Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Slow laptop


  • This topic is locked This topic is locked

#1
Bismillah

Bismillah

    Member

  • Member
  • PipPipPip
  • 514 posts
Hey guys recently i got my new ibm thinkpad laptop its vista business

The other day windows firewall popped up telling me it was blocking a incoming ip ever since that my laptop has been going slow

02/09/2010 19:48:05
mbam-log-2010-09-02 (19-48-05).txt

Scan type: Quick scan
Objects scanned: 142300
Time elapsed: 12 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OTL logfile created on: 02/09/2010 19:33:30 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\LENOVO\Desktop
Windows Vista Business Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 41.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 126.10 Gb Total Space | 79.05 Gb Free Space | 62.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Q: | 21.49 Gb Total Space | 15.98 Gb Free Space | 74.38% Space Free | Partition Type: NTFS
Drive S: | 1.46 Gb Total Space | 0.69 Gb Free Space | 47.08% Space Free | Partition Type: NTFS

Computer Name: LENOVO-PC
Current User Name: LENOVO
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\LENOVO\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\LENOVO\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1158612.exe (Adobe Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Users\LENOVO\Desktop\New Folder\bot v2\MSN Bot Panel.exe ()
PRC - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
PRC - C:\Program Files\ManyCam 2.4\ManyCam.exe (ManyCam LLC)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe (Lenovo)
PRC - C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Windows\System32\ibmpmsvc.exe (Lenovo)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Client Security Solution\password_manager.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Client Security Solution\cssauth.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe (Lenovo)
PRC - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Windows\System32\TpShocks.exe (Lenovo.)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Windows\System32\TPHDEXLG.exe (Lenovo.)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\ShortKeys2\shortkey.exe (Insight Software Solutions)
PRC - C:\Windows\System32\DTS.exe ()
PRC - C:\Windows\System32\AtService.exe (AuthenTec, Inc.)
PRC - C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10a.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe ()
PRC - C:\Windows\System32\PING.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\DDNI\SBITS\DDNIOEMService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )


========== Modules (SafeList) ==========

MOD - C:\Users\LENOVO\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\System32\networkexplorer.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (AcSvc) -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo)
SRV - (AcPrfMgrSvc) -- C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo)
SRV - (Power Manager DBC Service) -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE (Lenovo)
SRV - (TPHKSVC) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) -- C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (IBMPMSVC) -- C:\Windows\System32\ibmpmsvc.exe (Lenovo)
SRV - (TSSCoreService) -- C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe (Lenovo)
SRV - (ThinkVantage Registry Monitor Service) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (TPHDEXLGSVC) -- C:\Windows\System32\TPHDEXLG.exe (Lenovo.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (dtsvc) -- C:\Windows\System32\DTS.exe ()
SRV - (ADMonitor) -- C:\Windows\System32\ADMonitor.exe ()
SRV - (ATService) -- C:\Windows\System32\AtService.exe (AuthenTec, Inc.)
SRV - (TVT_UpdateMonitor) -- C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe (Lenovo Group Limited)
SRV - (TVT Scheduler) -- C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (TVT Backup Service) -- C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe (Lenovo Group Limited)
SRV - (TVT Backup Protection Service) -- C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe ()
SRV - (RoxMediaDB10) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (DDNIOEMService) -- C:\Program Files\DDNI\SBITS\DDNIOEMService.exe (Digital Delivery Networks, Inc.)
SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (vmm) -- C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (tvtfilter) -- C:\Windows\System32\drivers\tvtfilter.sys (Lenovo)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (fssfltr) -- C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (TPPWRIF) -- C:\Windows\System32\drivers\TPPWR32V.SYS (Lenovo Group Limited)
DRV - (IBMPMDRV) -- C:\Windows\System32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (MUXP) -- C:\Windows\System32\drivers\mux.sys (Intel© Corporation)
DRV - (MUXMP) -- C:\Windows\System32\drivers\mux.sys (Intel© Corporation)
DRV - (NETw5v32) Intel® -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (Shockprf) -- C:\Windows\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) -- C:\Windows\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (ATSwpWDF) -- C:\Windows\System32\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV - (psadd) -- C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (e1yexpress) Intel® -- C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (tvtumon) -- C:\Windows\System32\drivers\tvtumon.sys (Lenovo)
DRV - (intelkmd) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (lenovo.smi) -- C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (WimFltr) -- C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (HECI) Intel® -- C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (TVTI2C) -- C:\Windows\System32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ManyCam) -- C:\Windows\System32\drivers\ManyCam.sys (ManyCam LLC.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (DLADResM) -- C:\Windows\System32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) -- C:\Windows\System32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDFAM) -- C:\Windows\System32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAUDF_M) -- C:\Windows\System32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAOPIOM) -- C:\Windows\System32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) -- C:\Windows\System32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) -- C:\Windows\System32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) -- C:\Windows\System32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DRVMCDB) -- C:\Windows\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM) -- C:\Windows\System32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLARTL_M) -- C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) -- C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (VPCNetS2) -- C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0...S01?FORM=TOOLBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo)
O4 - HKLM..\Run: [ACWlIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BTVLOGEX.DLL ()
O4 - HKLM..\Run: [CreateLMBCShortCut] C:\Program Files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe ()
O4 - HKLM..\Run: [cssauth] C:\Program Files\Lenovo\Client Security Solution\cssauth.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (AuthenTec)
O4 - HKLM..\Run: [LENOVO.TPFNF6R] C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [LPMailChecker] C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [LPManager] C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TpShocks] C:\Windows\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam 2.4\ManyCam.exe (ManyCam LLC)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys 2.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\SWTOOLS\Wallpaper\1600x1200-Thinkdots.jpg
O24 - Desktop BackupWallPaper: C:\SWTOOLS\Wallpaper\1600x1200-Thinkdots.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/06/10 17:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O32 - AutoRun File - [2008/06/02 23:46:54 | 000,000,049 | -HS- | M] () - S:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{4a81fea3-a096-11df-9871-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{4a81fea3-a096-11df-9871-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2008/07/21 17:09:40 | 000,262,144 | -HS- | M] (Lenovo Group Limited)
O33 - MountPoints2\{b876d564-a08e-11df-924e-b752416b2d89}\Shell - "" = AutoRun
O33 - MountPoints2\{b876d564-a08e-11df-924e-b752416b2d89}\Shell\AutoRun\command - "" = S:\LenovoSDrive.exe -- [2008/07/29 23:37:58 | 000,180,224 | -HS- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/09/02 19:31:31 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\LENOVO\Desktop\OTL.exe
[2010/09/02 15:18:08 | 000,679,936 | ---- | C] (Generated by JEDI) -- C:\Windows\System32\D3DX81ab.dll
[2010/09/02 15:18:08 | 000,000,000 | ---D | C] -- C:\Program Files\Cheat Engine
[2010/09/02 14:29:05 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2010/09/02 14:28:29 | 000,000,000 | ---D | C] -- C:\Program Files\ManyCam 2.4
[2010/09/02 14:28:29 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\ManyCam
[2010/09/02 14:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2010/09/02 12:15:09 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Desktop\Shortkeys folder
[2010/09/02 01:58:39 | 000,065,536 | ---- | C] ( ) -- C:\Users\LENOVO\Desktop\Interop.MessengerAPI.dll
[2010/09/02 01:47:45 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Desktop\ShadowNL's Msn Freezer 1.0
[2010/09/02 01:16:51 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\Malwarebytes
[2010/09/02 01:15:28 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/09/02 01:15:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/09/02 01:15:26 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/09/02 01:15:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/02 00:10:49 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Documents\My Chat Logs
[2010/09/02 00:05:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Messenger Plus!
[2010/09/02 00:04:50 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger Plus! Live
[2010/09/01 23:55:00 | 000,000,000 | ---D | C] -- C:\Program Files\QS
[2010/09/01 23:54:58 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\TeamViewer
[2010/09/01 23:41:29 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Desktop\New Folder
[2010/09/01 23:30:23 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Desktop\bot v2
[2010/08/30 00:41:47 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\Apple Computer
[2010/08/30 00:41:47 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Apple Computer
[2010/08/30 00:40:20 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/08/30 00:40:17 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/08/30 00:40:17 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/08/30 00:38:31 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/08/30 00:38:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010/08/30 00:37:59 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Apple
[2010/08/30 00:37:44 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/08/30 00:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/08/30 00:34:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010/08/30 00:34:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/08/27 15:11:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010/08/27 15:11:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/08/27 15:10:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/08/27 15:08:32 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Microsoft Help
[2010/08/27 15:08:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010/08/27 15:08:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2010/08/27 15:07:40 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/08/26 19:07:32 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Adobe
[2010/08/26 18:30:55 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Google
[2010/08/26 18:30:42 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Deployment
[2010/08/26 18:30:42 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Apps
[2010/08/26 14:33:54 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/08/26 00:25:24 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Roblox
[2010/08/25 23:14:51 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Documents\My Virtual Machines
[2010/08/25 23:14:13 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\WinRAR
[2010/08/25 22:43:29 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010/08/25 19:54:10 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Insight Software Solutions
[2010/08/25 19:54:10 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Insight Software
[2010/08/25 19:54:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Insight Software
[2010/08/25 19:54:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Insight Software Solutions
[2010/08/25 19:54:06 | 000,000,000 | ---D | C] -- C:\Program Files\ShortKeys2
[2010/08/25 19:04:25 | 000,000,000 | ---D | C] -- C:\Windows\System32\Adobe
[2010/08/25 18:58:00 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Documents\My Received Files
[2010/08/25 18:49:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Virtual PC
[2010/08/25 18:34:05 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Tracing
[2010/08/25 18:32:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/08/25 18:32:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2010/08/25 18:31:51 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Documents\Insight Software
[2010/08/25 18:30:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Insight Software Solutions
[2010/08/25 18:30:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2010/08/25 18:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2010/08/25 18:26:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/08/25 18:26:27 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010/08/25 18:26:21 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2010/08/25 18:26:04 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2010/08/25 18:25:52 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/08/25 18:20:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2010/08/25 17:07:19 | 000,017,744 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010/08/25 17:07:18 | 000,165,456 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010/08/25 17:07:18 | 000,046,672 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010/08/25 17:07:18 | 000,023,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010/08/25 17:07:17 | 000,050,256 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010/08/25 17:06:46 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\Windows\avastSS.scr
[2010/08/25 17:06:45 | 000,165,032 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2010/08/25 17:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010/08/25 17:06:38 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/08/25 17:00:47 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\Macromedia
[2010/08/25 17:00:42 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\Adobe
[2010/08/08 12:31:10 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\InterVideo
[2010/08/05 22:58:00 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Roxio
[2010/08/05 22:57:55 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\ATI
[2010/08/05 22:57:55 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\ATI
[2010/08/05 22:57:55 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2010/08/05 22:57:36 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\Lenovo
[2010/08/05 22:57:26 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Searches
[2010/08/05 22:57:20 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Roaming\Identities
[2010/08/05 22:57:18 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Contacts
[2010/08/05 22:55:25 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live Toolbar
[2010/08/05 22:52:56 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\VirtualStore
[2010/08/05 22:50:51 | 000,000,000 | --SD | C] -- C:\Users\LENOVO\AppData\Roaming\Microsoft
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Videos
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Saved Games
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Pictures
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Music
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Links
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Favorites
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Downloads
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Documents
[2010/08/05 22:50:51 | 000,000,000 | R--D | C] -- C:\Users\LENOVO\Desktop
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\AppData\Local\Temporary Internet Files
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Templates
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Start Menu
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\SendTo
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Recent
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\PrintHood
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\NetHood
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Documents\My Videos
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Documents\My Pictures
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Documents\My Music
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\My Documents
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Local Settings
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\AppData\Local\History
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Cookies
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\Application Data
[2010/08/05 22:50:51 | 000,000,000 | -HSD | C] -- C:\Users\LENOVO\AppData\Local\Application Data
[2010/08/05 22:50:51 | 000,000,000 | -H-D | C] -- C:\Users\LENOVO\AppData
[2010/08/05 22:50:51 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Temp
[2010/08/05 22:50:51 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\Roaming
[2010/08/05 22:50:51 | 000,000,000 | ---D | C] -- C:\Users\LENOVO\AppData\Local\Microsoft
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\zh-TW
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\zh-HK
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\zh-CN
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\uk-UA
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\tr-TR
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\th-TH
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\sv-SE
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\sr-Latn-CS
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\sl-SI
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\sk-SK
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\ru-RU
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\ro-RO
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\pt-PT
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\pt-BR
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\pl-PL
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\nl-NL
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\nb-NO
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\lv-LV
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\lt-LT
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\ko-KR
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\ja-JP
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\it-IT
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\hu-HU
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\hr-HR
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\he-IL
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\fr-FR
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\fi-FI
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\et-EE
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\es-ES
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\el-GR
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\de-DE
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\da-DK
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\cs-CZ
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\bg-BG
[2010/08/05 15:15:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\ar-SA
[2010/08/05 15:13:41 | 000,000,000 | ---D | C] -- C:\ProgramData\DDNI
[2010/08/05 15:13:41 | 000,000,000 | ---D | C] -- C:\Program Files\DDNI
[2010/08/05 15:12:34 | 000,000,000 | ---D | C] -- C:\Program Files\Digital Line Detect
[2010/08/05 15:12:30 | 000,000,000 | ---D | C] -- C:\Program Files\NetWaiting
[2010/08/05 15:10:36 | 000,000,000 | RHSD | C] -- C:\RRbackups
[2010/08/05 15:07:54 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2010/08/05 15:07:48 | 000,000,000 | ---D | C] -- C:\Program Files\Verizon Wireless
[2010/08/05 15:07:29 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows
[2010/08/05 15:07:27 | 000,000,000 | ---D | C] -- C:\ProgramData\PCDr
[2010/08/05 15:07:15 | 000,000,000 | ---D | C] -- C:\Program Files\PCDR5
[2010/08/05 15:05:51 | 000,000,000 | ---D | C] -- C:\AuthLog
[2010/08/05 15:04:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Lenovo
[2010/08/05 15:01:12 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/08/05 15:01:10 | 000,051,768 | ---- | C] (Roxio) -- C:\Windows\System32\drivers\DRVNDDM.SYS
[2010/08/05 15:01:10 | 000,028,120 | ---- | C] (Roxio) -- C:\Windows\System32\drivers\DLARTL_M.SYS
[2010/08/05 15:01:10 | 000,012,856 | ---- | C] (Roxio) -- C:\Windows\System32\drivers\DLACDBHM.SYS
[2010/08/05 15:01:10 | 000,000,000 | ---D | C] -- C:\Program Files\Sonic Icons for Lenovo
[2010/08/05 15:01:09 | 000,092,920 | ---- | C] (Roxio) -- C:\Windows\DLA.EXE
[2010/08/05 15:01:09 | 000,000,000 | ---D | C] -- C:\Windows\System32\DLA
[2010/08/05 15:01:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Uninstall
[2010/08/05 15:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield
[2010/08/05 15:00:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sonic
[2010/08/05 14:59:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Roxio
[2010/08/05 14:59:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SureThing Shared
[2010/08/05 14:59:42 | 000,000,000 | ---D | C] -- C:\Program Files\Roxio
[2010/08/05 14:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sonic Shared
[2010/08/05 14:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2010/08/05 14:59:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Roxio Shared
[2010/08/05 14:59:07 | 000,000,000 | ---D | C] -- C:\Icons
[2010/08/05 14:58:58 | 000,000,000 | ---D | C] -- C:\Program Files\InterVideo
[2010/08/05 14:57:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InterVideo
[2010/08/05 14:57:04 | 000,000,000 | ---D | C] -- C:\Program Files\Lenovo Registration
[2010/08/05 14:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Lenovo
[2010/08/05 14:56:57 | 000,000,000 | ---D | C] -- C:\Program Files\ThinkVantage
[2010/08/05 14:56:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010/08/05 14:56:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010/08/05 14:56:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/08/05 14:56:33 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/08/05 14:56:12 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2010/08/05 14:56:00 | 001,256,116 | ---- | C] (Multidmedia Limited) -- C:\Windows\System32\Think Screensaver.scr
[2010/08/05 14:55:47 | 000,000,000 | ---D | C] -- C:\Program Files\Lenovo Group Limited
[2010/08/05 14:55:15 | 000,000,000 | ---D | C] -- C:\Program Files\Lenovo Fingerprint Software
[2010/08/05 14:49:48 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2010/08/05 14:49:47 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2010/08/05 14:49:38 | 000,258,048 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\System32\Oemdspif.dll
[2010/08/05 14:49:37 | 000,327,680 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\System32\atipdlxx.dll
[2010/08/05 14:49:37 | 000,043,520 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\System32\ati2edxx.dll
[2010/08/05 14:49:08 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2010/08/05 14:48:59 | 000,206,120 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\SynCtrl.dll
[2010/08/05 14:48:59 | 000,205,232 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\drivers\SynTP.sys
[2010/08/05 14:48:59 | 000,169,256 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\SynCOM.dll
[2010/08/05 14:48:59 | 000,161,064 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\SynTPAPI.dll
[2010/08/05 14:48:59 | 000,120,104 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\SynTPCo4.dll
[2010/08/05 14:48:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Roaming
[2010/08/05 14:47:57 | 000,073,264 | ---- | C] (Intel© Corporation) -- C:\Windows\System32\mux.dll
[2010/08/05 14:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco
[2010/08/05 14:47:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2010/08/05 14:47:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2010/08/05 14:47:02 | 000,000,000 | ---D | C] -- C:\Program Files\CONEXANT
[2010/08/05 14:45:47 | 000,000,000 | ---D | C] -- C:\Windows\System32\Lang
[2010/08/05 14:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2010/08/05 14:45:47 | 000,000,000 | ---D | C] -- C:\Intel
[2010/08/05 14:45:42 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2010/08/05 14:45:42 | 000,000,000 | ---D | C] -- C:\Program Files\ThinkPad
[2010/08/05 14:45:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010/08/05 14:44:35 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010/08/05 14:44:13 | 000,000,000 | ---D | C] -- C:\Program Files\Lenovo
[2010/08/05 14:43:56 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2010/08/05 14:39:46 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010/08/05 14:38:21 | 000,000,000 | ---D | C] -- C:\Windows\CSC
[2010/08/05 14:19:54 | 000,000,000 | ---D | C] -- C:\Windows\Users
[2010/08/05 14:19:13 | 000,000,000 | ---D | C] -- C:\DRIVERS
[2010/08/05 14:18:59 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010/08/05 14:13:08 | 000,000,000 | ---D | C] -- C:\SWShare

========== Files - Modified Within 90 Days ==========

[2010/09/02 19:37:30 | 001,835,008 | -HS- | M] () -- C:\Users\LENOVO\NTUSER.DAT
[2010/09/02 19:35:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000UA.job
[2010/09/02 19:31:45 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\LENOVO\Desktop\OTL.exe
[2010/09/02 19:22:06 | 000,008,472 | ---- | M] () -- C:\Users\LENOVO\Desktop\nypd master copy.xlsx
[2010/09/02 19:22:06 | 000,000,165 | -H-- | M] () -- C:\Users\LENOVO\Desktop\~$nypd master copy.xlsx
[2010/09/02 18:35:00 | 000,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000Core.job
[2010/09/02 18:04:31 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/02 18:04:31 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/02 17:22:43 | 000,009,371 | ---- | M] () -- C:\Users\LENOVO\Desktop\people attending meeting.xlsx
[2010/09/02 15:18:10 | 000,000,802 | ---- | M] () -- C:\Users\LENOVO\Desktop\Cheat Engine.lnk
[2010/09/02 14:30:12 | 000,001,724 | ---- | M] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam 2.4.lnk
[2010/09/02 14:30:12 | 000,001,700 | ---- | M] () -- C:\Users\LENOVO\Desktop\ManyCam 2.4.lnk
[2010/09/02 13:45:40 | 000,008,694 | ---- | M] () -- C:\Users\LENOVO\Desktop\Nypd Mentoring Scheme.xlsx
[2010/09/02 12:04:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/02 01:15:31 | 000,000,828 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/31 17:02:23 | 000,001,024 | ---- | M] () -- C:\Users\LENOVO\.rnd
[2010/08/31 17:01:53 | 000,000,080 | ---- | M] () -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys 2.lnk
[2010/08/31 17:00:00 | 000,524,288 | -HS- | M] () -- C:\Users\LENOVO\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
[2010/08/31 17:00:00 | 000,065,536 | -HS- | M] () -- C:\Users\LENOVO\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
[2010/08/31 16:59:44 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/31 16:59:23 | 2038,460,416 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/30 07:48:15 | 003,026,707 | -H-- | M] () -- C:\Users\LENOVO\AppData\Local\IconCache.db
[2010/08/30 00:41:19 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/08/30 00:38:46 | 000,001,736 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/08/29 23:37:07 | 000,008,642 | ---- | M] () -- C:\Users\LENOVO\Desktop\Image.jpg
[2010/08/29 23:15:34 | 000,001,732 | ---- | M] () -- C:\tvtpktfilter.dat
[2010/08/28 17:49:17 | 000,074,912 | ---- | M] () -- C:\Users\LENOVO\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/28 17:46:40 | 000,313,112 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/08/27 15:43:52 | 000,028,366 | ---- | M] () -- C:\Users\LENOVO\Desktop\Evaluation Questions.docx
[2010/08/27 12:36:19 | 000,007,728 | ---- | M] () -- C:\Users\LENOVO\AppData\Local\d3d9caps.dat
[2010/08/27 12:17:29 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/08/27 12:17:29 | 000,602,728 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/08/27 12:17:29 | 000,107,242 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/08/27 11:47:05 | 000,001,599 | ---- | M] () -- C:\Users\Public\Desktop\Browser Choice.lnk
[2010/08/26 19:55:41 | 000,003,525 | ---- | M] () -- C:\Users\Public\Documents\AcIpConfig.dat
[2010/08/26 19:55:40 | 002,786,196 | ---- | M] () -- C:\Users\Public\Documents\AccConnAdvanced.dat
[2010/08/26 19:55:40 | 000,027,482 | ---- | M] () -- C:\Users\Public\Documents\ACGinaWinlogon.dat
[2010/08/26 19:55:39 | 000,069,672 | ---- | M] () -- C:\Users\Public\Documents\AcSvc.dmp
[2010/08/26 18:31:42 | 000,002,057 | ---- | M] () -- C:\Users\LENOVO\Desktop\Google Chrome.lnk
[2010/08/26 18:31:42 | 000,002,019 | ---- | M] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/26 14:27:35 | 000,000,953 | ---- | M] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/25 23:02:10 | 000,001,610 | ---- | M] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2010/08/25 19:54:10 | 000,000,846 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys 2.lnk
[2010/08/25 19:31:35 | 000,002,560 | ---- | M] () -- C:\Windows\_MSRSTRT.EXE
[2010/08/25 17:07:19 | 000,001,850 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/08/25 17:07:17 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2010/08/08 12:30:48 | 000,000,948 | ---- | M] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/08/05 23:03:15 | 000,524,288 | -HS- | M] () -- C:\Users\LENOVO\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000002.regtrans-ms
[2010/08/05 23:00:13 | 000,000,959 | ---- | M] () -- C:\Users\LENOVO\Desktop\Internet Explorer.lnk
[2010/08/05 22:59:09 | 000,001,947 | ---- | M] () -- C:\Users\LENOVO\Desktop\Mobile Broadband.lnk
[2010/08/05 22:56:09 | 000,000,100 | ---- | M] () -- C:\Windows\System32\drivers\Lenovo_6475_WRB.MRK
[2010/08/05 22:56:05 | 000,000,010 | ---- | M] () -- C:\Windows\System32\firstboot.lgl
[2010/08/05 22:50:51 | 000,000,020 | -HS- | M] () -- C:\Users\LENOVO\ntuser.ini
[2010/08/05 15:53:59 | 000,038,372 | ---- | M] () -- C:\Windows\System32\license.rtf
[2010/08/05 15:20:01 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2010/08/05 15:13:38 | 000,000,992 | ---- | M] () -- C:\Users\Public\Desktop\Lenovo Welcome.lnk
[2010/08/05 15:12:34 | 000,001,756 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2010/08/05 15:11:01 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\AccConnAdvanced.html
[2010/08/05 15:10:21 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2010/08/05 15:04:25 | 053,149,696 | ---- | M] () -- C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2010/08/05 15:04:19 | 000,196,608 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.perf
[2010/08/05 15:04:19 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
[2010/08/05 15:01:10 | 000,000,120 | ---- | M] () -- C:\Windows\wininit.ini
[2010/08/05 14:57:04 | 000,001,803 | ---- | M] () -- C:\Users\Public\Desktop\Lenovo Registration.lnk
[2010/08/05 14:56:58 | 000,001,791 | ---- | M] () -- C:\Users\Public\Desktop\ThinkVantage Productivity Center.lnk
[2010/08/05 14:56:53 | 000,000,884 | ---- | M] () -- C:\Users\Public\Desktop\Acrobat.com.lnk
[2010/08/05 14:56:36 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/05 14:55:20 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ATSwpWDF_01005.Wdf
[2010/08/05 14:54:52 | 000,085,724 | ---- | M] () -- C:\Windows\System32\log.xml
[2010/08/05 14:49:12 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01007.Wdf
[2010/08/05 14:25:02 | 000,009,127 | ---- | M] () -- C:\Windows\System32\RacUR.xml
[2010/08/05 14:25:02 | 000,000,153 | ---- | M] () -- C:\Windows\System32\RacUREx.xml
[2010/08/05 14:22:37 | 011,967,524 | ---- | M] () -- C:\Windows\System32\korwbrkr.lex
[2010/08/05 14:22:37 | 000,106,605 | ---- | M] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/08/05 14:22:37 | 000,018,904 | ---- | M] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/08/02 11:21:36 | 000,778,240 | ---- | M] () -- C:\Users\LENOVO\Desktop\Brians Msn Premium v0.1.exe
[2010/07/26 13:47:53 | 000,065,536 | ---- | M] ( ) -- C:\Users\LENOVO\Desktop\Interop.MessengerAPI.dll
[2010/06/28 21:57:33 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\Windows\avastSS.scr
[2010/06/28 21:57:12 | 000,165,032 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2010/06/28 21:37:52 | 000,046,672 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010/06/28 21:37:30 | 000,165,456 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010/06/28 21:33:13 | 000,023,376 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010/06/28 21:32:56 | 000,050,256 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010/06/28 21:32:33 | 000,017,744 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys

========== Files Created - No Company Name ==========

[2010/09/02 19:22:06 | 000,000,165 | -H-- | C] () -- C:\Users\LENOVO\Desktop\~$nypd master copy.xlsx
[2010/09/02 19:22:05 | 000,008,472 | ---- | C] () -- C:\Users\LENOVO\Desktop\nypd master copy.xlsx
[2010/09/02 15:18:10 | 000,000,802 | ---- | C] () -- C:\Users\LENOVO\Desktop\Cheat Engine.lnk
[2010/09/02 15:18:08 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2010/09/02 14:30:12 | 000,001,724 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam 2.4.lnk
[2010/09/02 14:30:12 | 000,001,700 | ---- | C] () -- C:\Users\LENOVO\Desktop\ManyCam 2.4.lnk
[2010/09/02 13:45:39 | 000,008,694 | ---- | C] () -- C:\Users\LENOVO\Desktop\Nypd Mentoring Scheme.xlsx
[2010/09/02 01:58:39 | 000,778,240 | ---- | C] () -- C:\Users\LENOVO\Desktop\Brians Msn Premium v0.1.exe
[2010/09/02 01:58:36 | 000,094,208 | ---- | C] () -- C:\Users\LENOVO\Desktop\Stub.exe
[2010/09/02 01:15:31 | 000,000,828 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/01 16:31:58 | 000,009,371 | ---- | C] () -- C:\Users\LENOVO\Desktop\people attending meeting.xlsx
[2010/08/30 00:41:19 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/08/30 00:38:46 | 000,001,736 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/08/29 23:37:06 | 000,008,642 | ---- | C] () -- C:\Users\LENOVO\Desktop\Image.jpg
[2010/08/29 23:15:34 | 000,001,732 | ---- | C] () -- C:\tvtpktfilter.dat
[2010/08/27 15:18:30 | 000,028,366 | ---- | C] () -- C:\Users\LENOVO\Desktop\Evaluation Questions.docx
[2010/08/27 11:47:05 | 000,001,599 | ---- | C] () -- C:\Users\Public\Desktop\Browser Choice.lnk
[2010/08/26 19:55:40 | 000,027,482 | ---- | C] () -- C:\Users\Public\Documents\ACGinaWinlogon.dat
[2010/08/26 19:55:40 | 000,003,525 | ---- | C] () -- C:\Users\Public\Documents\AcIpConfig.dat
[2010/08/26 19:55:39 | 002,786,196 | ---- | C] () -- C:\Users\Public\Documents\AccConnAdvanced.dat
[2010/08/26 19:55:33 | 000,069,672 | ---- | C] () -- C:\Users\Public\Documents\AcSvc.dmp
[2010/08/26 18:31:42 | 000,002,057 | ---- | C] () -- C:\Users\LENOVO\Desktop\Google Chrome.lnk
[2010/08/26 18:31:42 | 000,002,019 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/26 18:30:58 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000UA.job
[2010/08/26 18:30:57 | 000,000,858 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000Core.job
[2010/08/26 14:28:28 | 000,001,024 | ---- | C] () -- C:\Users\LENOVO\.rnd
[2010/08/26 14:27:44 | 000,007,728 | ---- | C] () -- C:\Users\LENOVO\AppData\Local\d3d9caps.dat
[2010/08/25 23:02:10 | 000,001,610 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2010/08/25 21:44:21 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010/08/25 20:05:17 | 000,000,080 | ---- | C] () -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys 2.lnk
[2010/08/25 19:54:10 | 000,000,846 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys 2.lnk
[2010/08/25 19:31:34 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010/08/25 17:53:21 | 002,501,921 | ---- | C] () -- C:\Windows\System32\wlan.tmf
[2010/08/25 17:07:19 | 000,001,850 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/08/08 12:30:48 | 000,000,948 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/08/07 14:59:41 | 000,000,953 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/05 23:00:13 | 000,000,959 | ---- | C] () -- C:\Users\LENOVO\Desktop\Internet Explorer.lnk
[2010/08/05 22:59:02 | 000,605,056 | ---- | C] () -- C:\Users\LENOVO\AppData\Local\wanancsp.dat
[2010/08/05 22:57:38 | 000,001,947 | ---- | C] () -- C:\Users\LENOVO\Desktop\Mobile Broadband.lnk
[2010/08/05 22:56:05 | 000,000,010 | ---- | C] () -- C:\Windows\System32\firstboot.lgl
[2010/08/05 22:50:51 | 001,835,008 | -HS- | C] () -- C:\Users\LENOVO\NTUSER.DAT
[2010/08/05 22:50:51 | 000,524,288 | -HS- | C] () -- C:\Users\LENOVO\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000002.regtrans-ms
[2010/08/05 22:50:51 | 000,524,288 | -HS- | C] () -- C:\Users\LENOVO\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
[2010/08/05 22:50:51 | 000,262,144 | -H-- | C] () -- C:\Users\LENOVO\ntuser.dat.LOG1
[2010/08/05 22:50:51 | 000,065,536 | -HS- | C] () -- C:\Users\LENOVO\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
[2010/08/05 22:50:51 | 000,000,258 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/08/05 22:50:51 | 000,000,240 | ---- | C] () -- C:\Users\LENOVO\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/08/05 22:50:51 | 000,000,020 | -HS- | C] () -- C:\Users\LENOVO\ntuser.ini
[2010/08/05 22:50:51 | 000,000,000 | -H-- | C] () -- C:\Users\LENOVO\ntuser.dat.LOG2
[2010/08/05 15:20:01 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/08/05 15:13:38 | 000,000,992 | ---- | C] () -- C:\Users\Public\Desktop\Lenovo Welcome.lnk
[2010/08/05 15:12:34 | 000,001,756 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2010/08/05 15:11:06 | 000,146,036 | ---- | C] () -- C:\Windows\System32\drivers\HSFProf.cty
[2010/08/05 15:11:01 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\AccConnAdvanced.html
[2010/08/05 15:07:39 | 000,000,436 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2010/08/05 15:01:22 | 053,149,696 | ---- | C] () -- C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2010/08/05 15:01:22 | 000,196,608 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.perf
[2010/08/05 15:01:22 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
[2010/08/05 15:01:10 | 000,056,056 | ---- | C] () -- C:\Windows\System32\DLAAPI_W.DLL
[2010/08/05 15:01:09 | 000,000,120 | ---- | C] () -- C:\Windows\wininit.ini
[2010/08/05 14:59:00 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2010/08/05 14:59:00 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2010/08/05 14:59:00 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2010/08/05 14:59:00 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2010/08/05 14:59:00 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2010/08/05 14:59:00 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2010/08/05 14:57:04 | 000,001,803 | ---- | C] () -- C:\Users\Public\Desktop\Lenovo Registration.lnk
[2010/08/05 14:57:03 | 000,009,679 | ---- | C] () -- C:\Windows\System32\msxml4r.cat
[2010/08/05 14:57:03 | 000,003,489 | ---- | C] () -- C:\Windows\System32\msxml4.Manifest
[2010/08/05 14:57:03 | 000,000,500 | ---- | C] () -- C:\Windows\System32\msxml4r.Manifest
[2010/08/05 14:57:02 | 000,009,675 | ---- | C] () -- C:\Windows\System32\msxml4.cat
[2010/08/05 14:56:58 | 000,001,791 | ---- | C] () -- C:\Users\Public\Desktop\ThinkVantage Productivity Center.lnk
[2010/08/05 14:56:53 | 000,000,884 | ---- | C] () -- C:\Users\Public\Desktop\Acrobat.com.lnk
[2010/08/05 14:56:36 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/05 14:55:20 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ATSwpWDF_01005.Wdf
[2010/08/05 14:54:52 | 000,085,724 | ---- | C] () -- C:\Windows\System32\log.xml
[2010/08/05 14:49:40 | 002,192,024 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
[2010/08/05 14:49:40 | 000,034,512 | ---- | C] () -- C:\Windows\System32\iglhxs32.vp
[2010/08/05 14:49:40 | 000,002,096 | ---- | C] () -- C:\Windows\System32\iglhxo32.vp
[2010/08/05 14:49:40 | 000,002,096 | ---- | C] () -- C:\Windows\System32\iglhxc32.vp
[2010/08/05 14:49:38 | 000,492,496 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
[2010/08/05 14:49:38 | 000,328,162 | ---- | C] () -- C:\Windows\System32\drivers\ativcaxx.cpa
[2010/08/05 14:49:38 | 000,147,172 | ---- | C] () -- C:\Windows\System32\igfcg550.bin
[2010/08/05 14:49:38 | 000,052,400 | ---- | C] () -- C:\Windows\System32\drivers\ativvpxx.vp
[2010/08/05 14:49:38 | 000,002,096 | ---- | C] () -- C:\Windows\System32\drivers\ativpkxx.vp
[2010/08/05 14:49:38 | 000,002,096 | ---- | C] () -- C:\Windows\System32\drivers\ativokxx.vp
[2010/08/05 14:49:38 | 000,002,096 | ---- | C] () -- C:\Windows\System32\drivers\ativdkxx.vp
[2010/08/05 14:49:38 | 000,000,929 | ---- | C] () -- C:\Windows\System32\drivers\ativcaxx.vp
[2010/08/05 14:49:37 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2010/08/05 14:49:37 | 000,174,820 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010/08/05 14:49:37 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2010/08/05 14:49:37 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2010/08/05 14:49:37 | 000,014,138 | ---- | C] () -- C:\Windows\atiogl.xml
[2010/08/05 14:49:37 | 000,003,568 | ---- | C] () -- C:\Windows\System32\atiumdva.cap
[2010/08/05 14:49:37 | 000,000,466 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010/08/05 14:49:12 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01007.Wdf
[2010/08/05 14:45:30 | 000,000,100 | ---- | C] () -- C:\Windows\System32\drivers\Lenovo_6475_WRB.MRK
[2010/08/05 14:42:19 | 2038,460,416 | -HS- | C] () -- C:\hiberfil.sys
[2010/08/05 14:25:02 | 000,009,127 | ---- | C] () -- C:\Windows\System32\RacUR.xml
[2010/08/05 14:25:02 | 000,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml
[2010/08/05 14:22:37 | 011,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2010/08/05 14:22:37 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/08/05 14:22:37 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/08/05 14:19:26 | 000,002,722 | ---- | C] () -- C:\Windows\System32\e1y6032.din
[2010/08/05 14:19:13 | 000,016,896 | ---- | C] () -- C:\Windows\Eventclr.exe
[2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/08/08 12:31:10 | 000,000,000 | ---D | M] -- C:\Users\LENOVO\AppData\Roaming\InterVideo
[2010/08/05 22:58:01 | 000,000,000 | ---D | M] -- C:\Users\LENOVO\AppData\Roaming\Lenovo
[2010/09/02 14:32:10 | 000,000,000 | ---D | M] -- C:\Users\LENOVO\AppData\Roaming\ManyCam
[2010/09/01 23:54:58 | 000,000,000 | ---D | M] -- C:\Users\LENOVO\AppData\Roaming\TeamViewer
[2010/08/05 15:10:21 | 000,000,436 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2010/08/31 09:58:42 | 000,017,362 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2006/09/18 22:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/08/31 16:59:23 | 2038,460,416 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/31 16:59:19 | 2352,226,304 | -HS- | M] () -- C:\pagefile.sys
[2010/08/05 14:46:34 | 000,000,086 | ---- | M] () -- C:\setup.log
[2010/08/05 15:16:39 | 000,001,072 | ---- | M] () -- C:\sysiclog.txt
[2010/08/29 23:15:34 | 000,001,732 | ---- | M] () -- C:\tvtpktfilter.dat

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:19 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:19 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:19 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 13:37:19 | 000,030,808 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:36:30 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/06/28 21:57:33 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\Windows\avastSS.scr
[2010/04/17 00:04:40 | 000,306,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:58 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 04:20:25 | 017,223,680 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:20:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:20:25 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2007/09/19 23:41:12 | 000,004,096 | ---- | M] () -- C:\Windows\System32\Thumbs.db

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/26 14:27:35 | 000,000,352 | -HS- | M] () -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/08/02 11:21:36 | 000,778,240 | ---- | M] () -- C:\Users\LENOVO\Desktop\Brians Msn Premium v0.1.exe
[2010/09/02 19:31:45 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\LENOVO\Desktop\OTL.exe
[2010/05/20 17:11:10 | 000,094,208 | ---- | M] () -- C:\Users\LENOVO\Desktop\Stub.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2006/11/02 13:36:17 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/08/05 22:57:26 | 000,000,402 | -HS- | M] () -- C:\Users\LENOVO\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-01 14:14:07
< End of report >



OTL Extras logfile created on: 02/09/2010 19:33:30 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\LENOVO\Desktop
Windows Vista Business Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 41.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 126.10 Gb Total Space | 79.05 Gb Free Space | 62.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Q: | 21.49 Gb Total Space | 15.98 Gb Free Space | 74.38% Space Free | Partition Type: NTFS
Drive S: | 1.46 Gb Total Space | 0.69 Gb Free Space | 47.08% Space Free | Partition Type: NTFS

Computer Name: LENOVO-PC
Current User Name: LENOVO
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{96871178-11DA-4D99-BED8-5B8908D7E0B0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BDF0DFDC-FB14-4B76-9BC9-11479FD3491D}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{27117410-1363-4612-A06C-757EB5D178AE}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{2A77DFFA-B23B-4E4F-8933-105BC90D5CF3}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2C62E312-1007-43E1-9A5B-4D7F64CDCFFC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{343FB819-FC15-4E93-8913-71A6A61E5401}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{61FAC299-C882-4C2C-958E-B68C0B641AA2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{77552DD5-8E79-4653-95F7-9E26A27A50BA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{86DD0301-BC92-469D-891D-6E88E219442E}" = protocol=17 | dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{9A8E0563-416F-4A65-8D37-CD399D8CBE90}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{BDE10E61-1428-4596-89A5-CB9D0013435A}" = protocol=6 | dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{E7A69F0A-86BC-406E-B399-8798CA1DBB07}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{F73950FE-E876-44F3-BBF1-19B06098C83E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"TCP Query User{F26B82D2-F736-4A06-A803-563D789CF147}C:\users\lenovo\desktop\mess-mania v8.0\mess-mania v8.0.exe" = protocol=6 | dir=in | app=c:\users\lenovo\desktop\mess-mania v8.0\mess-mania v8.0.exe |
"UDP Query User{F157B8A8-6B39-447F-A253-EDECE4F0E195}C:\users\lenovo\desktop\mess-mania v8.0\mess-mania v8.0.exe" = protocol=17 | dir=in | app=c:\users\lenovo\desktop\mess-mania v8.0\mess-mania v8.0.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}" = RICOH R5U230 Media Driver ver.2.02.02.01
"{052E244C-3674-8907-D9C3-092C89521B94}" = Catalyst Control Center Localization Korean
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{09A84D86-C709-4825-9548-ACF4838D478D}" = Intel® PROSet/Wireless WiFi Software
"{0C7DE40E-7C89-4AFB-B744-846F1B582B71}" = SBITS
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{10F90FAD-6627-7113-86AE-C243C74F0DEF}" = CCC Help German
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad EasyEject Utility
"{1433371A-F983-9562-3947-92420A72849D}" = Catalyst Control Center Graphics Previews Vista
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22266E88-29AF-8D27-F85F-DD75D76E4AE2}" = Catalyst Control Center Localization German
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23146B80-2B64-023D-0696-A753E5C45FB4}" = Catalyst Control Center Graphics Full Existing
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2BD2FA21-B51D-4F01-94A7-AC16737B2163}" = Adobe Flash Player 10 ActiveX
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Drag-to-Disc
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3752F72E-A481-41C7-256B-C20D7BFBE3BC}" = CCC Help English
"{3D8994A3-02A8-45B5-B955-53E608BC69ED}" = Lenovo Fingerprint Software
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{3F963A06-7C18-4039-9789-9644B3266AE7}" = Verizon Wireless BroadbandAccess Self Activation
"{433894BE-54BF-CC72-2147-14EA837ADC87}" = CCC Help Portuguese
"{44E9D4C2-946C-4378-9354-558803C47A68}" = Client Security - Password Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4AB5764A-3894-49A2-BAA8-C4665F74CD4C}" = Registry patch to improve USB device detection on resume from sleep for Windows Vista
"{4BD295B9-0190-4C54-B08E-33A6ECA922DF}" = ThinkVantage Access Connections
"{52F58309-1687-0C82-699A-27D9029B9429}" = CCC Help Spanish
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business Edition
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.02
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65706020-7B6F-41F2-8047-FC69579E386A}" = Presentation Director
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6ADC5DFC-24AA-D4E1-478A-5CD6337F8051}" = Catalyst Control Center Localization Italian
"{6B00B854-F04B-5C6A-63C5-21B9EF8CE3CF}" = CCC Help French
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{771C80E2-7A02-D773-96C3-155F217CD02A}" = CCC Help Japanese
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B647582-EE62-8275-9D76-15692741C585}" = Catalyst Control Center Localization Chinese Traditional
"{7E4C16B8-8F76-4940-8505-98E93C00BF19}" = Rescue and Recovery
"{821456F8-EB18-41A8-DED5-695096B7D9D6}" = Catalyst Control Center Localization Chinese Standard
"{8220C00D-CBA1-AB41-1A66-7B99FAEF65F9}" = ATI Catalyst Install Manager
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007
"{8ACB5112-A58B-7283-B771-6271A0D9471D}" = Catalyst Control Center Core Implementation
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8EBBED54-C2D0-928A-7CA9-D28FAD39C4B6}" = CCC Help Korean
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90FABD40-E741-446F-839D-CEAE905D63BE}" = ThinkPad Mobility Center Customization
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{94B1AD86-8764-8853-F4BB-7F92D5E94AA3}" = Catalyst Control Center Graphics Full New
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{986F64DC-FF15-449D-998F-EE3BCEC6666A}" = Help Center
"{9B14495A-E66F-3D68-3B03-D40A6862D6D7}" = ccc-utility
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{9FCE66F0-EE03-43BD-916E-66EDF0DBC18C}" = Catalyst Control Center - Branding
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7EE37A9-367B-651F-9F4A-0BDE35D7417F}" = CCC Help Chinese Standard
"{ABC6E084-55EA-5860-4654-B21FFE886B1B}" = PX Profile Update
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AE2832A3-8108-F2BF-7086-BE66D29106E7}" = Catalyst Control Center Graphics Light
"{B05B22B8-72AE-4DC3-8D6F-FBC2233CAF41}" = Roxio Creator Business Edition
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B334D9AE-1393-423E-97C0-3BDC3360E692}" = Sonic Icons for Lenovo
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{BA0B7C1F-5315-50C4-1EE9-FFA688A28C74}" = Catalyst Control Center Localization Spanish
"{BAAC402D-86A7-3918-4A24-7C8E83AE1756}" = CCC Help Swedish
"{BBDD2E21-F74F-FE49-956D-13FB1999DC28}" = CCC Help Italian
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BF1ECD50-5A11-B18B-4AA0-20E41E7C20F7}" = Catalyst Control Center Localization Japanese
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{C710E77E-6AC2-608B-214C-CEF6B9CDBA6E}" = Catalyst Control Center InstallProxy
"{C7EE261A-06E9-402D-B504-9967F8FC6F0C}" = Mobile Broadband Connect
"{C945C17F-2E78-4511-ABB6-EF637D2EE8FB}" = Skins
"{CCCF9048-DAFD-F1F5-B860-9B5C32FBD2D6}" = Catalyst Control Center Localization Portuguese
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{D22E6706-136E-4810-AF2E-359AE30A7323}" = ThinkVantage Status Gadget
"{D728E945-256D-4477-B377-6BBA693714AC}" = Productivity Center Supplement for ThinkPad
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = ThinkPad Power Manager
"{DB71210F-8314-4AE3-B7A7-EBAF85BD30E9}" = Wallpapers
"{E2ACDD92-7A9F-FCE8-2452-8A660792038E}" = CCC Help Chinese Traditional
"{E4CB66D5-C29E-9612-5E32-6807E91A82CD}" = Catalyst Control Center Localization Swedish
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}" = Message Center
"{EA5AB32C-970E-D7C4-C896-1C927FB3E384}" = Catalyst Control Center Localization Dutch
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F9230D65-8EED-B6DD-F9FB-8AEFDE06579C}" = Catalyst Control Center Localization French
"{FA62B4C2-6CFD-462F-9B59-68A730001AB3}" = Product Recovery Disc Burning Utility
"{FAA034EC-DB6A-A753-5DCE-DD7D75EDEA8E}" = ccc-core-static
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FF878914-1DDC-44E2-92F6-69DE291DDCA7}" = CCC Help Dutch
"0A7603E3091C168CDE422A2B3481A2F7D17D0954" = Windows Driver Package - Intel hdc (02/20/2008 6.9.1.1001)
"25A4FC9EFE7A8860FCF6F86FFABDD9334A2619E3" = Windows Driver Package - Intel (e1yexpress) Net (08/22/2008 9.52.10.1001)
"3EB6CB625B5778835F0A66A7529E69050E0EE033" = Windows Driver Package - Lenovo 1.53 (03/19/2009 1.53)
"432D918ED17EA51B73E8491A0369730C0076A292" = Windows Driver Package - Intel System (02/20/2008 8.6.1.1002)
"464CE3922A214073AAEE00DEB23EA5C750AF8CE8" = Windows Driver Package - Intel USB (02/05/2007 8.3.0.1011)
"513C7D1BF4530B30EC84716327E4D7E76810DCC5" = Windows Driver Package - Intel System (02/20/2008 8.7.0.1007)
"5A4D4FF375E24E41AE5D2D907E67E0884BE2CAF4" = Windows Driver Package - Intel System (01/30/2008 8.6.1.1001)
"A4680BD43717441189C52EBF2C4FD6B182EE1101" = Windows Driver Package - AuthenTec Inc. (ATSwpWDF) Biometric (10/02/2008 8.1.2.37)
"Adobe AIR" = Adobe AIR
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Uninstaller" = ATI Uninstaller
"avast5" = avast! Free Antivirus
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = ThinkPad Modem Adapter
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dipmon" = Registry Patch of Enabling Device Initiated Power Management(DIPM) on SATA for Windows Vista
"E6CEFD9A59425A2A27E92572AB367B28C371D3D8" = Windows Driver Package - Intel System (09/15/2006 7.0.0.1011)
"EC1E678D1EFB79A1D02C312390944027C715CD5C" = Windows Driver Package - Intel (iaStor) hdc (02/11/2009 8.8.0.1009)
"FPIRPOn" = Registry patch of Changing Timing of IDLE IRP by Finger Print Driver for Windows Vista
"HECI" = Intel® Management Engine Interface
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Lenovo Registration" = Lenovo Registration
"Lenovo Welcome_is1" = Lenovo Welcome
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"ManyCam" = ManyCam 2.4 (remove only)
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"OnScreenDisplay" = On Screen Display
"PC-Doctor for Windows" = Lenovo System Toolbox
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"ShortKeys 2" = ShortKeys 2
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"USBPMon" = Registry patch for Windows Vista USB S3 PM Enablement
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = Roblox for LENOVO
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 02/09/2010 07:04:45 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 33644533

Error - 02/09/2010 07:04:47 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 02/09/2010 07:04:47 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 33645578

Error - 02/09/2010 07:04:47 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 33645578

Error - 02/09/2010 07:04:48 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 02/09/2010 07:04:48 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 33646732

Error - 02/09/2010 07:04:48 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 33646732

Error - 02/09/2010 07:04:49 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 02/09/2010 07:04:49 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 33647762

Error - 02/09/2010 07:04:49 | Computer Name = LENOVO-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 33647762

[ System Events ]
Error - 01/09/2010 10:00:29 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 01/09/2010 10:01:13 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7010
Description =

Error - 01/09/2010 21:44:35 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:03:45 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:04:42 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:05:21 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:05:53 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:06:23 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:06:53 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 02/09/2010 07:07:23 | Computer Name = LENOVO-PC | Source = Service Control Manager | ID = 7011
Description =


< End of report >
  • 0

Advertisements


#2
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello nortan360,

Please run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
    O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
    O3 - HKCU\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
    O4 - HKLM..\Run: [] File not found
    O33 - MountPoints2\{4a81fea3-a096-11df-9871-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{4a81fea3-a096-11df-9871-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2008/07/21 17:09:40 | 000,262,144 | -HS- | M] (Lenovo Group Limited)
    O33 - MountPoints2\{b876d564-a08e-11df-924e-b752416b2d89}\Shell - "" = AutoRun
    O33 - MountPoints2\{b876d564-a08e-11df-924e-b752416b2d89}\Shell\AutoRun\command - "" = S:\LenovoSDrive.exe -- [2008/07/29 23:37:58 | 000,180,224 | -HS- | M] ()
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    [2010/09/02 14:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
    
    :Commands
    [emptytemp]
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.
Next

Please download RKUnhooker and save it to your desktop.

Please note:

RKU does not run in Safe Mode.


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.

Close all open programs and browsers, then double-click RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning. Please click OK to continue:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

So when you return please post
  • OTL fix log
  • RootkitUnhooker report

  • 0

#3
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
Otl froze when it started the unhooker log is on its way

Could i also ask what 'PCdoctor' is i was looking through the logs and found that i havent installed this myself

Edited by nortan360, 09 September 2010 - 09:34 AM.

  • 0

#4
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6001 (Service Pack 1)
Number of processors #2
==============================================
>Drivers
==============================================
0x8C80D000 C:\Windows\system32\DRIVERS\igdkmd32.sys 7225344 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x8C203000 C:\Windows\system32\DRIVERS\atikmdag.sys 5898240 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver)
0x82619000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System)
0x82619000 PnpManager 3907584 bytes
0x82619000 RAW 3907584 bytes
0x82619000 WMIxWDM 3907584 bytes
0x8D004000 C:\Windows\system32\DRIVERS\NETw5v32.sys 3756032 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver)
0x9C080000 Win32k 2105344 bytes
0x9C080000 C:\Windows\System32\win32k.sys 2105344 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8840A000 C:\Windows\System32\Drivers\Ntfs.sys 1110016 bytes (Microsoft Corporation, NT File System Driver)
0x8360C000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x90208000 C:\Windows\system32\DRIVERS\HSX_DPV.sys 1056768 bytes (Conexant Systems, Inc., HSF_DP driver)
0x8820B000 C:\Windows\System32\drivers\tcpip.sys 954368 bytes (Microsoft Corporation, TCP/IP Driver)
0x804C5000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)
0xB1606000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x8831C000 C:\Windows\System32\Drivers\dump_iaStor.sys 897024 bytes
0x83403000 C:\Windows\system32\DRIVERS\iaStor.sys 897024 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0x9030A000 C:\Windows\system32\DRIVERS\HSX_CNXT.sys 741376 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0xAC4DC000 C:\Windows\system32\drivers\spsys.sys 716800 bytes (Microsoft Corporation, security processor)
0x8CEF1000 C:\Windows\System32\drivers\dxgkrnl.sys 651264 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8C105000 C:\Windows\system32\DRIVERS\rdpdr.sys 561152 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0x80602000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x9010A000 C:\Windows\System32\Drivers\ATSwpWDF.sys 479232 bytes (AuthenTec, Inc., AuthenTec Swipe Sensor WDF USB Driver)
0x90008000 C:\Windows\system32\drivers\CHDRT32.sys 471040 bytes (Conexant Systems Inc., High Definition Audio Function Driver)
0x8357F000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xAFE0E000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8040B000 C:\Windows\system32\mcupdate_GenuineIntel.dll 393216 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x9075C000 C:\Windows\system32\drivers\csc.sys 368640 bytes (Microsoft Corporation, Windows Client Side Caching Driver)
0x8C050000 C:\Windows\system32\DRIVERS\mux.sys 323584 bytes (Intel© Corporation, My WiFi PAN Intermediate Miniport Driver)
0xAFF7D000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x80734000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x9061C000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x8068B000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)
0x80484000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x805A5000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x8C7A3000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x900CD000 C:\Windows\system32\DRIVERS\HSXHWAZL.sys 249856 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0x90714000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x906D2000 C:\Windows\system32\Drivers\vmm.sys 241664 bytes (Microsoft Corporation, Virtual Machine Monitor)
0x8CFBA000 C:\Windows\system32\DRIVERS\e1y6032.sys 237568 bytes (Intel Corporation, Intel® Gigabit Network Connection NDIS 6 deserialized driver)
0x83742000 C:\Windows\system32\drivers\NETIO.SYS 237568 bytes (Microsoft Corporation, Network I/O Subsystem)
0xAFF05000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x88519000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xAC433000 C:\Windows\system32\drivers\aswMonFlt.sys 225280 bytes (AVAST Software, avast! File System Minifilter for Windows 2003/Vista)
0x8C1C6000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x829D3000 ACPI_HAL 208896 bytes
0x829D3000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x8351C000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x90669000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x837B0000 C:\Windows\system32\DRIVERS\SynTP.sys 200704 bytes (Synaptics Incorporated, Synaptics Touchpad Driver)
0x807BB000 C:\Windows\system32\DRIVERS\msiscsi.sys 188416 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x8077E000 C:\Windows\system32\DRIVERS\pcmcia.sys 184320 bytes (Microsoft Corporation, PCMCIA Bus Driver)
0x9007B000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x83717000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8C00F000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0xAC59B000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x907CD000 C:\Windows\System32\Drivers\aswSP.SYS 159744 bytes (AVAST Software, avast! self protection module)
0x88592000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x806E2000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xAFF56000 C:\Windows\System32\DRIVERS\srv2.sys 159744 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x900A8000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x8C0AA000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x885CA000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0x901B0000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0x88563000 C:\Windows\System32\DRIVERS\Apsx86.sys 131072 bytes (Lenovo., Shockproof Disk Driver)
0xAFEC6000 C:\Windows\system32\drivers\mrxdav.sys 131072 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xAFEE6000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x834E6000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0xAFE7B000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x882F4000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0xAC418000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0xAFE98000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x837E1000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xAC482000 C:\Windows\System32\DLA\DLAIFS_M.SYS 98304 bytes (Roxio, Drive Letter Access Component)
0xAFF3E000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x907B6000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0xAC4C5000 C:\Windows\System32\DLA\DLAUDF_M.SYS 94208 bytes (Roxio, Drive Letter Access Component)
0x8355E000 C:\Windows\System32\Drivers\DRVMCDB.SYS 94208 bytes (Sonic Solutions, Device Driver)
0x8C039000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xB1702000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xAC4AF000 C:\Windows\System32\DLA\DLAUDFAM.SYS 90112 bytes (Roxio, Drive Letter Access Component)
0x9069B000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x805E6000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0xAFEB1000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8C0F0000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8C0DC000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x90608000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8CF9D000 C:\Windows\system32\DRIVERS\atikmpag.sys 77824 bytes (Advanced Micro Devices, Inc., AMD multi-vendor Miniport Driver)
0x8D3B7000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)
0xAC5CF000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x906BF000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x8379E000 C:\Windows\system32\DRIVERS\HDAudBus.sys 73728 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x885B9000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x807E9000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x8046B000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x8354E000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x903D5000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library)
0xAC58B000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x807AB000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x8D399000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0x8C18E000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x8377C000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0xAC409000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x88583000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x80709000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x8C0CD000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x8C7E1000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x8378B000 C:\Windows\system32\DRIVERS\VMNetSrv.sys 61440 bytes (Microsoft Corporation, Virtual Machine Network Services Driver)
0x80725000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x8D3A9000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0x9C2D0000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x906B1000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x901EC000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x8350E000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8D3E2000 C:\Windows\system32\drivers\tpm.sys 57344 bytes (Microsoft Corporation, TPM Device Driver)
0x8830F000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x903BF000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x835F0000 C:\Windows\system32\DRIVERS\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0)
0x8C1B9000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x8CF90000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver)
0x8067E000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0xB16EE000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x901A4000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xAC476000 C:\Windows\System32\Drivers\DRVNDDM.SYS 45056 bytes (Roxio, Device Driver Manager)
0x8D3CA000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)
0x8D3D7000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)
0x901E1000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x8C09F000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x88200000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x885F4000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8CFF4000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x8C000000 C:\Windows\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver)
0x8071B000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x907F4000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x8CFB0000 C:\Windows\system32\DRIVERS\HECI.sys 40960 bytes (Intel Corporation, Intel® Management Engine Interface)
0x83504000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8C1AF000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0xAC5C5000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x90750000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x83575000 C:\Windows\System32\Drivers\PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xB16E4000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x88552000 C:\Windows\System32\DRIVERS\ApsHM86.sys 36864 bytes (Lenovo., ThinkVantage Active Protection System HID Digitizer Activity Monitor Driver)
0x885EB000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x9018E000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x903CC000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0xB1718000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x9017F000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x9C2A0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x88400000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0xAC46D000 C:\Windows\system32\DRIVERS\tvtfilter.sys 36864 bytes (Lenovo, Rescue and Recovery filter driver)
0x8C7F0000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x806D1000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x834DE000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x8047C000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x80403000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x903F3000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0x806DA000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x901D1000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x901D9000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8855B000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8C1A5000 C:\Windows\system32\DRIVERS\Tvti2c.sys 32768 bytes (Lenovo (United States) Inc., SMBUS Driver)
0xB16FA000 C:\Windows\system32\DRIVERS\xaudio.sys 32768 bytes (Conexant Systems, Inc., Modem Audio Device Driver)
0x90197000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0xAC4A1000 C:\Windows\System32\DLA\DLABMFSM.SYS 28672 bytes (Roxio, Drive Letter Access Component)
0xAC4A8000 C:\Windows\System32\DLA\DLABOIOM.SYS 28672 bytes (Roxio, Drive Letter Access Component)
0x903E5000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x903EC000 C:\Windows\system32\DRIVERS\NuidFltr.sys 28672 bytes (Microsoft Corporation, Filter Driver for Microsoft Hardware HID Non-User Input Data)
0x90200000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8C19E000 C:\Windows\system32\DRIVERS\psadd.sys 28672 bytes (Lenovo (United States) Inc., SMBIOS Driver)
0x9070D000 C:\Windows\System32\drivers\Tppwr32v.sys 28672 bytes (Lenovo Group Limited, Power Manager)
0x9019E000 C:\Windows\System32\Drivers\DLARTL_M.SYS 24576 bytes (Roxio, Shared Driver Component)
0x8C800000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0x8C806000 C:\Windows\system32\DRIVERS\ManyCam.sys 24576 bytes (ManyCam LLC., ManyCam Virtual Webcam, WDM Video Capture Driver)
0x90664000 C:\Windows\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver)
0xAC49A000 C:\Windows\System32\DLA\DLAOPIOM.SYS 20480 bytes (Roxio, Drive Letter Access Component)
0x8D3F4000 C:\Windows\system32\DRIVERS\ibmpmdrv.sys 20480 bytes (Lenovo., ThinkPad Power Management Driver)
0x8D3F0000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0xAFFE3000 C:\Windows\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface x86 Driver)
0xAC46A000 C:\Windows\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver)
0x80718000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x8D3F9000 C:\Windows\System32\Drivers\DLACDBHM.SYS 8192 bytes (Roxio, Shared Driver Component)
0xAC49F000 C:\Windows\System32\DLA\DLAPoolM.SYS 8192 bytes (Roxio, Drive Letter Access Component)
0x9075A000 C:\Windows\system32\DRIVERS\smiif32.sys 8192 bytes (Lenovo Group Limited, SMI Driver for Lenovo system)
0x8C1AD000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x8D3D5000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xAC481000 C:\Windows\System32\DLA\DLADResM.SYS 4096 bytes (Roxio, Drive Letter Access Component)
==============================================
>Stealth
==============================================
==============================================
>Files
==============================================
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00F2C.log
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010018.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010018.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010018.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.wid
!-->[Hidden] C:\RRbackups\common\bmgrmode.dat
!-->[Hidden] C:\RRbackups\common\css.dat
!-->[Hidden] C:\RRbackups\common\hints.dat
!-->[Hidden] C:\RRbackups\common\mnd.dat
!-->[Hidden] C:\RRbackups\common\regcerts.dat
!-->[Hidden] C:\RRbackups\common\restore.log
!-->[Hidden] C:\RRbackups\common\rr.log
!-->[Hidden] C:\RRbackups\common\rr_bcdenum.dat
!-->[Hidden] C:\RRbackups\common\SAM
!-->[Hidden] C:\RRbackups\common\seccache.dat
!-->[Hidden] C:\RRbackups\common\secpolicy.dat
!-->[Hidden] C:\RRbackups\common\settings.dat
!-->[Hidden] C:\RRbackups\common\system.dat
!-->[Hidden] C:\RRbackups\common\tvtcmn.dat
!-->[Hidden] C:\RRbackups\common\tvtns.bin
!-->[Hidden] C:\RRbackups\common\usersids.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-500\8f71098770f72c7a67cd8f1151619865_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-500\a18ca4003deb042bbee7a40f15e1970b_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1853308285-865056411-922338472-500\fe37cbff-df92-472f-b191-4ced8be6282a
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1853308285-865056411-922338472-500\Preferred
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-946592493-3211520402-3949043191-500\1e617109-803e-4be7-9818-0d7338a89cf9
!-->[Hidden] C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-946592493-3211520402-3949043191-500\Preferred
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\config.ini
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\cspContainer.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\cssversion.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\encobject.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\enroll.ini
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\hibernation.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\hwkeys.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Lenovo\Client Security Solution\symkeys.dat
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-1000\49ac1cf87687c5a4c794042acbff288e_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-1000\533145ef011ddf5ca3983e2545a902b4_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-1000\5c05a24649dce38756a5072a69bfe1ba_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-1000\83aa4cc77f591dfc2374580bbd95f6ba_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-1000\8f71098770f72c7a67cd8f1151619865_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1853308285-865056411-922338472-1000\932a2db58c237abd381d22df4c63a04a_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Protect\CREDHIST
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Protect\S-1-5-21-1853308285-865056411-922338472-1000\1490f83c-0c8e-4046-8207-939e9c0c08c1
!-->[Hidden] C:\RRbackups\Documents and Settings\LENOVO\AppData\Roaming\Microsoft\Protect\S-1-5-21-1853308285-865056411-922338472-1000\Preferred
!-->[Hidden] C:\RRbackups\ProgramData\Lenovo\Client Security Solution\cspContainer.dat
!-->[Hidden] C:\RRbackups\ProgramData\Lenovo\Client Security Solution\encobject.dat
!-->[Hidden] C:\RRbackups\ProgramData\Lenovo\Client Security Solution\hwkeys.dat
!-->[Hidden] C:\RRbackups\ProgramData\Lenovo\Client Security Solution\symkeys.dat
!-->[Hidden] C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_2d523134-07d7-4b79-ba88-501f51b85683
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{1B8BA7B6-BC27-11DF-9D74-002713B3DE01}.dat::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{43B89BC6-BC28-11DF-9D74-002713B3DE01}.dat
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{68BC5DE6-BC27-11DF-9D74-002713B3DE01}.dat
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{BD6C9A86-BC27-11DF-9D74-002713B3DE01}.dat
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{D4B86116-BC27-11DF-9D74-002713B3DE01}.dat
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{E947EDD6-BC27-11DF-9D74-002713B3DE01}.dat
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KH7GAO6U\faviconCAO8SYOU.ico
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\10-General-Hacking-Discussion[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\13486-Retro-Megathread[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\14896-How-to-verify-habbo-account[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\2a672bp[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\2hqdzy8[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\2k593l[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\68u92a[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\ACH_Travel8[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\add[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\adsCARANLXB.htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar1182_15[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar118_23[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar176_38[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar2704_8[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar295_3[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar3664_3[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar56_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatar802_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatarimage[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatarimage[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatarimage[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatarimage[4].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\avatarimage[5].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\badgeback[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\bg2[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\borders[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\branding_bg[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\brstrip[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\campaignButton_subonusfix[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\client[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\client_error[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\collapse_collapsed_40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\domready[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\enter_button[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\forumhome-rollup[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\frown[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\habbo-imager[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\habboclient[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\habbo_skeleton[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_club[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_dynamic_downloader[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_entry_init[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_friend_list[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_human_50_acc_face[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_human_50_body[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_human_acc_eye[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_human_leg[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_human_shoe[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_interface[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_photo[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hh_shared[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hotel-button-splash[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\hotel-button[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\icon4[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\ieerror[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\ignore[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\im_aim[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\italic[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\job_application[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\kfc-1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\lastpost-right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\LoginRight[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\loki-stond[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\MainForm-FormRight[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\maintitle[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\memberinfo-rollup[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\me[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\mod[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\moredata[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\motto_field[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\NavFooter[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\NavNews[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\NavShoutBox[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\NavSpacer[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\newbtn_middle[4].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\News[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\popup_habbocount_bg[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\popup_topbar_slice[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\post_new[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\primary[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\quote_40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\randombg[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\rating-15_1[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\rating-15_5[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\reputation-40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\resize_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\search-rollup[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\shenkx_co_uk[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\Shoutbox[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\showthread-rollup[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\small_icons[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\smil[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\spacer[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\stripepattern[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\subforum_old-48[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\subscribed_40b[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\tapatalkdetect[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\taysmokesloud[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\thread_hot-16[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\thread_new-30[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\topstories_nav_bg[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\topstory_vistas[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\top[2]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\transparent_area[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\underline[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\user-online[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\usernav[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin-editor[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin-read-marker[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin-threadbit[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin_ajax_threadrate[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin_lightbox[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin_post_loader[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\vbulletin_quick_comment[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\warning[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\39ZBNHJ3\zomb[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\10-08-morelargefigures[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\10-08fivegroupicons[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\105-Habbo-Hotel-(TRIAL)[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\12084590[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\12591-Maintenance-Break-Thread[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\12591-Maintenance-Break-Thread[3].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\14435-Getting-Habbo-Accounts[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\2ec23km[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\507131[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\adsCART8YBI.htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\ads[8].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar108_2[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar1178_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar1388_9[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar1966_5[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar2820_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar342_5[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar3884_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar54_106[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatar66_13[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatarimage[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatarimage[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatarimage[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatarimage[4].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatarimage[5].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\avatarimage[6].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\bg-right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\black_downward_arrow[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\bold[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\borders[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\border_left[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\bottom[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\Bradlul[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\btn_donate_SM[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\c4lebirl[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\collapse_40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\common[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\community[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\connection-min[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\display[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\forumdisplay-rollup[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\forum[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\forum_stats[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\GraphData[1].cfm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\green_vip[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\group[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\habboclient[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\help_16[2]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_buffer[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_entry_base[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_entry_ru[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_furni_classes[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_human_50_acc_eye[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_human_50_hair[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_human_hair[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_human_shirt[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_ig[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_ig_interface[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_poll[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_room[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\hh_tutorial[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\icon1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\icon6[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\imgad[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\imgad[2].swf
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\imgad[4].swf
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\im_msn[2].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\index[3].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\insertimage[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\katyperry2d[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\libs[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\LoginHeader[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\LoginMiddleBar[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\login[3].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\multiquote_40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\NavAbout[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\navbit-arrow-right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\navbit-home[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\NavDisclaimer[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\NavHabboExploits[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\navi2-borders[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\navi2-bottom[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\new[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\Olly+Murs+what+would+have+been+his+singl[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\personal[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\player2[1].swf
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\post_thanks[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\post_thanks[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\previous-right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\profile[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\rating-15_0[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\rating-15_2[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\reply_40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\resize_0[2].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\rooms[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\search[2].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\separator[2].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\smile[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\sortarrow-asc[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\sparkle[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\sticky[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\style[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\subforum_new-48[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\swf[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\tab[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\textsigv[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\thread_hot_new-16[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\thread_hot_new-30[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\tooltips[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\tooltips[2].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\top_banner[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\top_story_credits[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\user-offline[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\users_online[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\vbulletin-ajax-reputation[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\vbulletin_quick_edit_generic[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\vbulletin_quick_edit_visitormessage[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\viewpost-right[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\VIP[2].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTEVXMKD\yuiloader-dom-event[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\10-08-largechars-smalltext[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\10-08newpetcmd[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\10-08patchfail[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\10-08runescape_newitemfail[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\10252-Read-me-FIRST[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\105-Habbo-Hotel-(TRIAL)[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\106-General-Habbo-Discussion[1].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\14755-Thou-hath-been-h4x3d[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\18eidz[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\2qterv8[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\3338sc9[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\476126[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\506769[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\54-savi0r[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\ACH_AllTimeHotelPresence6[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\ACH_Forum3[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\adsCAI9H49Y.htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\animation[1].xml
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\arrow[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar1673_87[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar176_38[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar17_18[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar181_6[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar213_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar2243_7[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar226_13[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar2356_8[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar3458_5[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar567_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar60_2[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar976_12[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatar976_12[2].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatarimage[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatarimage[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\avatarimage[4].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\bg-left[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\bg[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\big_icons[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\border_right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\bottom-shadow[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\boxblue[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\boxes[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\branding_right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\button[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\child_forum[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\clear[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\client[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\client_error[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\cola[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\createlink[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\domready[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\draworder[1].xml
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\firstnew[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\forum[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\forum_old-48[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\fuse_client[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\group[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\habbo[1].dir
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\health[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_cat_code[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_cat_gfx_all[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_human[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_human_50_face[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_human_50_hats[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_human_hats[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_human_item[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_room_ui[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hh_room_utils[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hotel-button-hotelopen[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\hot_campaign_button_160x60_Writer[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\ieerror[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\imgad[6].swf
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\imgad[9].swf
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\immunity[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\info_habbo_plate[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\inksig[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\int[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\j96bt0[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\last-right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\legend[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\LoginForm[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\logo[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\MainHeader-LoginLeft[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\message[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\multiquote-back_40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\NavLeft[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\NavLinks[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\NavVL64Decoder[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\partsets[1].xml
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\player_wavestreaming_com[2]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\popupctrl[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\popup_habbocount_bg[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\post_new[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\post_old[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\quote[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\quote_icon[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\rating-15_3[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\rating-trans-15_5[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\removeformat[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\rooms[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\row2[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\row[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\search[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\search[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\Spacer[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\spelling[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\statsimg[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\status[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\swfobject[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\thread-16-right[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\thread_dot-16-right[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\thread_hot-30[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\thread_lock-30[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\top-highlight[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\topstory_neon_2[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\up[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\vbulletin-core[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\vbulletin_quick_reply[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\visual[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ0SZMKP\WD0[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\10-08-invistest[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\10-08-newinvisableskinh[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\10-08catalion[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\10-08newimbug[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\14952-null-a-revert[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\440824[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\506768[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\adbrite-your-ad-here-banner[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\additional[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\admin[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\adsCAL21801.htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\adsCAPF4GMB.htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\advertisement[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar104_2[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar1070_11[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar130_11[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar1799_2[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar17_18[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar192_7[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar1_15[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar2938_4[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar3207_11[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar39_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar426_26[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar520_1[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatar54_106[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatarimage[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatarimage[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatarimage[3].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\avatarimage[4].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\biggrin[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\boxes[2].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\box[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\box[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\buttons[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\buttons[2].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\button[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\cb_beta_2[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\collapse[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\collapse_nor[2]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\color[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\common[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\dixonink[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\dokttx[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\down[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\empty[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\fitchtwinsemilyandkatie[1].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\flashy_arrow[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\forum_new-48[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\fullcontent[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\generic_button[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\gold_vip[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\gototop[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\GraphData[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\habboclient[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\header[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_guide[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_human_50_acc_head[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_human_acc_face[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_human_acc_head[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_human_body[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_human_face[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_instant_messenger[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_kiosk_room[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_navigator[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_patch_uk[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_pets[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_pets_common[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\hh_recycler[1].cct
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\homepage[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\htlview_ws[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\icon1[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\icon5[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\imgad[3].jpg
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\info_icons[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\IOSec[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\ip[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\jersey-shore-silly[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\kd3[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\libs[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\LoginFooter[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\main-rollup[1].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\MainFooter[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\modieus[1].swf
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\NavBlank[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\NavHeader[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\NavRight[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\NewTabPageScripts[1]
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\next-right[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\phazeddl[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\popup_topbar_slice[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\progress[2].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\quote-left[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\rating-15_4[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\realtransblack[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\report-40b[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\reputation_highpos[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\reputation_pos[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\rolleyes[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\search[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\search_results_postbit[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\shocked[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\strength[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\stylesheet[1].htm
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\style[2].css
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\swfobject[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\switchmode[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\tabs[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\thread_hot_lock-30[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\thread_lock-16[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\thread_new-16[2].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\thread_old-30[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\tumblr_l7otqu2qyp1qzlt56o1_400[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\unknown[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\vbulletin_md5[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\vbulletin_multi_quote[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\vbulletin_quick_edit[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\vbulletin_read_marker[1].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\vbulletin_textedit[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\video[1].png
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\visual[2].js
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UMHOFPH3\wink[1].gif
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\MessengerCache\ZNNVKwHhm5hmhwUC3dH8RFKnhlA=
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF115B.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF2283.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF228D.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF2465.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF246F.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF25B.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF265.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF2A84.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF2ABB.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF326.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF330.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF3C3.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF3CE.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF4161.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF4470.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF46AF.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF47B0.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF4A10.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF5168.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF5CE.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF6277.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF6CF4.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF6D03.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF6EF7.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF7930.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DF8CF9.tmp
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFA24E.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFBCDA.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFBD47.tmp
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFC84A.tmp
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFDFDE.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFE079.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Local\Temp\~DFE088.tmp::$DATA
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\lenovo@adbrite[1].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\lenovo@deaglegame[2].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\lenovo@live[1].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\lenovo@msn[2].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\lenovo@stond[1].txt
!-->[Hidden] C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x000B50AA, Type: Inline - RelativeJump 0x826CE0AA-->826CE0B1 [WMIxWDM]
ntkrnlpa.exe-->KeFindConfigurationEntry, Type: Inline - RelativeJump 0x8296C3B8-->8296C3C2 [WMIxWDM]
ntkrnlpa.exe-->NtCreateProcessEx, Type: Inline - RelativeJump 0x828AE860-->907E2BB2 [aswSP.SYS]
ntkrnlpa.exe-->NtCreateSection, Type: Inline - RelativeJump 0x828633D9-->907E29D6 [aswSP.SYS]
ntkrnlpa.exe-->NtLoadDriver, Type: Inline - RelativeJump 0x82789A6A-->907E2B10 [aswSP.SYS]
ntkrnlpa.exe-->ObInsertObject, Type: Inline - RelativeJump 0x828625C2-->907DFFFA [aswSP.SYS]
ntkrnlpa.exe-->ObMakeTemporaryObject, Type: Inline - RelativeJump 0x827F9B74-->907DE5D4 [aswSP.SYS]
ntkrnlpa.exe-->TmInitSystem, Type: Inline - RelativeJump 0x829712C0-->829712B1 [WMIxWDM]
[1564]rundll32.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]
[1564]rundll32.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B71170-->00000000 [shimeng.dll]
[1564]rundll32.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x080E1414-->00000000 [shimeng.dll]
[1564]rundll32.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]
[1564]rundll32.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [shimeng.dll]
[1772]AvastSvc.exe-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - PushRet 0x76816E2D-->00000000 [unknown_code_page]
[3232]msnmsgr.exe-->advapi32.dll-->CryptDecrypt, Type: Inline - RelativeJump 0x766FE8D9-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->advapi32.dll-->CryptDecrypt, Type: Inline - SEH 0x766FE8DE [unknown_code_page]
[3232]msnmsgr.exe-->advapi32.dll-->CryptDecrypt, Type: Inline - SEH 0x766FE8DF [unknown_code_page]
[3232]msnmsgr.exe-->advapi32.dll-->CryptDeriveKey, Type: Inline - RelativeJump 0x766FE6F6-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->advapi32.dll-->CryptDeriveKey, Type: Inline - SEH 0x766FE6FB [unknown_code_page]
[3232]msnmsgr.exe-->advapi32.dll-->CryptDeriveKey, Type: Inline - SEH 0x766FE6FC [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->CreateEventA, Type: Inline - RelativeJump 0x76834AD8-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceA, Type: Inline - RelativeJump 0x768209A5-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceExA, Type: Inline - RelativeJump 0x768208DD-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceExA, Type: Inline - SEH 0x768208E2 [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceExA, Type: Inline - SEH 0x768208E3 [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceExW, Type: Inline - RelativeJump 0x7683813B-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceExW, Type: Inline - SEH 0x76838140 [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceExW, Type: Inline - SEH 0x76838141 [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->FindResourceW, Type: Inline - RelativeJump 0x768397C7-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->LoadResource, Type: Inline - RelativeJump 0x76838213-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->LoadResource, Type: Inline - SEH 0x76838218 [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->LoadResource, Type: Inline - SEH 0x76838219 [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->LockResource, Type: Inline - RelativeJump 0x76837F1F-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->SizeofResource, Type: Inline - RelativeJump 0x768397E5-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->kernel32.dll-->SizeofResource, Type: Inline - SEH 0x768397EA [unknown_code_page]
[3232]msnmsgr.exe-->kernel32.dll-->SizeofResource, Type: Inline - SEH 0x768397EB [unknown_code_page]
[3232]msnmsgr.exe-->shell32.dll-->Shell_NotifyIconW, Type: Inline - RelativeJump 0x76A1C808-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x77581C58-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x77563D67-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->GetWindowLongW, Type: Inline - RelativeJump 0x7756F67F-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->GetWindowLongW, Type: Inline - SEH 0x7756F684 [unknown_code_page]
[3232]msnmsgr.exe-->user32.dll-->GetWindowLongW, Type: Inline - SEH 0x7756F685 [unknown_code_page]
[3232]msnmsgr.exe-->user32.dll-->LoadIconW, Type: Inline - RelativeJump 0x7755EC94-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->LoadImageW, Type: Inline - RelativeJump 0x7755D61D-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775AD56B-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->PeekMessageW, Type: Inline - RelativeJump 0x7756FD9F-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->SetWindowPlacement, Type: Inline - RelativeJump 0x775579BB-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->SetWindowRgn, Type: Inline - RelativeJump 0x775595E2-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->user32.dll-->SetWindowRgn, Type: Inline - SEH 0x775595E7 [unknown_code_page]
[3232]msnmsgr.exe-->user32.dll-->SetWindowRgn, Type: Inline - SEH 0x775595E8 [unknown_code_page]
[3232]msnmsgr.exe-->user32.dll-->TrackPopupMenuEx, Type: Inline - RelativeJump 0x77580F4D-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->wininet.dll-->HttpOpenRequestA, Type: Inline - RelativeJump 0x768ED508-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->wininet.dll-->HttpSendRequestA, Type: Inline - RelativeJump 0x768FEE89-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->wininet.dll-->InternetCloseHandle, Type: Inline - RelativeJump 0x768E9088-->00000000 [MsgPlusLive.dll]
[3232]msnmsgr.exe-->wininet.dll-->InternetReadFile, Type: Inline - RelativeJump 0x768E654B-->00000000 [MsgPlusLive.dll]
[3976]java.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]
[3976]java.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B71170-->00000000 [shimeng.dll]
[3976]java.exe-->kernel32.dll-->CreateProcessA, Type: IAT modification 0x00413038-->00000000 [AcLayers.dll]
[3976]java.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x00413048-->00000000 [shimeng.dll]
[3976]java.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6C94123C-->00000000 [shimeng.dll]
[3976]java.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x080E1414-->00000000 [shimeng.dll]
[3976]java.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]
[3976]java.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [shimeng.dll]
[3976]java.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [shimeng.dll]
[4748]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B71130-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B7119C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B711BC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B71170-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B7111C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B71110-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B71174-->00000000 [IEShims.dll]
[4748]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B711AC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6C94123C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x080E125C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x080E13B0-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x080E1460-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x080E11A8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x080E12E8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x080E13B4-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x080E132C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x080E1328-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x080E1118-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x080E1280-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x080E1370-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x080E14A0-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x080E13BC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x080E14E8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x080E1390-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x080E1168-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x080E1104-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x080E13A0-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x080E136C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x080E1428-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x080E14DC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x080E1284-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x080E1448-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x080E13C0-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x080E130C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x080E13AC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x080E1144-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x080E1384-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x080E14F8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x080E13B8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x080E116C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x080E1170-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x080E2318-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x080E1890-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x080E1A6C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x080E191C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x77558C33-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x775727CD-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x77579AFA-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x775716FD-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x77581C58-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x77563D67-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775983DD-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x7755BD25-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775980B2-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x77571FD5-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x7755DC79-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7755C178-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x77558DF4-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x775687C7-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x7757179A-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x775699AE-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[4748]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x775AD93C-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775AD5D1-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775AD5F5-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775AD471-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775AD56B-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x7755BEE7-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x77596F1A-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x77581ECE-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x77557B69-->00000000 [ieframe.dll]
[4748]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x775808BE-->00000000 [ieframe.dll]
[4748]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[4748]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]
[5688]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x77563D67-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775983DD-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x7755BD25-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775980B2-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x77571FD5-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775AD5D1-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775AD5F5-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775AD471-->00000000 [ieframe.dll]
[5688]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775AD56B-->00000000 [ieframe.dll]
[5844]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B71130-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B7119C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B711BC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B71170-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B7111C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B71110-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B71174-->00000000 [IEShims.dll]
[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B711AC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6C94123C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x080E125C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x080E13B0-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x080E1460-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x080E11A8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x080E12E8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x080E13B4-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x080E132C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x080E1328-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x080E1118-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x080E1280-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x080E1370-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x080E14A0-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x080E13BC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x080E14E8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x080E1390-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x080E1168-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x080E1104-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x080E13A0-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x080E136C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x080E1428-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x080E14DC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x080E1284-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x080E1448-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x080E13C0-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x080E130C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x080E13AC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x080E1144-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x080E1384-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x080E14F8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x080E13B8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x080E116C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x080E1170-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x080E2318-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x080E1890-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x080E1A6C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x080E191C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x77558C33-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x775727CD-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x77579AFA-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x775716FD-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x77581C58-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x77563D67-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775983DD-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x7755BD25-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775980B2-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x77571FD5-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x7755DC79-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7755C178-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x77558DF4-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x775687C7-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x7757179A-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x775699AE-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[5844]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x775AD93C-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775AD5D1-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775AD5F5-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775AD471-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775AD56B-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x7755BEE7-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x77596F1A-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x77581ECE-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x77557B69-->00000000 [ieframe.dll]
[5844]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x775808BE-->00000000 [ieframe.dll]
[5844]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[5844]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B71130-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B7119C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B711BC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B71170-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B7111C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B71110-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B71174-->00000000 [IEShims.dll]
[5952]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B711AC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6C94123C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x080E125C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x080E13B0-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x080E1460-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x080E11A8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x080E12E8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x080E13B4-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x080E132C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x080E1328-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x080E1118-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x080E1280-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x080E1370-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x080E14A0-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x080E13BC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x080E14E8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x080E1390-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x080E1168-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x080E1104-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x080E13A0-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x080E136C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x080E1428-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x080E14DC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x080E1284-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x080E1448-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x080E13C0-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x080E130C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x080E13AC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x080E1144-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x080E1384-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x080E14F8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x080E13B8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x080E116C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x080E1170-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x080E2318-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x080E1890-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x080E1A6C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x080E191C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x77558C33-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x775727CD-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x77579AFA-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x775716FD-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x77581C58-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x77563D67-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775983DD-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x7755BD25-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775980B2-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x77571FD5-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x7755DC79-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7755C178-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x77558DF4-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x775687C7-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x7757179A-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x775699AE-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[5952]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x775AD93C-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775AD5D1-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775AD5F5-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775AD471-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775AD56B-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x7755BEE7-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x77596F1A-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x77581ECE-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x77557B69-->00000000 [ieframe.dll]
[5952]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x775808BE-->00000000 [ieframe.dll]
[5952]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[5952]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]
[952]jp2launcher.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]
[952]jp2launcher.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B71170-->00000000 [shimeng.dll]
[952]jp2launcher.exe-->kernel32.dll-->CreateProcessA, Type: IAT modification 0x00403078-->00000000 [AcLayers.dll]
[952]jp2launcher.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x00403050-->00000000 [shimeng.dll]
[952]jp2launcher.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x080E1414-->00000000 [shimeng.dll]
[952]jp2launcher.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]


!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)
  • 0

#5
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello nortan360,

Otl froze


Did your machine reboot after that? If not, please reboot before you carry out the actions below.

Could i also ask what 'PCdoctor' is


It is a misleading Security software - rogue spyware not to be confused with the legitimate PC Tools products.

Now

Please download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#6
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
Sorry for the delay i keep getting bsod 5th time now
the log is on its way
  • 0

#7
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Okie dokie :)
  • 0

#8
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
ComboFix 10-09-08.03 - LENOVO 11/09/2010 0:29.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.44.1033.18.1943.1133 [GMT 1:00]
Running from: c:\users\LENOVO\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Thumbs.db
Q:\AUTORUN.INF
S:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2010-08-10 to 2010-09-10 )))))))))))))))))))))))))))))))
.

2010-09-10 23:38 . 2010-09-10 23:42 -------- d-----w- c:\users\LENOVO\AppData\Local\temp
2010-09-09 20:00 . 2010-09-09 20:09 -------- d-----w- c:\users\LENOVO\AppData\Roaming\PFStaticIP
2010-09-09 20:00 . 2010-09-09 20:00 -------- d-----w- c:\program files\PFStaticIP
2010-09-09 15:15 . 2010-09-09 15:15 -------- d-----w- C:\_OTL
2010-09-08 21:42 . 2010-09-08 21:42 -------- d-----w- c:\users\LENOVO\AppData\Roaming\.minecraft
2010-09-07 22:27 . 2010-09-07 22:27 -------- d-----w- c:\program files\TeamViewer
2010-09-03 00:10 . 2010-09-03 00:10 -------- d-----w- c:\program files\ZD Soft
2010-09-02 14:18 . 2010-09-09 23:58 -------- d-----w- c:\program files\Cheat Engine
2010-09-02 14:18 . 2009-11-03 13:07 679936 ----a-w- c:\windows\system32\D3DX81ab.dll
2010-09-02 14:18 . 2009-11-03 13:07 1970176 ----a-w- c:\windows\system32\d3dx9.dll
2010-09-02 13:28 . 2010-09-02 13:32 -------- d-----w- c:\program files\ManyCam 2.4
2010-09-02 13:28 . 2010-09-02 13:32 -------- d-----w- c:\users\LENOVO\AppData\Roaming\ManyCam
2010-09-02 13:28 . 2010-09-09 15:15 -------- d-----w- c:\program files\Ask.com
2010-09-02 00:16 . 2010-09-02 00:16 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Malwarebytes
2010-09-02 00:15 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-02 00:15 . 2010-09-02 00:15 -------- d-----w- c:\programdata\Malwarebytes
2010-09-02 00:15 . 2010-09-02 00:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-02 00:15 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-01 23:05 . 2010-09-03 01:32 -------- d-----w- c:\programdata\Messenger Plus!
2010-09-01 23:04 . 2010-09-01 23:04 -------- d-----w- c:\program files\Messenger Plus! Live
2010-09-01 22:55 . 2010-09-01 22:55 -------- d-----w- c:\program files\QS
2010-09-01 22:54 . 2010-09-01 22:54 -------- d-----w- c:\users\LENOVO\AppData\Roaming\TeamViewer
2010-08-29 23:41 . 2010-09-01 19:13 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Apple Computer
2010-08-29 23:41 . 2010-08-29 23:41 -------- d-----w- c:\users\LENOVO\AppData\Local\Apple Computer
2010-08-29 23:41 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-08-29 23:41 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-08-29 23:40 . 2010-08-29 23:40 -------- d-----w- c:\program files\iPod
2010-08-29 23:40 . 2010-08-29 23:41 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-29 23:40 . 2010-08-29 23:41 -------- d-----w- c:\program files\iTunes
2010-08-29 23:38 . 2010-08-29 23:39 -------- d-----w- c:\program files\QuickTime
2010-08-29 23:38 . 2010-08-29 23:40 -------- d-----w- c:\programdata\Apple Computer
2010-08-29 23:37 . 2010-08-29 23:37 -------- d-----w- c:\users\LENOVO\AppData\Local\Apple
2010-08-29 23:37 . 2010-08-29 23:37 -------- d-----w- c:\program files\Apple Software Update
2010-08-29 23:34 . 2010-08-29 23:34 -------- d-----w- c:\program files\Bonjour
2010-08-29 23:34 . 2010-09-01 19:13 -------- d-----w- c:\programdata\Apple
2010-08-29 23:34 . 2010-08-29 23:40 -------- d-----w- c:\program files\Common Files\Apple
2010-08-29 22:15 . 2010-08-29 22:15 1732 ----a-w- C:\tvtpktfilter.dat
2010-08-28 11:01 . 2010-08-28 11:01 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-08-28 10:57 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-28 10:57 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-28 10:57 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-08-28 10:57 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-28 10:57 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-08-27 14:12 . 2008-11-10 10:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-08-27 14:12 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-08-27 14:11 . 2010-08-28 11:00 -------- d-----w- c:\program files\Microsoft Works
2010-08-27 14:10 . 2010-08-27 14:10 -------- d-----w- c:\program files\Microsoft.NET
2010-08-27 14:08 . 2010-08-27 14:08 -------- d-----w- c:\users\LENOVO\AppData\Local\Microsoft Help
2010-08-27 14:08 . 2010-08-29 11:33 -------- d-----w- c:\programdata\Microsoft Help
2010-08-27 14:07 . 2010-08-27 14:07 -------- d-----r- C:\MSOCache
2010-08-27 10:51 . 2010-08-27 10:51 229208 ----a-w- c:\windows\system32\drivers\VMM.sys
2010-08-26 18:07 . 2010-08-26 18:07 -------- d-----w- c:\users\LENOVO\AppData\Local\Adobe
2010-08-26 17:30 . 2010-08-26 17:31 -------- d-----w- c:\users\LENOVO\AppData\Local\Google
2010-08-26 17:30 . 2010-08-26 17:30 -------- d-----w- c:\users\LENOVO\AppData\Local\Deployment
2010-08-26 17:30 . 2010-08-26 17:30 -------- d-----w- c:\users\LENOVO\AppData\Local\Apps
2010-08-26 15:37 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-08-26 15:37 . 2009-08-24 12:16 378368 ----a-w- c:\windows\system32\winhttp.dll
2010-08-26 13:51 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-08-26 13:42 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2010-08-26 13:42 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-08-26 13:42 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2010-08-26 13:42 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2010-08-26 13:42 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2010-08-26 13:37 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2010-08-26 13:36 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2010-08-26 13:34 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-08-26 13:34 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-08-26 13:34 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-08-26 13:33 . 2010-08-26 13:33 -------- d-----w- c:\program files\MSXML 4.0
2010-08-26 13:27 . 2010-09-04 23:39 7728 ----a-w- c:\users\LENOVO\AppData\Local\d3d9caps.dat
2010-08-25 23:25 . 2010-08-25 23:25 -------- d-----w- c:\users\LENOVO\AppData\Local\Roblox
2010-08-25 20:42 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2010-08-25 18:54 . 2010-08-25 18:54 -------- d-----w- c:\programdata\Insight Software
2010-08-25 18:54 . 2010-08-25 18:54 -------- d-----w- c:\program files\Common Files\Insight Software Solutions
2010-08-25 18:54 . 2010-08-25 18:54 -------- d-----w- c:\program files\ShortKeys2
2010-08-25 18:31 . 2010-08-25 18:31 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-08-25 18:04 . 2010-08-25 18:04 -------- d-----w- c:\windows\system32\Adobe
2010-08-25 17:49 . 2010-08-25 17:49 -------- d-----w- c:\program files\Microsoft Virtual PC
2010-08-25 17:34 . 2010-09-10 22:01 -------- d-----w- c:\users\LENOVO\Tracing
2010-08-25 17:32 . 2010-08-28 16:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-25 17:32 . 2010-08-29 23:41 -------- dc----w- c:\windows\system32\DRVSTORE
2010-08-25 17:32 . 2010-04-28 06:44 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-08-25 17:30 . 2010-08-25 17:30 -------- d-----w- c:\programdata\Insight Software Solutions
2010-08-25 17:30 . 2010-08-25 17:30 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-08-25 17:28 . 2010-08-25 17:28 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-25 17:26 . 2010-08-25 17:26 -------- d-----w- c:\program files\Microsoft
2010-08-25 17:26 . 2010-08-25 17:26 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-08-25 17:26 . 2010-08-25 17:32 -------- d-----w- c:\program files\Windows Live
2010-08-25 17:25 . 2010-08-25 17:25 -------- d-----w- c:\windows\PCHEALTH
2010-08-25 17:20 . 2010-08-25 17:20 -------- d-----w- c:\program files\Common Files\Windows Live
2010-08-25 16:51 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-08-25 16:50 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-25 16:45 . 2010-05-21 13:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-08-25 16:10 . 2009-12-23 12:43 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-08-25 16:10 . 2010-01-15 00:04 98304 ----a-w- c:\windows\system32\cabview.dll
2010-08-25 16:07 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-25 16:07 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-25 16:07 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-25 16:07 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-25 16:07 . 2010-09-07 14:47 50768 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-25 16:06 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-08-25 16:06 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-25 16:06 . 2010-08-25 16:06 -------- d-----w- c:\programdata\Alwil Software
2010-08-25 16:06 . 2010-08-25 16:06 -------- d-----w- c:\program files\Alwil Software
2010-08-25 16:03 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-08-25 16:03 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2010-08-25 16:03 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2010-08-25 16:03 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2010-08-25 16:03 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2010-08-25 16:03 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2010-08-25 16:03 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2010-08-25 16:03 . 2009-08-06 18:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2010-08-25 16:03 . 2009-08-06 17:44 33792 ----a-w- c:\windows\system32\wuapp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-09 20:09 . 2010-09-09 20:01 372 ----a-w- c:\users\LENOVO\AppData\Roaming\PFStaticIP\set_to_static.bat
2010-09-09 20:07 . 2010-09-09 20:03 202 ----a-w- c:\users\LENOVO\AppData\Roaming\PFStaticIP\ipconfig_release_renew.bat
2010-09-04 20:33 . 2010-09-04 20:33 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-08-28 21:49 . 2010-08-25 22:13 165232 ---ha-w- c:\users\LENOVO\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2010-08-28 16:49 . 2010-08-05 21:55 74912 ----a-w- c:\users\LENOVO\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-27 01:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-25 18:48 . 2010-08-05 13:56 -------- d-----w- c:\programdata\Lenovo
2010-08-25 17:31 . 2010-08-05 21:55 -------- d-----w- c:\program files\Windows Live Toolbar
2010-08-08 11:31 . 2010-08-08 11:31 -------- d-----w- c:\users\LENOVO\AppData\Roaming\InterVideo
2010-08-05 21:58 . 2010-08-05 21:57 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Lenovo
2010-08-05 21:57 . 2010-08-05 21:57 -------- d-----w- c:\users\LENOVO\AppData\Roaming\ATI
2010-08-05 21:57 . 2010-08-05 21:57 -------- d-----w- c:\programdata\ATI
2010-08-05 21:56 . 2010-08-05 13:45 100 ----a-w- c:\windows\system32\drivers\Lenovo_6475_WRB.MRK
2010-08-05 21:56 . 2010-08-05 14:04 -------- d-----w- c:\program files\Common Files\Lenovo
2010-08-05 14:20 . 2010-08-05 14:20 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-05 14:14 . 2010-08-05 13:44 -------- d-----w- c:\program files\Lenovo
2010-08-05 14:14 . 2010-08-05 14:07 -------- d-----w- c:\program files\PCDR5
2010-08-05 14:13 . 2010-08-05 14:13 -------- d-----w- c:\programdata\DDNI
2010-08-05 14:13 . 2010-08-05 14:13 -------- d-----w- c:\program files\DDNI
2010-08-05 14:12 . 2010-08-05 13:45 -------- d-----w- c:\program files\ThinkPad
2010-08-05 14:12 . 2010-08-05 14:12 -------- d-----w- c:\program files\Digital Line Detect
2010-08-05 14:12 . 2010-08-05 13:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-05 14:12 . 2010-08-05 14:12 -------- d-----w- c:\program files\NetWaiting
2010-08-05 14:12 . 2010-08-05 13:47 -------- d-----w- c:\program files\CONEXANT
2010-08-05 14:08 . 2010-08-05 14:08 33536 ----a-w- c:\windows\system32\drivers\tvtfilter.sys
2010-08-05 14:07 . 2010-08-05 14:08 118520 ------w- c:\windows\system32\pxinsi64.exe
2010-08-05 14:07 . 2010-08-05 14:08 129784 ------w- c:\windows\system32\pxafs.dll
2010-08-05 14:07 . 2010-08-05 14:08 116472 ------w- c:\windows\system32\pxcpyi64.exe
2010-08-05 14:07 . 2010-08-05 14:07 -------- d-----w- c:\program files\Verizon Wireless
2010-08-05 14:07 . 2010-08-05 14:07 -------- d-----w- c:\programdata\PCDr
2010-08-05 14:07 . 2010-08-05 14:07 -------- d-----w- c:\programdata\PC-Doctor for Windows
2010-08-05 14:01 . 2010-08-05 14:01 410984 ----a-w- c:\windows\system32\deploytk.dll
2010-08-05 14:01 . 2010-08-05 14:01 -------- d-----w- c:\program files\Java
2010-08-05 14:01 . 2010-08-05 14:01 -------- d-----w- c:\program files\Sonic Icons for Lenovo
2010-08-05 14:01 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-08-05 14:01 . 2010-08-05 14:01 -------- d-----w- c:\programdata\Uninstall
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\program files\Roxio
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\Sonic Shared
2010-08-05 14:00 . 2010-08-05 14:00 -------- d-----w- c:\programdata\InstallShield
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\programdata\Roxio
2010-08-05 14:00 . 2010-08-05 14:00 -------- d-----w- c:\programdata\Sonic
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-08-05 13:59 . 2010-08-05 13:45 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-05 13:59 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\SureThing Shared
2010-08-05 13:59 . 2010-08-05 13:56 -------- d-----w- c:\program files\ThinkVantage
2010-08-05 13:58 . 2010-08-05 13:58 -------- d-----w- c:\program files\InterVideo
2010-08-05 13:57 . 2010-08-05 13:57 -------- d-----w- c:\program files\Common Files\InterVideo
2010-08-05 13:57 . 2010-08-05 13:57 -------- d-----w- c:\program files\Lenovo Registration
2010-08-05 13:56 . 2010-08-05 13:56 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-05 13:56 . 2010-08-05 13:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-05 13:55 . 2010-08-05 13:55 -------- d-----w- c:\program files\Lenovo Group Limited
2010-08-05 13:55 . 2010-08-05 13:55 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ATSwpWDF_01005.Wdf
2010-08-05 13:55 . 2010-08-05 13:43 -------- d-----w- c:\program files\DIFX
2010-08-05 13:55 . 2010-08-05 13:55 -------- d-----w- c:\program files\Lenovo Fingerprint Software
2010-08-05 13:51 . 2010-08-05 13:49 -------- d-----w- c:\program files\ATI Technologies
2010-08-05 13:49 . 2010-08-05 13:49 -------- d-----w- c:\program files\ATI
2010-08-05 13:49 . 2010-08-05 13:49 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2010-08-05 13:49 . 2010-08-05 13:49 -------- d-----w- c:\program files\Synaptics
2010-08-05 13:48 . 2010-08-05 13:48 -------- d-----w- c:\programdata\Roaming
2010-08-05 13:47 . 2010-08-05 13:47 -------- d-----w- c:\program files\Cisco
2010-08-05 13:47 . 2010-08-05 13:47 -------- d-----w- c:\programdata\Intel
2010-08-05 13:47 . 2010-08-05 13:47 -------- d-----w- c:\program files\Common Files\Intel
2010-08-05 13:47 . 2010-08-05 13:45 -------- d-----w- c:\program files\Intel
2010-08-05 13:32 . 2010-08-05 13:32 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-08-05 13:32 . 2010-08-05 13:32 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-08-05 13:31 . 2010-08-05 13:31 24064 ----a-w- c:\windows\system32\amxread.dll
2010-08-05 13:31 . 2010-08-05 13:31 13824 ----a-w- c:\windows\system32\apilogen.dll
2010-08-05 13:31 . 2010-08-05 13:31 1645568 ----a-w- c:\windows\system32\connect.dll
2010-08-05 13:30 . 2010-08-05 13:30 2927104 ----a-w- c:\windows\explorer.exe
2010-08-05 13:29 . 2010-08-05 13:29 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2010-08-05 13:29 . 2010-08-05 13:29 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2010-08-05 13:29 . 2010-08-05 13:29 347648 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2010-08-05 13:27 . 2010-08-05 13:27 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-08-05 13:27 . 2010-08-05 13:27 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2010-08-05 13:27 . 2010-08-05 13:27 45056 ----a-w- c:\windows\system32\dataclen.dll
2010-08-05 13:27 . 2010-08-05 13:27 36864 ----a-w- c:\windows\system32\cdd.dll
2010-08-05 13:26 . 2010-08-05 13:26 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2010-08-05 13:26 . 2010-08-05 13:26 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2010-08-05 13:26 . 2010-08-05 13:26 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2010-08-05 13:25 . 2010-08-05 13:25 1334272 ----a-w- c:\windows\system32\msxml6.dll
2010-08-05 13:25 . 2010-08-05 13:25 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2010-08-05 13:25 . 2010-08-05 13:25 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2010-08-05 13:25 . 2010-08-05 13:25 443392 ----a-w- c:\windows\system32\win32spl.dll
2010-08-05 13:25 . 2010-08-05 13:25 885248 ----a-w- c:\windows\system32\RacEngn.dll
2010-08-05 13:24 . 2010-08-05 13:24 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2010-08-05 13:24 . 2010-08-05 13:24 15360 ----a-w- c:\windows\system32\pacerprf.dll
2010-08-05 13:24 . 2010-08-05 13:24 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2010-08-05 13:24 . 2010-08-05 13:24 94720 ----a-w- c:\windows\system32\logagent.exe
2010-08-05 13:24 . 2010-08-05 13:24 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2010-08-05 13:24 . 2010-08-05 13:24 38912 ----a-w- c:\windows\system32\xolehlp.dll
2010-08-05 13:24 . 2010-08-05 13:24 90112 ----a-w- c:\windows\system32\wshext.dll
2010-08-05 13:24 . 2010-08-05 13:24 180224 ----a-w- c:\windows\system32\scrobj.dll
2010-08-05 13:24 . 2010-08-05 13:24 172032 ----a-w- c:\windows\system32\scrrun.dll
2010-08-05 13:24 . 2010-08-05 13:24 155648 ----a-w- c:\windows\system32\wscript.exe
2010-08-05 13:24 . 2010-08-05 13:24 135168 ----a-w- c:\windows\system32\cscript.exe
2010-08-05 13:23 . 2010-08-05 13:23 269312 ----a-w- c:\windows\system32\es.dll
2010-08-05 13:23 . 2010-08-05 13:23 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2010-08-05 13:23 . 2010-08-05 13:23 529464 ----a-w- c:\windows\system32\drivers\ndis.sys
2010-08-05 13:20 . 2010-08-05 13:20 574976 ----a-w- c:\windows\system32\sysmain.dll
2010-08-05 13:19 . 2006-11-02 08:30 141880 ----a-w- c:\windows\system32\halacpi.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Google Update"="c:\users\LENOVO\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-08-26 136176]
"ManyCam"="c:\program files\ManyCam 2.4\ManyCam.exe" [2010-04-21 1824040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-10-07 256576]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-04-26 61728]
"TpShocks"="TpShocks.exe" [2009-02-03 181536]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-04-14 15136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-19 1434920]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-12 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-12 145944]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2009-01-28 185688]
"LPMailChecker"="c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-01-28 124248]
"RoxioDragToDisc"="c:\program files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 1116920]
"Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-04-22 49976]
"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2009-04-15 660768]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2009-04-15 214576]
"CreateLMBCShortCut"="c:\program files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe" [2009-04-13 40960]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2009-04-16 435488]
"ACWlIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWlIcon.exe" [2009-04-16 177440]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2009-03-05 3093816]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-8-5 50688]
ShortKeys 2.lnk - c:\program files\ShortKeys2\shortkey.exe [2010-8-25 2767360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumon.sys [2008-07-11 48192]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-03-30 45424]
R3 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [2008-10-27 106496]
R3 MUXP;My WiFi PAN Mux-IM Protocol Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-09 29232]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2009-02-11 204800]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
R4 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-10-09 360448]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2009-01-29 20520]
S1 aswSP;aswSP; [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [2008-10-27 1676536]
S2 DDNIOEMService;DDNIOEMService;c:\program files\DDNI\SBITS\DDNIOEMService.exe [2007-09-28 162280]
S2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [2008-10-27 98304]
S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2009-04-15 66848]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-09-03 173352]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-04-02 62320]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2008-05-24 520192]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-09-19 3881472]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2008-09-19 54784]
S3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2008-10-27 482176]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-08-22 225408]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdkmd32.sys [2008-06-12 2381312]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-09 29232]
S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-02-09 3715072]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2008-02-22 37312]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder

2010-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000Core.job
- c:\users\LENOVO\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-26 17:30]

2010-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000UA.job
- c:\users\LENOVO\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-26 17:30]

2010-08-05 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PCDR5\pcdr5cuiw32.exe [2009-02-20 20:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-11 00:45
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(4832)
c:\program files\ShortKeys2\shkHook.dll
c:\program files\Lenovo\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Lenovo\Drag-to-Disc\ShellRes.dll
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\program files\ThinkPad\Utilities\EZEJMNAP.EXE
c:\windows\System32\TpShocks.exe
c:\program files\ThinkVantage\PrdCtr\LPMGR.EXE
c:\program files\ThinkVantage\PrdCtr\LPMLCHK.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\windows\System32\rundll32.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\program files\Alwil Software\Avast5\AvastUI.exe
c:\users\LENOVO\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\ThinkPad\UTILIT~1\PWMUIAux.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\System32\TPHDEXLG.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
.
**************************************************************************
.
Completion time: 2010-09-11 00:50:48 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-10 23:50

Pre-Run: 84,965,621,760 bytes free
Post-Run: 84,950,016,000 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - B503E4842EC1579E2CD35D3860FED02F
  • 0

#9
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello nortan360,

Further to my comment about PCDoctor.

When I research this further it appears there is also a legitimate PCDoctor which is a hardware diagnostic tool from a company PC-Doctor, Inc. belonging to product Hardware Diagnostic Tools. Lenova machines seem to have this.

Let's check yours to make sure it is the legitimate one:

  • c:\program files\PCDR5\pcdr5cuiw32.exe
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

  • 0

#10
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
Im scanning it now i think i might also have a hardware problem ive been warned a couple of days ago that i have low memory and also every time i get a blue screen it says the same thing


It looks clean although i have never seen pcdoctor working or do anything
Posted Image
  • 0

Advertisements


#11
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello nortan360,

It looks clean although i have never seen pcdoctor working or do anything


I don't know for sure but I think it's part of Lenova System Toolbox and monitors for system for problems.

Im scanning it now i think i might also have a hardware problem ive been warned a couple of days ago that i have low memory and also every time i get a blue screen it says the same thing


Not something I can help you with although with 2Gigabytes of memory I wouldn't have thought there would be a problem there. Sometimes memory can be faulty though.

We need to finish the cleaning process and then you can seek technical assistance if you still have a problem.

Now

Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job.

Kaspersky works with Internet Explorer and Firefox 3. It uses Java Runtime Environment (JRE) .

Go to Kaspersky website and perform an online antivirus scan.

Note: you will need to turn off your security programs to allow Kaspersky to do its job.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start dowanloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Copy and paste that information in your next post.
  • 0

#12
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, September 13, 2010
Operating system: Microsoft Windows Vista Business Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, September 13, 2010 11:32:59
Records in database: 4213809
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
Q:\
S:\

Scan statistics:
Objects scanned: 144329
Threats found: 1
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 02:16:00


File name / Threat / Threats count
C:\$RECYCLE.BIN\S-1-5-21-1853308285-865056411-922338472-1000\$RM3ZWW3\Pirater les contacts.js Infected: Backdoor.JS.Agent.a 1
C:\Program Files\Messenger Plus! Live\Scripts\Pirates contacts\Pirater les contacts.js Infected: Backdoor.JS.Agent.a 1

Selected area has been scanned.
  • 0

#13
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello nortan360,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

File::
C:\$RECYCLE.BIN\S-1-5-21-1853308285-865056411-922338472-1000\$RM3ZWW3\Pirater les contacts.js
C:\Program Files\Messenger Plus! Live\Scripts\Pirates contacts\Pirater les contacts.js

Reboot::


Save this as CFScript.txt, in the same location as ComboFix.exe

Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review.
  • 0

#14
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts
ComboFix 10-09-08.03 - LENOVO 15/09/2010 17:06:21.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.44.1033.18.1943.803 [GMT 1:00]
Running from: c:\users\LENOVO\Desktop\ComboFix.exe
Command switches used :: c:\users\LENOVO\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
"c:\$recycle.bin\S-1-5-21-1853308285-865056411-922338472-1000\$RM3ZWW3\Pirater les contacts.js"
"c:\program files\Messenger Plus! Live\Scripts\Pirates contacts\Pirater les contacts.js"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Messenger Plus! Live\Scripts\Pirates contacts\Pirater les contacts.js

.
((((((((((((((((((((((((( Files Created from 2010-08-15 to 2010-09-15 )))))))))))))))))))))))))))))))
.

2010-09-15 16:07 . 2010-09-15 16:10 -------- d-----w- c:\users\LENOVO\AppData\Local\temp
2010-09-15 16:07 . 2010-09-15 16:07 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-15 16:07 . 2010-09-15 16:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-15 16:03 . 2010-09-15 16:03 -------- d-----w- C:\32788R22FWJFW
2010-09-13 18:57 . 2010-09-13 18:57 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Doctor Who
2010-09-13 18:53 . 2010-09-13 18:53 -------- d-----w- c:\users\LENOVO\AppData\Local\Doctor Who
2010-09-13 18:51 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2010-09-13 18:51 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-09-13 18:51 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-09-13 18:51 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-09-13 18:51 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-09-13 18:51 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-09-13 18:51 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-09-13 18:51 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-09-13 18:48 . 2010-09-13 18:53 -------- d-----w- c:\program files\Doctor Who - The Adventure Games
2010-09-13 14:24 . 2010-09-13 14:24 -------- d-----w- c:\program files\The Hat
2010-09-09 20:00 . 2010-09-09 20:09 -------- d-----w- c:\users\LENOVO\AppData\Roaming\PFStaticIP
2010-09-09 20:00 . 2010-09-09 20:00 -------- d-----w- c:\program files\PFStaticIP
2010-09-09 15:15 . 2010-09-09 15:15 -------- d-----w- C:\_OTL
2010-09-08 21:42 . 2010-09-08 21:42 -------- d-----w- c:\users\LENOVO\AppData\Roaming\.minecraft
2010-09-07 22:27 . 2010-09-07 22:27 -------- d-----w- c:\program files\TeamViewer
2010-09-03 00:10 . 2010-09-03 00:10 -------- d-----w- c:\program files\ZD Soft
2010-09-02 14:18 . 2010-09-09 23:58 -------- d-----w- c:\program files\Cheat Engine
2010-09-02 14:18 . 2009-11-03 13:07 679936 ----a-w- c:\windows\system32\D3DX81ab.dll
2010-09-02 14:18 . 2009-11-03 13:07 1970176 ----a-w- c:\windows\system32\d3dx9.dll
2010-09-02 13:28 . 2010-09-02 13:32 -------- d-----w- c:\program files\ManyCam 2.4
2010-09-02 13:28 . 2010-09-02 13:32 -------- d-----w- c:\users\LENOVO\AppData\Roaming\ManyCam
2010-09-02 13:28 . 2010-09-09 15:15 -------- d-----w- c:\program files\Ask.com
2010-09-02 00:16 . 2010-09-02 00:16 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Malwarebytes
2010-09-02 00:15 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-02 00:15 . 2010-09-02 00:15 -------- d-----w- c:\programdata\Malwarebytes
2010-09-02 00:15 . 2010-09-02 00:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-02 00:15 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-01 23:05 . 2010-09-03 01:32 -------- d-----w- c:\programdata\Messenger Plus!
2010-09-01 23:04 . 2010-09-01 23:04 -------- d-----w- c:\program files\Messenger Plus! Live
2010-09-01 22:55 . 2010-09-01 22:55 -------- d-----w- c:\program files\QS
2010-09-01 22:54 . 2010-09-01 22:54 -------- d-----w- c:\users\LENOVO\AppData\Roaming\TeamViewer
2010-08-29 23:41 . 2010-09-01 19:13 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Apple Computer
2010-08-29 23:41 . 2010-08-29 23:41 -------- d-----w- c:\users\LENOVO\AppData\Local\Apple Computer
2010-08-29 23:41 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-08-29 23:41 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-08-29 23:40 . 2010-08-29 23:40 -------- d-----w- c:\program files\iPod
2010-08-29 23:40 . 2010-08-29 23:41 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-29 23:40 . 2010-08-29 23:41 -------- d-----w- c:\program files\iTunes
2010-08-29 23:38 . 2010-08-29 23:39 -------- d-----w- c:\program files\QuickTime
2010-08-29 23:38 . 2010-08-29 23:40 -------- d-----w- c:\programdata\Apple Computer
2010-08-29 23:37 . 2010-08-29 23:37 -------- d-----w- c:\users\LENOVO\AppData\Local\Apple
2010-08-29 23:37 . 2010-08-29 23:37 -------- d-----w- c:\program files\Apple Software Update
2010-08-29 23:34 . 2010-08-29 23:34 -------- d-----w- c:\program files\Bonjour
2010-08-29 23:34 . 2010-09-01 19:13 -------- d-----w- c:\programdata\Apple
2010-08-29 23:34 . 2010-08-29 23:40 -------- d-----w- c:\program files\Common Files\Apple
2010-08-29 22:15 . 2010-08-29 22:15 1732 ----a-w- C:\tvtpktfilter.dat
2010-08-28 11:01 . 2010-08-28 11:01 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-08-28 10:57 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-28 10:57 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-28 10:57 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-08-28 10:57 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-28 10:57 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-08-27 14:12 . 2008-11-10 10:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-08-27 14:12 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-08-27 14:11 . 2010-08-28 11:00 -------- d-----w- c:\program files\Microsoft Works
2010-08-27 14:10 . 2010-08-27 14:10 -------- d-----w- c:\program files\Microsoft.NET
2010-08-27 14:08 . 2010-08-27 14:08 -------- d-----w- c:\users\LENOVO\AppData\Local\Microsoft Help
2010-08-27 14:08 . 2010-08-29 11:33 -------- d-----w- c:\programdata\Microsoft Help
2010-08-27 14:07 . 2010-08-27 14:07 -------- d-----r- C:\MSOCache
2010-08-27 10:51 . 2010-08-27 10:51 229208 ----a-w- c:\windows\system32\drivers\VMM.sys
2010-08-26 18:07 . 2010-08-26 18:07 -------- d-----w- c:\users\LENOVO\AppData\Local\Adobe
2010-08-26 17:30 . 2010-08-26 17:31 -------- d-----w- c:\users\LENOVO\AppData\Local\Google
2010-08-26 17:30 . 2010-08-26 17:30 -------- d-----w- c:\users\LENOVO\AppData\Local\Deployment
2010-08-26 17:30 . 2010-08-26 17:30 -------- d-----w- c:\users\LENOVO\AppData\Local\Apps
2010-08-26 15:37 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-08-26 15:37 . 2009-08-24 12:16 378368 ----a-w- c:\windows\system32\winhttp.dll
2010-08-26 13:51 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-08-26 13:42 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2010-08-26 13:42 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-08-26 13:42 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2010-08-26 13:42 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2010-08-26 13:42 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2010-08-26 13:37 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2010-08-26 13:36 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2010-08-26 13:34 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-08-26 13:34 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-08-26 13:34 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-08-26 13:33 . 2010-08-26 13:33 -------- d-----w- c:\program files\MSXML 4.0
2010-08-26 13:27 . 2010-09-04 23:39 7728 ----a-w- c:\users\LENOVO\AppData\Local\d3d9caps.dat
2010-08-25 23:25 . 2010-08-25 23:25 -------- d-----w- c:\users\LENOVO\AppData\Local\Roblox
2010-08-25 20:42 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2010-08-25 18:54 . 2010-08-25 18:54 -------- d-----w- c:\programdata\Insight Software
2010-08-25 18:54 . 2010-08-25 18:54 -------- d-----w- c:\program files\Common Files\Insight Software Solutions
2010-08-25 18:54 . 2010-08-25 18:54 -------- d-----w- c:\program files\ShortKeys2
2010-08-25 18:31 . 2010-08-25 18:31 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-08-25 18:04 . 2010-08-25 18:04 -------- d-----w- c:\windows\system32\Adobe
2010-08-25 17:49 . 2010-08-25 17:49 -------- d-----w- c:\program files\Microsoft Virtual PC
2010-08-25 17:34 . 2010-09-15 15:40 -------- d-----w- c:\users\LENOVO\Tracing
2010-08-25 17:32 . 2010-09-14 18:38 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-25 17:32 . 2010-08-29 23:41 -------- dc----w- c:\windows\system32\DRVSTORE
2010-08-25 17:32 . 2010-04-28 06:44 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-08-25 17:30 . 2010-08-25 17:30 -------- d-----w- c:\programdata\Insight Software Solutions
2010-08-25 17:30 . 2010-08-25 17:30 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-08-25 17:28 . 2010-08-25 17:28 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-25 17:26 . 2010-08-25 17:26 -------- d-----w- c:\program files\Microsoft
2010-08-25 17:26 . 2010-08-25 17:26 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-08-25 17:26 . 2010-08-25 17:32 -------- d-----w- c:\program files\Windows Live
2010-08-25 17:25 . 2010-08-25 17:25 -------- d-----w- c:\windows\PCHEALTH
2010-08-25 17:20 . 2010-08-25 17:20 -------- d-----w- c:\program files\Common Files\Windows Live
2010-08-25 16:51 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-08-25 16:50 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-25 16:45 . 2010-05-21 13:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-08-25 16:10 . 2009-12-23 12:43 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-08-25 16:10 . 2010-01-15 00:04 98304 ----a-w- c:\windows\system32\cabview.dll
2010-08-25 16:07 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-25 16:07 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-25 16:07 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-25 16:07 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-25 16:07 . 2010-09-07 14:47 50768 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-25 16:06 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-08-25 16:06 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-25 16:06 . 2010-08-25 16:06 -------- d-----w- c:\programdata\Alwil Software
2010-08-25 16:06 . 2010-08-25 16:06 -------- d-----w- c:\program files\Alwil Software
2010-08-25 16:03 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-08-25 16:03 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2010-08-25 16:03 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2010-08-25 16:03 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2010-08-25 16:03 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2010-08-25 16:03 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-04 20:33 . 2010-09-04 20:33 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-08-28 16:49 . 2010-08-05 21:55 74912 ----a-w- c:\users\LENOVO\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-27 01:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-25 18:48 . 2010-08-05 13:56 -------- d-----w- c:\programdata\Lenovo
2010-08-25 17:31 . 2010-08-05 21:55 -------- d-----w- c:\program files\Windows Live Toolbar
2010-08-08 11:31 . 2010-08-08 11:31 -------- d-----w- c:\users\LENOVO\AppData\Roaming\InterVideo
2010-08-05 21:58 . 2010-08-05 21:57 -------- d-----w- c:\users\LENOVO\AppData\Roaming\Lenovo
2010-08-05 21:57 . 2010-08-05 21:57 -------- d-----w- c:\users\LENOVO\AppData\Roaming\ATI
2010-08-05 21:57 . 2010-08-05 21:57 -------- d-----w- c:\programdata\ATI
2010-08-05 21:56 . 2010-08-05 13:45 100 ----a-w- c:\windows\system32\drivers\Lenovo_6475_WRB.MRK
2010-08-05 21:56 . 2010-08-05 14:04 -------- d-----w- c:\program files\Common Files\Lenovo
2010-08-05 14:20 . 2010-08-05 14:20 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-05 14:14 . 2010-08-05 13:44 -------- d-----w- c:\program files\Lenovo
2010-08-05 14:14 . 2010-08-05 14:07 -------- d-----w- c:\program files\PCDR5
2010-08-05 14:13 . 2010-08-05 14:13 -------- d-----w- c:\programdata\DDNI
2010-08-05 14:13 . 2010-08-05 14:13 -------- d-----w- c:\program files\DDNI
2010-08-05 14:12 . 2010-08-05 13:45 -------- d-----w- c:\program files\ThinkPad
2010-08-05 14:12 . 2010-08-05 14:12 -------- d-----w- c:\program files\Digital Line Detect
2010-08-05 14:12 . 2010-08-05 13:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-05 14:12 . 2010-08-05 14:12 -------- d-----w- c:\program files\NetWaiting
2010-08-05 14:12 . 2010-08-05 13:47 -------- d-----w- c:\program files\CONEXANT
2010-08-05 14:08 . 2010-08-05 14:08 33536 ----a-w- c:\windows\system32\drivers\tvtfilter.sys
2010-08-05 14:07 . 2010-08-05 14:08 118520 ------w- c:\windows\system32\pxinsi64.exe
2010-08-05 14:07 . 2010-08-05 14:08 129784 ------w- c:\windows\system32\pxafs.dll
2010-08-05 14:07 . 2010-08-05 14:08 116472 ------w- c:\windows\system32\pxcpyi64.exe
2010-08-05 14:07 . 2010-08-05 14:07 -------- d-----w- c:\program files\Verizon Wireless
2010-08-05 14:07 . 2010-08-05 14:07 -------- d-----w- c:\programdata\PCDr
2010-08-05 14:07 . 2010-08-05 14:07 -------- d-----w- c:\programdata\PC-Doctor for Windows
2010-08-05 14:01 . 2010-08-05 14:01 410984 ----a-w- c:\windows\system32\deploytk.dll
2010-08-05 14:01 . 2010-08-05 14:01 -------- d-----w- c:\program files\Java
2010-08-05 14:01 . 2010-08-05 14:01 -------- d-----w- c:\program files\Sonic Icons for Lenovo
2010-08-05 14:01 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-08-05 14:01 . 2010-08-05 14:01 -------- d-----w- c:\programdata\Uninstall
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\program files\Roxio
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\Sonic Shared
2010-08-05 14:00 . 2010-08-05 14:00 -------- d-----w- c:\programdata\InstallShield
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\programdata\Roxio
2010-08-05 14:00 . 2010-08-05 14:00 -------- d-----w- c:\programdata\Sonic
2010-08-05 14:00 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-08-05 13:59 . 2010-08-05 13:45 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-05 13:59 . 2010-08-05 13:59 -------- d-----w- c:\program files\Common Files\SureThing Shared
2010-08-05 13:59 . 2010-08-05 13:56 -------- d-----w- c:\program files\ThinkVantage
2010-08-05 13:58 . 2010-08-05 13:58 -------- d-----w- c:\program files\InterVideo
2010-08-05 13:57 . 2010-08-05 13:57 -------- d-----w- c:\program files\Common Files\InterVideo
2010-08-05 13:57 . 2010-08-05 13:57 -------- d-----w- c:\program files\Lenovo Registration
2010-08-05 13:56 . 2010-08-05 13:56 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-05 13:56 . 2010-08-05 13:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-05 13:55 . 2010-08-05 13:55 -------- d-----w- c:\program files\Lenovo Group Limited
2010-08-05 13:55 . 2010-08-05 13:55 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ATSwpWDF_01005.Wdf
2010-08-05 13:55 . 2010-08-05 13:43 -------- d-----w- c:\program files\DIFX
2010-08-05 13:55 . 2010-08-05 13:55 -------- d-----w- c:\program files\Lenovo Fingerprint Software
2010-08-05 13:51 . 2010-08-05 13:49 -------- d-----w- c:\program files\ATI Technologies
2010-08-05 13:49 . 2010-08-05 13:49 -------- d-----w- c:\program files\ATI
2010-08-05 13:49 . 2010-08-05 13:49 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2010-08-05 13:49 . 2010-08-05 13:49 -------- d-----w- c:\program files\Synaptics
2010-08-05 13:48 . 2010-08-05 13:48 -------- d-----w- c:\programdata\Roaming
2010-08-05 13:47 . 2010-08-05 13:47 -------- d-----w- c:\program files\Cisco
2010-08-05 13:47 . 2010-08-05 13:47 -------- d-----w- c:\programdata\Intel
2010-08-05 13:47 . 2010-08-05 13:47 -------- d-----w- c:\program files\Common Files\Intel
2010-08-05 13:47 . 2010-08-05 13:45 -------- d-----w- c:\program files\Intel
2010-08-05 13:32 . 2010-08-05 13:32 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-08-05 13:32 . 2010-08-05 13:32 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-08-05 13:31 . 2010-08-05 13:31 24064 ----a-w- c:\windows\system32\amxread.dll
2010-08-05 13:31 . 2010-08-05 13:31 13824 ----a-w- c:\windows\system32\apilogen.dll
2010-08-05 13:31 . 2010-08-05 13:31 1645568 ----a-w- c:\windows\system32\connect.dll
2010-08-05 13:30 . 2010-08-05 13:30 2927104 ----a-w- c:\windows\explorer.exe
2010-08-05 13:29 . 2010-08-05 13:29 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2010-08-05 13:29 . 2010-08-05 13:29 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2010-08-05 13:29 . 2010-08-05 13:29 347648 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2010-08-05 13:27 . 2010-08-05 13:27 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-08-05 13:27 . 2010-08-05 13:27 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2010-08-05 13:27 . 2010-08-05 13:27 45056 ----a-w- c:\windows\system32\dataclen.dll
2010-08-05 13:27 . 2010-08-05 13:27 36864 ----a-w- c:\windows\system32\cdd.dll
2010-08-05 13:26 . 2010-08-05 13:26 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2010-08-05 13:26 . 2010-08-05 13:26 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2010-08-05 13:26 . 2010-08-05 13:26 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2010-08-05 13:25 . 2010-08-05 13:25 1334272 ----a-w- c:\windows\system32\msxml6.dll
2010-08-05 13:25 . 2010-08-05 13:25 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2010-08-05 13:25 . 2010-08-05 13:25 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2010-08-05 13:25 . 2010-08-05 13:25 443392 ----a-w- c:\windows\system32\win32spl.dll
2010-08-05 13:25 . 2010-08-05 13:25 885248 ----a-w- c:\windows\system32\RacEngn.dll
2010-08-05 13:24 . 2010-08-05 13:24 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2010-08-05 13:24 . 2010-08-05 13:24 15360 ----a-w- c:\windows\system32\pacerprf.dll
2010-08-05 13:24 . 2010-08-05 13:24 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2010-08-05 13:24 . 2010-08-05 13:24 94720 ----a-w- c:\windows\system32\logagent.exe
2010-08-05 13:24 . 2010-08-05 13:24 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2010-08-05 13:24 . 2010-08-05 13:24 38912 ----a-w- c:\windows\system32\xolehlp.dll
2010-08-05 13:24 . 2010-08-05 13:24 90112 ----a-w- c:\windows\system32\wshext.dll
2010-08-05 13:24 . 2010-08-05 13:24 180224 ----a-w- c:\windows\system32\scrobj.dll
2010-08-05 13:24 . 2010-08-05 13:24 172032 ----a-w- c:\windows\system32\scrrun.dll
2010-08-05 13:24 . 2010-08-05 13:24 155648 ----a-w- c:\windows\system32\wscript.exe
2010-08-05 13:24 . 2010-08-05 13:24 135168 ----a-w- c:\windows\system32\cscript.exe
2010-08-05 13:23 . 2010-08-05 13:23 269312 ----a-w- c:\windows\system32\es.dll
2010-08-05 13:23 . 2010-08-05 13:23 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2010-08-05 13:23 . 2010-08-05 13:23 529464 ----a-w- c:\windows\system32\drivers\ndis.sys
2010-08-05 13:20 . 2010-08-05 13:20 574976 ----a-w- c:\windows\system32\sysmain.dll
2010-08-05 13:19 . 2006-11-02 08:30 141880 ----a-w- c:\windows\system32\halacpi.dll
2010-08-05 13:19 . 2006-11-02 08:30 177208 ----a-w- c:\windows\system32\halmacpi.dll
2010-06-26 06:05 . 2010-08-25 20:45 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-25 20:45 71680 ----a-w- c:\windows\system32\iesetup.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Google Update"="c:\users\LENOVO\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-08-26 136176]
"ManyCam"="c:\program files\ManyCam 2.4\ManyCam.exe" [2010-04-21 1824040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-10-07 256576]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-04-26 61728]
"TpShocks"="TpShocks.exe" [2009-02-03 181536]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-04-14 15136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-19 1434920]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-12 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-12 145944]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2009-01-28 185688]
"LPMailChecker"="c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-01-28 124248]
"RoxioDragToDisc"="c:\program files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 1116920]
"Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-04-22 49976]
"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2009-04-15 660768]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2009-04-15 214576]
"CreateLMBCShortCut"="c:\program files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe" [2009-04-13 40960]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2009-04-16 435488]
"ACWlIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWlIcon.exe" [2009-04-16 177440]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2009-03-05 3093816]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-8-5 50688]
ShortKeys 2.lnk - c:\program files\ShortKeys2\shortkey.exe [2010-8-25 2767360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumon.sys [2008-07-11 48192]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-03-30 45424]
R3 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [2008-10-27 106496]
R3 MUXP;My WiFi PAN Mux-IM Protocol Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-09 29232]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2009-02-11 204800]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
R4 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-10-09 360448]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2009-01-29 20520]
S1 aswSP;aswSP; [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [2008-10-27 1676536]
S2 DDNIOEMService;DDNIOEMService;c:\program files\DDNI\SBITS\DDNIOEMService.exe [2007-09-28 162280]
S2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [2008-10-27 98304]
S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2009-04-15 66848]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-09-03 173352]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-04-02 62320]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2008-05-24 520192]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-09-19 3881472]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2008-09-19 54784]
S3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2008-10-27 482176]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-08-22 225408]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdkmd32.sys [2008-06-12 2381312]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-09 29232]
S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-02-09 3715072]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2008-02-22 37312]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder

2010-09-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000Core.job
- c:\users\LENOVO\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-26 17:30]

2010-09-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853308285-865056411-922338472-1000UA.job
- c:\users\LENOVO\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-26 17:30]

2010-08-05 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PCDR5\pcdr5cuiw32.exe [2009-02-20 20:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-15 17:09
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(6044)
c:\program files\Lenovo\Client Security Solution\tvtpwm_windows_hook.dll
c:\program files\Lenovo\Client Security Solution\tvtpwm_interface.dll
c:\program files\ShortKeys2\shkHook.dll
c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL
c:\progra~1\ThinkPad\UTILIT~1\US\PWMRT32V.DLL
c:\progra~1\ThinkPad\UTILIT~1\PWMIF32V.DLL
c:\program files\Lenovo\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Lenovo\Drag-to-Disc\ShellRes.dll
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\program files\ThinkPad\Utilities\EZEJMNAP.EXE
c:\windows\System32\TpShocks.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\ThinkVantage\PrdCtr\LPMGR.EXE
c:\program files\ThinkVantage\PrdCtr\LPMLCHK.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\System32\rundll32.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\program files\Alwil Software\Avast5\AvastUI.exe
c:\program files\Synaptics\SynTP\SynTPLpr.exe
c:\users\LENOVO\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Lenovo\Client Security Solution\password_manager.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\System32\TPHDEXLG.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Common Files\Lenovo\bmgr\bmgr32.exe
c:\windows\servicing\TrustedInstaller.exe
c:\progra~1\ThinkPad\UTILIT~1\PWMUIAux.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2010-09-15 17:22:27 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-15 16:22
ComboFix2.txt 2010-09-10 23:50

Pre-Run: 83,472,093,184 bytes free
Post-Run: 83,477,131,264 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,11
- - End Of File - - 75968FF14A090FB2EF865768809328A5
  • 0

#15
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello nortan360,

I think your machine is clean.

As far as the memory problem is concerned I think there is a fairly simple setting change that will increase the virtual memory on your computer. However I am not a techie and it might be that the people who know about these things will give you a different answer. Here is a link to the Vista OS forum here. Hopefully someone there with be able to help you. If you do go there be sure and tell them you have been here first.

http://www.geekstogo...-and-windows-7/

Now

We have a couple of last steps to perform and then you're all set.Posted Image

Follow these steps to uninstall Combofix and tools used in the removal of malware. This will also clean out and reset your Restore Points.
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    Posted Image
Step 2
  • Double-click OTL.exe to run it. (Vista users, please right click on OTL.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

MBAM can be uninstalled via control panel add/remove but it may be a useful tool to keep.

-------------------------------------------------------------------------------------------------------------------

A reminder: Remember to turn back on any anti-malware programs you may have turned off during the cleaning process.

-------------------------------------------------------------------------------------------------------------------

Now that your machine is clean here are some things that I think are worth having a look at if you don't already know a bout them:

---------------------------------------------------------------------------------------------------------------------

Regularly check that your Java is up to date. Older versions are vunerable to malicious attack.
  • Download from here Java Runtime Environment (JDK) Update
  • Scroll to where it says "Windows XP/Vista/2000/2003/2008 online" and download and follow the instructions to install.

    Reboot your computer.
    You also need to uininstall older versions of Java.
  • Click Start > Control Panel > Programs
  • Remove all Java updates except the latest one you have just installed.
--------------------------------------------------------------------------------------------------------------------

Be sure and give the Temp folders a cleaning out now and then. This helps with security and your computer will run more efficiently. I clean mine once a week.

For ease of use, you might consider the following free program:--------------------------------------------------------------------------------------------------------------------

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
* Consider using an alternate browser.

Opera may be downloaded from here. It is one of the least targeted of all browers.

Avant may be downloaded from here. Another one that is less well known.

Firefox may be downloaded from Here. I use Firefox because I like it. Used to be one of the safest but now targeted probably as much as IE.

Adblock Plus is a good Add-on for Firefox that helps prevent those annoying pop ups.

-----------------------------------------------------------------------------------------------------------------------

To help protect your computer in the future here are some free programs you can look at:

  • If you do not already have automatic updates set then it is recommended that you do set Windows to check, download and install your updates automatically.

    * Click Start > Control Panel > System and Security > Windows Update
    * Under Windows Update click on Turn automatic updating on or off
    * Check items shown to ensure you receive updates automatically. Click OK.

    And to keep your system clean consider choosing from these free for home use malware scanners and updating and running weekly.
  • Malwarebytes
  • SuperAntiSpyWare
Be aware of what emails you open and websites you visit.

Go here for some good advice about how to prevent infection.

Have a safe and happy computing day!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP