- C:\WINDOWS\System32\BRCrypt.dll
[2010/06/29 08:26:41 | 000,102,400 | ---- | C] (Brother Industries,LTD.) -- C:\WINDOWS\System32\BrMfNt.dll
[2010/06/29 08:26:10 | 000,167,936 | ---- | C] (brother) -- C:\WINDOWS\System32\NSSearch.dll
[2010/06/29 08:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Brother
[2010/06/29 08:24:46 | 000,000,000 | ---D | C] -- C:\Program Files\Nuance
[2010/06/29 08:24:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\InstallShield
[2010/06/29 08:23:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ScanSoft Shared
[2010/06/29 08:23:45 | 000,000,000 | ---D | C] -- C:\Program Files\ScanSoft
[2010/06/29 08:23:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/06/29 08:23:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010/06/29 08:23:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Brother
[2010/06/29 08:06:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\debbie\PrivacIE
[2010/06/29 08:05:38 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\debbie\IETldCache
[2010/06/29 08:00:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/06/29 07:59:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2010/06/29 07:58:39 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/06/29 07:58:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2010/06/28 11:24:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\My Documents\LEGO Creations
[2010/06/28 11:24:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\LEGO Company
[2010/06/28 11:24:36 | 000,000,000 | ---D | C] -- C:\Program Files\LEGO Company
[2010/06/28 10:02:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\Macromedia
[2010/06/28 10:02:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\Adobe
[2010/06/28 09:58:40 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/06/28 09:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/06/28 08:25:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\SACore
[2010/06/28 07:41:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2010/06/28 07:38:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2010/06/28 07:35:52 | 000,079,816 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2010/06/28 07:35:52 | 000,040,552 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfesmfk.sys
[2010/06/28 07:35:52 | 000,035,272 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2010/06/28 07:35:50 | 000,120,136 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\Mpfp.sys
[2010/06/28 07:35:32 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2010/06/28 07:35:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2010/06/28 07:35:26 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2010/06/28 07:32:52 | 000,034,248 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdk.sys
[2010/06/28 07:15:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2010/06/27 22:11:17 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2010/06/27 22:11:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2010/06/27 21:52:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2010/06/27 20:21:59 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/06/27 20:21:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/06/27 20:12:53 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2010/06/27 20:07:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2010/06/27 20:07:49 | 000,000,000 | ---D | C] -- C:\Intel
[2010/06/27 20:07:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\vmm32
[2010/06/27 20:07:08 | 000,000,000 | ---D | C] -- C:\Program Files\Dell
[2010/06/27 20:05:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2010/06/27 20:02:31 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2010/06/27 20:02:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2010/06/27 20:02:06 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/06/27 20:01:58 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/06/27 20:01:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/06/27 19:56:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Application Data\Identities
[2010/06/27 19:56:29 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2010/06/27 19:56:26 | 000,000,000 | R--D | C] -- C:\Documents and Settings\debbie\My Documents\My Music
[2010/06/27 19:56:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\debbie\My Documents\My Pictures
[2010/06/27 19:56:23 | 000,000,000 | --SD | C] -- C:\Documents and Settings\debbie\Application Data\Microsoft
[2010/06/27 19:56:23 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\debbie\Application Data
[2010/06/27 19:56:23 | 000,000,000 | R--D | C] -- C:\Documents and Settings\debbie\Favorites
[2010/06/27 19:56:23 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\debbie\Cookies
[2010/06/27 19:56:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Desktop
[2010/06/27 19:56:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\debbie\SendTo
[2010/06/27 19:56:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\debbie\Recent
[2010/06/27 19:56:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\debbie\Start Menu
[2010/06/27 19:56:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\debbie\My Documents
[2010/06/27 19:56:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\debbie\Templates
[2010/06/27 19:56:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\debbie\PrintHood
[2010/06/27 19:56:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\debbie\NetHood
[2010/06/27 19:56:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\debbie\Local Settings
[2010/06/27 19:56:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\debbie\Local Settings\Application Data\Microsoft
[2010/06/27 19:53:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2010/06/27 19:53:33 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2010/06/27 19:53:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010/06/27 19:53:32 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/06/27 19:53:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/06/27 19:52:04 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/06/27 19:52:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/06/27 19:50:55 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2010/06/27 19:50:55 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2010/06/27 19:50:55 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2010/06/27 19:50:08 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2010/06/27 19:49:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2010/06/27 19:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2010/06/27 19:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010/06/27 19:49:49 | 000,000,000 | ---D | C] -- C:\DELL
[2010/06/27 19:49:40 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2010/06/27 19:48:46 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2010/06/27 19:48:40 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2010/06/27 19:48:40 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2010/06/27 19:48:31 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2010/06/27 19:48:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2010/06/27 19:47:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2010/06/27 19:47:47 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2010/06/27 19:47:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2010/06/27 19:47:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2010/06/27 19:47:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2010/06/27 19:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2010/06/27 19:47:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2010/06/27 19:47:27 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2010/06/27 19:47:25 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2010/06/27 19:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2010/06/27 19:47:19 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2010/06/27 19:47:18 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2010/06/27 19:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2010/06/27 19:47:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2010/06/27 19:46:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2010/06/27 19:46:43 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2010/06/27 19:46:43 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2010/06/27 19:46:39 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2010/06/27 19:46:36 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2010/06/27 19:46:05 | 000,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2010/06/27 19:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2010/06/27 19:46:04 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2010/06/27 19:46:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2010/06/27 19:46:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2010/06/27 15:33:48 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2010/06/27 15:33:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2010/06/27 15:33:45 | 000,000,000 | R--D | C] -- C:\Program Files
[2010/06/27 15:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2010/06/27 15:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2010/06/27 15:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2010/06/27 15:33:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2010/06/27 15:33:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2010/06/27 15:33:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2010/06/27 15:33:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2010/06/27 15:33:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2010/06/27 15:33:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2010/06/27 15:33:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2010/06/27 15:33:04 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2010/06/27 15:33:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2010/06/27 15:32:46 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010/06/27 15:32:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2010/06/27 15:26:38 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2010/06/27 15:26:38 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2010/06/27 15:26:38 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2010/06/27 15:26:38 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\dell
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2010/06/27 15:26:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025