OTListIt logfile created on: 2/19/2009 2:50:29 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.18 Folder = C:\Documents and Settings\Lucky\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 563.84 Mb Available Physical Memory | 55.09% Memory free
2.41 Gb Paging File | 2.04 Gb Available in Paging File | 84.64% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.30 Gb Total Space | 12.46 Gb Free Space | 33.39% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 465.65 Gb Total Space | 458.15 Gb Free Space | 98.39% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: NONE-4607955B50
Current User Name: Lucky
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe ()
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Lucky\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gupdate1c98e39710d8ed0 [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Running]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (Nero BackItUp Scheduler 4.0 [Auto | Stopped]) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pctspk [Auto | Running]) -- C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (ALCXWDM [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Avance Logic, Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BIOS [System | Running]) -- C:\WINDOWS\system32\drivers\BIOS.sys (BIOSTAR Group)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) -- C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (pavboot [Unknown | Running]) -- File not found
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Ptserlp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptserlp.sys (PCTEL, INC.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (SCDEmu [System | Running]) -- C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (tmcomm [Auto | Running]) -- C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbbus [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (viaagp1 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (VIAudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\viaudios.sys (VIA Technologies, Inc.)
DRV - (videX32 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (Vmodem [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Vpctcom [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Vsp [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\Vsp.sys ()
DRV - (Vvoice [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vvoice.sys (PCtel, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.c...rch/search.htmlIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.co...m...tf8&oe=utf8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O1 HOSTS File: (297250 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10268 more lines...
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [au] C:\Program Files\Dealio\DealioAU.exe File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe File not found
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [SoundMan] soundman.exe (Avance Logic, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 File not found
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AudioDeck.lnk = C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe ()
O4 - Startup: C:\Documents and Settings\Lucky\Start Menu\Programs\Startup\OneNote Table Of Contents.one File not found
O4 - Startup: C:\Documents and Settings\Lucky\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: &Search - ?p=ZRman000
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
http://www.pcpitstop...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134}
http://lads.myspace....ploader1006.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125}
http://www.pcpitstop.com/mhLbl.cab (mhLabel Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - H:\autorun.inf () - [ FAT32 ]
O32 - Autorun File - H:\autorun [2007/07/20 10:43:34 00,000,000 | ---D | M] - [ FAT32 ]
O33 - MountPoints2\{8a4b6390-e81e-11dd-aa4e-004005391945}\Shell\AutoRun\command - "" = I:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8a4b6390-e81e-11dd-aa4e-004005391945}\Shell\install\command - "" = I:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8a4b6390-e81e-11dd-aa4e-004005391945}\Shell\usermanualEnglish\command - "" = I:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8a4b6390-e81e-11dd-aa4e-004005391945}\Shell\usermanualFrench\command - "" = I:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8a4b6390-e81e-11dd-aa4e-004005391945}\Shell\usermanualSpanish\command - "" = I:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{f4b00110-1645-11dd-a962-004005391945}\Shell\AutoRun\command - "" = H:\wd_windows_tools\setup.exe -- [2007/06/26 12:02:12 | 00,212,992 | ---- | M] (Western Digital Technologies, Inc.)
========== Files/Folders - Created Within 30 Days ========== [5 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/02/19 14:45:41 | 00,494,592 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lucky\Desktop\OTListIt2.exe
[2009/02/19 14:43:50 | 00,003,656 | ---- | C] () -- C:\Documents and Settings\Lucky\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2
[2009/02/19 14:43:50 | 00,000,851 | ---- | C] () -- C:\Documents and Settings\Lucky\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2009/02/19 10:46:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\Malwarebytes
[2009/02/19 10:46:02 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/19 10:45:58 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/19 10:45:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/19 10:45:55 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/19 10:43:43 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/02/19 10:42:19 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/02/19 09:52:58 | 00,001,067 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AudioDeck.lnk
[2009/02/17 16:12:50 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Lucky\Desktop\V CAST Music with Rhapsody.lnk
[2009/02/13 16:21:29 | 00,001,750 | ---- | C] () -- C:\Documents and Settings\Lucky\Desktop\Google Earth.lnk
[2009/02/13 16:16:14 | 00,000,880 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/02/13 14:39:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\Focus Mp3 Recorder
[2009/02/13 14:39:37 | 00,335,872 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioVisualization2.dll
[2009/02/13 14:39:37 | 00,196,608 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTWMAFile2.dll
[2009/02/13 14:39:36 | 01,843,200 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioFile2.dll
[2009/02/13 14:39:36 | 01,040,384 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioInformation2.dll
[2009/02/13 14:39:36 | 00,450,560 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioTransform2.dll
[2009/02/13 14:39:36 | 00,315,392 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioPlayer2.dll
[2009/02/13 14:39:36 | 00,311,296 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioRecord2.dll
[2009/02/13 14:39:36 | 00,270,336 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioDisplay2.dll
[2009/02/13 14:39:35 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009/02/13 14:39:32 | 00,000,000 | ---D | C] -- C:\Program Files\Focus MP3 Recorder Splitter
[2009/02/12 10:12:37 | 00,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/02/12 10:11:45 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/02/12 10:11:31 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/02/12 10:11:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/02/12 10:05:34 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/02/11 13:14:47 | 00,041,984 | ---- | C] () -- C:\Documents and Settings\Lucky\My Documents\Michelle's academic evaluation 2009.doc
[2009/02/10 20:22:01 | 00,002,251 | ---- | C] () -- C:\Documents and Settings\Lucky\Desktop\Nero Vision.lnk
[2009/02/10 09:31:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Desktop\Unused Desktop Shortcuts
[2009/02/10 08:13:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/02/10 08:13:10 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/02/10 08:12:25 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/02/10 08:08:44 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2009/02/10 08:08:43 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/02/10 08:08:40 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/02/10 08:08:39 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll
[2009/02/10 08:08:39 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/02/10 08:08:37 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2009/02/10 08:08:37 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/02/10 08:08:34 | 00,000,000 | ---D | C] -- C:\31aeea3084c234ab1ff3
[2009/02/10 08:07:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2009/02/09 20:27:47 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/02/09 20:25:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\My Documents\NeroVision
[2009/02/09 20:16:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\Nero
[2009/02/09 19:46:16 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2009/02/09 19:11:39 | 00,000,000 | ---D | C] -- C:\Program Files\Nero
[2009/02/09 19:10:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero
[2009/02/09 19:10:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2009/02/09 14:59:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Local Settings\Application Data\WMTools Downloaded Files
[2009/02/08 09:24:09 | 00,167,143 | ---- | C] () -- C:\Documents and Settings\Lucky\My Documents\Shawns 2008 Tax return.pdf
[2009/02/06 07:03:27 | 00,000,004 | ---- | C] () -- C:\Documents and Settings\Lucky\Application Data\714CA1
[2009/02/06 07:03:26 | 00,870,128 | ---- | C] () -- C:\Documents and Settings\Lucky\Application Data\mcs.rma
[2009/02/06 07:01:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Real
[2009/02/06 06:59:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\Real
[2009/02/06 06:56:02 | 00,000,000 | ---D | C] -- C:\Program Files\V CAST Music with Rhapsody
[2009/02/06 06:53:28 | 00,000,000 | ---D | C] -- C:\Program Files\LG Electronics
[2009/02/05 20:05:13 | 00,000,000 | ---D | C] -- C:\IC
[2009/02/03 20:28:37 | 00,133,181 | ---- | C] () -- C:\Documents and Settings\Lucky\My Documents\Dicks 2008TaxReturn.pdf
[2009/02/03 09:59:12 | 00,000,000 | ---D | C] -- C:\Program Files\PowerISO
[2009/02/03 09:38:10 | 00,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2009/02/03 09:38:06 | 00,136,704 | ---- | C] (Ligos Corporation) -- C:\WINDOWS\System32\iacenc.dll
[2009/02/03 09:06:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\WinRAR
[2009/02/03 09:04:46 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2009/02/02 11:16:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Desktop\Movie Downloads
[2009/02/02 07:42:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Desktop\New Folder
[2009/02/01 20:50:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Local Settings\Application Data\Ares
[2009/02/01 20:50:44 | 00,000,530 | ---- | C] () -- C:\Documents and Settings\Lucky\Desktop\Ares.lnk
[2009/02/01 20:50:18 | 00,000,000 | ---D | C] -- C:\Program Files\Ares
[2009/01/31 19:55:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\DivX
[2009/01/31 19:17:26 | 00,000,736 | ---- | C] () -- C:\WINDOWS\SamsungMaster.INI
[2009/01/31 19:01:41 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\vidccleaner.exe
[2009/01/31 19:01:36 | 00,000,663 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Samsung Master.lnk
[2009/01/31 19:01:06 | 00,217,088 | ---- | C] (STOIK Software) -- C:\WINDOWS\System32\skjpeg40.dll
[2009/01/31 19:01:05 | 00,083,968 | ---- | C] (STOIK Software Ltd.) -- C:\WINDOWS\System32\Skbase40.dll
[2009/01/31 19:01:04 | 00,000,000 | ---D | C] -- C:\Program Files\Samsung
[2009/01/29 15:39:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/01/29 15:39:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\Application Data\Uniblue
[2009/01/25 13:03:17 | 01,648,353 | ---- | C] () -- C:\Documents and Settings\Lucky\Desktop\Clutch Work Sheets.zip
[2009/01/23 14:38:07 | 00,157,534 | ---- | C] () -- C:\WINDOWS\hpoins29.dat.temp
[2009/01/23 14:38:07 | 00,000,986 | ---- | C] () -- C:\WINDOWS\hpomdl29.dat.temp
[2009/01/23 10:45:40 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/01/23 10:36:21 | 00,102,664 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/01/22 16:31:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\My Documents\My Scans
[2009/01/22 07:13:32 | 00,013,951 | ---- | C] () -- C:\Documents and Settings\Lucky\My Documents\Spring 2009 Schedule for Michelle.xlsx
[2009/01/22 00:50:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lucky\My Documents\My Completed Downloads
[2009/01/22 00:50:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2009/01/22 00:49:44 | 00,479,298 | ---- | C] (Stardock.Net, Inc) -- C:\WINDOWS\System32\wbocx.ocx
[2009/01/22 00:49:44 | 00,172,032 | ---- | C] (Jin Hui E-mail:
[email protected] Web:
http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2009/01/22 00:49:44 | 00,050,688 | ---- | C] (Stardock.Net, Inc) -- C:\WINDOWS\System32\wbhelp2.dll
[2009/01/21 17:29:18 | 00,000,067 | ---- | C] () -- C:\WINDOWS\AVIConverter.INI
[2009/01/21 16:26:36 | 00,028,160 | ---- | C] () -- C:\Documents and Settings\Lucky\My Documents\Weekly Journal 1--Spring.doc
[2009/01/21 13:03:25 | 00,043,008 | ---- | C] () -- C:\Documents and Settings\Lucky\My Documents\Bio 3 take home exam.doc
========== Files - Modified Within 30 Days ========== [5 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/02/19 14:45:34 | 00,494,592 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lucky\Desktop\OTListIt2.exe
[2009/02/19 14:43:50 | 00,000,542 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/02/19 14:43:50 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/02/19 14:43:50 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/02/19 14:35:14 | 00,022,607 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2009/02/19 14:33:18 | 00,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/02/19 14:30:32 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/02/19 14:30:20 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/02/19 09:57:30 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/02/19 09:39:46 | 00,001,744 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/02/19 09:33:12 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/19 09:03:12 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/02/19 08:02:34 | 00,030,720 | ---- | M] () -- C:\Documents and Settings\Lucky\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/19 01:05:24 | 00,000,336 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job
[2009/02/18 18:08:18 | 00,039,424 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Michelle Morris-Resume.doc
[2009/02/18 18:08:14 | 00,027,648 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Michelle Morris-references.doc
[2009/02/18 09:10:54 | 00,001,452 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\CCleaner.lnk
[2009/02/17 16:13:50 | 00,870,128 | ---- | M] () -- C:\Documents and Settings\Lucky\Application Data\mcs.rma
[2009/02/17 16:13:50 | 00,000,004 | ---- | M] () -- C:\Documents and Settings\Lucky\Application Data\714CA1
[2009/02/17 16:12:52 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\V CAST Music with Rhapsody.lnk
[2009/02/16 02:11:00 | 00,000,340 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
[2009/02/13 16:21:30 | 00,001,750 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\Google Earth.lnk
[2009/02/13 09:30:14 | 03,878,078 | -HS- | M] () -- C:\Documents and Settings\Lucky\My Documents\Thumbs.db
[2009/02/12 15:59:30 | 03,724,702 | -H-- | M] () -- C:\Documents and Settings\Lucky\Local Settings\Application Data\IconCache.db
[2009/02/12 10:12:38 | 00,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/02/11 15:18:30 | 00,028,160 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Weekly Journal 1--Spring.doc
[2009/02/11 13:14:50 | 00,041,984 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Michelle's academic evaluation 2009.doc
[2009/02/11 10:45:56 | 00,000,837 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\Spybot - Search & Destroy.lnk
[2009/02/11 10:19:42 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/10 20:22:02 | 00,002,251 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\Nero Vision.lnk
[2009/02/10 09:36:32 | 00,040,024 | ---- | M] () -- C:\Documents and Settings\Lucky\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/10 09:01:26 | 00,172,280 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/10 08:21:28 | 00,501,780 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/10 08:21:28 | 00,441,454 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/02/10 08:21:28 | 00,071,264 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/02/08 09:24:10 | 00,167,143 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Shawns 2008 Tax return.pdf
[2009/02/03 20:28:38 | 00,133,181 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Dicks 2008TaxReturn.pdf
[2009/02/03 15:21:12 | 21,244,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/02/01 20:50:46 | 00,000,530 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\Ares.lnk
[2009/01/31 19:54:58 | 00,000,736 | ---- | M] () -- C:\WINDOWS\SamsungMaster.INI
[2009/01/31 19:01:38 | 00,000,663 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Samsung Master.lnk
[2009/01/29 15:27:02 | 00,000,160 | ---- | M] () -- C:\WINDOWS\avrack.ini
[2009/01/26 15:59:02 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/01/26 15:59:00 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/26 15:59:00 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/26 15:58:40 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/26 15:29:44 | 00,001,632 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/01/25 13:03:18 | 01,648,353 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\Clutch Work Sheets.zip
[2009/01/24 15:46:06 | 00,043,008 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Bio 3 take home exam.doc
[2009/01/24 08:29:08 | 00,000,643 | ---- | M] () -- C:\Documents and Settings\Lucky\Desktop\MySpaceIM.lnk
[2009/01/23 14:39:44 | 00,156,899 | ---- | M] () -- C:\WINDOWS\hpoins29.dat
[2009/01/23 10:35:28 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/01/22 07:13:36 | 00,013,951 | ---- | M] () -- C:\Documents and Settings\Lucky\My Documents\Spring 2009 Schedule for Michelle.xlsx
[2009/01/22 00:49:46 | 00,479,298 | ---- | M] (Stardock.Net, Inc) -- C:\WINDOWS\System32\wbocx.ocx
[2009/01/22 00:49:46 | 00,172,032 | ---- | M] (Jin Hui E-mail:
[email protected] Web:
http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2009/01/22 00:49:46 | 00,050,688 | ---- | M] (Stardock.Net, Inc) -- C:\WINDOWS\System32\wbhelp2.dll
[2009/01/21 17:32:18 | 00,000,067 | ---- | M] () -- C:\WINDOWS\AVIConverter.INI
========== LOP Check ========== [2008/04/25 15:56:58 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/02/12 10:11:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/05/13 20:06:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/05/13 20:28:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2008/05/13 20:29:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/08/24 14:37:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg8
[2008/04/25 16:34:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/01/29 15:39:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
[2008/07/18 15:14:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2008/04/30 15:42:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2008/05/13 22:08:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/08/18 11:08:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2008/08/18 11:14:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP
[2008/08/18 11:14:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2008/10/13 09:49:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield
[2008/06/22 20:03:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intenium
[2009/02/19 10:45:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/08/24 14:14:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2008/10/13 09:25:00 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Memeo
[2008/04/25 15:56:30 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/04/29 20:43:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2009/02/09 19:10:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nero
[2008/07/08 18:40:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/07/07 21:34:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/04/29 21:25:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/01/22 00:50:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2009/01/08 17:52:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/04/29 16:48:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com
[2008/05/13 18:01:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/04/30 06:32:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/08/18 11:50:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WEBREG
[2008/05/11 18:19:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/05/05 20:19:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/04/25 15:56:58 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Lucky\Application Data
[2008/04/29 19:55:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Adobe
[2008/04/29 19:55:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\AdobeUM
[2008/05/13 20:31:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Apple Computer
[2008/05/31 10:24:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\BitTorrent
[2008/04/30 20:00:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\CyberLink
[2008/09/01 17:01:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Datel
[2009/01/31 19:55:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\DivX
[2009/02/13 14:39:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Focus Mp3 Recorder
[2008/07/18 18:18:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Gaijin Ent
[2009/01/10 11:45:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\GetGo Software
[2008/04/30 17:23:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Google
[2008/08/18 11:49:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\HP
[2008/08/18 11:22:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\HPAppData
[2008/04/25 16:23:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Identities
[2008/06/29 11:47:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\InstallShield
[2008/04/30 06:38:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Kodak
[2008/04/30 15:43:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\LimeWire
[2008/04/30 13:04:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Macromedia
[2009/02/19 10:46:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Malwarebytes
[2008/04/25 15:56:30 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Lucky\Application Data\Microsoft
[2008/07/01 19:54:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Mozilla
[2008/04/30 20:49:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\MySpace
[2009/02/09 20:16:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Nero
[2008/04/29 21:42:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Nikon
[2008/07/07 21:34:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\PlayFirst
[2009/02/06 06:59:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Real
[2008/06/18 13:59:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\SBTT
[2008/04/30 15:42:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Sun
[2008/07/01 19:55:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Talkback
[2008/04/30 06:34:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Ulead Systems
[2009/01/29 15:39:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Uniblue
[2008/07/16 13:53:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\WeatherBug
[2009/02/03 09:06:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\WinRAR
[2008/05/05 20:19:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lucky\Application Data\Yahoo!
[2006/02/28 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/02/19 14:30:32 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/02/19 01:05:24 | 00,000,336 | ---- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2009/02/16 02:11:00 | 00,000,340 | ---- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2009/02/19 09:33:12 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/02/19 14:33:18 | 00,000,880 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
========== Purity Check ========== < End of report >