[code] OTScanIt2 logfile created on: 16/12/2008 1:17:41 - Run 1 OTScanIt2 by OldTimer - Version 1.0.3.1 Folder = C:\Documents and Settings\WXP\Desktop\OTScanIt2 Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000C0A | Country: Spain | Language: ESN | Date Format: dd/MM/yyyy 1023,48 Mb Total Physical Memory | 178,56 Mb Available Physical Memory | 17,45% Memory free 2,40 Gb Paging File | 1,70 Gb Available in Paging File | 70,80% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072; %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 114,48 Gb Total Space | 28,75 Gb Free Space | 25,11% Space Free | Partition Type: NTFS Drive D: | 37,26 Gb Total Space | 4,72 Gb Free Space | 12,67% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: XPP-EF15FC4F71A Current User Name: WXP Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Whitelist: On File Age = 30 Days [Processes - Safe List] avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2008/08/19 09:41:46 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> [2008/11/27 12:37:18 | 01,261,336 | ---- | M] (AVG Technologies CZ, s.r.o.) avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/08/29 07:58:14 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) bgsvcgen.exe -> %SystemRoot%\system32\bgsvcgen.exe -> [2005/04/30 16:02:26 | 00,086,016 | ---- | M] (B.H.A Corporation) cleanmgr.exe -> %SystemRoot%\system32\cleanmgr.exe -> [2008/04/14 01:12:14 | 00,064,000 | ---- | M] (Microsoft Corporation) communications_helper.exe -> %CommonProgramFiles%\LogiShrd\LComMgr\Communications_Helper.exe -> [2007/03/06 16:48:46 | 00,488,984 | ---- | M] (Labtec Inc,) dkservice.exe -> %ProgramFiles%\Diskeeper Corporation\Diskeeper\DkService.exe -> [2005/11/23 06:58:04 | 00,765,952 | ---- | M] (Diskeeper Corporation) ezprint.exe -> %ProgramFiles%\Lexmark 5400 Series\ezprint.exe -> [2007/03/19 13:58:20 | 00,082,864 | ---- | M] (Lexmark International Inc.) fm3032.exe -> %ProgramFiles%\Lexmark 5400 Series\fm3032.exe -> [2007/03/19 13:59:49 | 00,304,048 | ---- | M] () jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2008/11/10 05:43:40 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) lvcomsx.exe -> %CommonProgramFiles%\LogiShrd\LComMgr\LVComSX.exe -> [2007/03/06 16:51:26 | 00,252,704 | ---- | M] (Labtec Inc.) lxctcoms.exe -> %SystemRoot%\system32\lxctcoms.exe -> [2007/03/19 13:58:47 | 00,537,520 | ---- | M] ( ) lxctmon.exe -> %ProgramFiles%\Lexmark 5400 Series\lxctmon.exe -> [2007/03/19 13:58:17 | 00,291,760 | ---- | M] () mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2002/01/05 09:00:38 | 00,315,392 | ---- | M] (Microsoft Corporation) nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2006/10/22 21:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/12/12 09:24:20 | 00,477,184 | ---- | M] (OldTimer Tools) phototoolkitmem.exe -> %ProgramFiles%\Photo Toolkit\IvBar\phototoolkitmem.exe -> [2006/10/27 20:34:00 | 00,065,536 | ---- | M] (VicMan Software) skype.exe -> %ProgramFiles%\Skype\Phone\Skype.exe -> [2007/06/08 14:18:00 | 23,233,576 | R--- | M] (Skype Technologies S.A.) skypepm.exe -> %ProgramFiles%\Skype\Plugin Manager\skypePM.exe -> [2007/06/08 14:18:00 | 01,928,136 | R--- | M] (Skype Technologies) syncservices.exe -> %ProgramFiles%\Maxtor\Sync\SyncServices.exe -> [2007/09/28 11:24:36 | 00,156,976 | ---- | M] (Seagate Technology LLC) webcam10.exe -> %ProgramFiles%\Labtec\WebCam10\WebCam10.exe -> [2007/03/06 16:58:16 | 01,060,376 | ---- | M] () winpatrol.exe -> %ProgramFiles%\BillP Studios\WinPatrol\WinPatrol.exe -> [2008/10/09 16:52:54 | 00,333,120 | ---- | M] (BillP Studios) wlan.exe -> %ProgramFiles%\3COM Technology Corporation\3COM Wireless USB Utility\Wlan.exe -> [2004/10/22 13:28:26 | 00,389,120 | ---- | M] (3COM) [Win32 Services - Safe List] (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 00:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) (avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/08/29 07:58:14 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) (bgsvcgen) B's Recorder GOLD Library General Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\bgsvcgen.exe -> [2005/04/30 16:02:26 | 00,086,016 | ---- | M] (B.H.A Corporation) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 00:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) (Diskeeper) Diskeeper [Win32_Own | Auto | Running] -> %ProgramFiles%\Diskeeper Corporation\Diskeeper\DkService.exe -> [2005/11/23 06:58:04 | 00,765,952 | ---- | M] (Diskeeper Corporation) (GoogleDesktopManager-061008-081103) Google Desktop Manager 5.7.806.10245 [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/08/12 14:29:51 | 00,029,744 | ---- | M] (Google) (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/10/20 08:45:36 | 00,168,432 | ---- | M] (Google) (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\pchealth\helpctr\binaries\pchsvc.dll -> [2008/04/14 01:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1150\Intel 32\IDriverT.exe -> [2005/11/14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) (iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2007/06/01 15:51:22 | 00,501,312 | ---- | M] (Apple Inc.) (JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2008/11/10 05:43:40 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) (LVSrvLauncher) LVSrvLauncher [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\LogiShrd\SrvLnch\SrvLnch.exe -> [2007/03/06 16:55:24 | 00,105,248 | ---- | M] (Labtec Inc.) (lxct_device) lxct_device [Win32_Own | Auto | Running] -> %SystemRoot%\system32\lxctcoms.exe -> [2007/03/19 13:58:47 | 00,537,520 | ---- | M] ( ) (Maxtor Sync Service) Maxtor Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Maxtor\Sync\SyncServices.exe -> [2007/09/28 11:24:36 | 00,156,976 | ---- | M] (Seagate Technology LLC) (MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2002/01/05 09:00:38 | 00,315,392 | ---- | M] (Microsoft Corporation) (NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2006/10/22 21:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) (ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/04/16 15:52:28 | 00,091,184 | ---- | M] (Microsoft Corporation) (ServiceLayer) ServiceLayer [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\PCSuite\Services\ServiceLayer.exe -> [2006/06/05 12:59:18 | 00,174,080 | ---- | M] (Nokia.) (usnjsvc) Servicio Lector del diario USN de Carpetas para compartir de Messenger [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\MSN Messenger\usnsvc.exe -> [2007/01/19 11:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) (WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) (WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) (WudfSvc) Windows Driver Foundation - User-mode Driver Framework [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\WudfSvc.dll -> [2006/09/28 18:56:14 | 00,055,808 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ALCXSENS.SYS -> [2004/02/24 20:08:00 | 00,400,384 | ---- | M] (Sensaura) (ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ALCXWDM.SYS -> [2004/06/22 01:53:00 | 00,626,204 | ---- | M] (Realtek Semiconductor Corp.) (AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avgldx86.sys -> [2008/08/29 07:58:12 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) (AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\system32\drivers\avgmfx86.sys -> [2008/08/19 09:41:56 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) (DNINDIS5) DNINDIS5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DNINDIS5.sys -> [2003/07/24 11:10:34 | 00,017,149 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) (gameenum) Game Port Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\gameenum.sys -> [2008/04/13 19:45:29 | 00,010,624 | ---- | M] (Microsoft Corporation) (GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2006/09/19 13:44:04 | 00,015,664 | ---- | M] (GEAR Software Inc.) (gmer) gmer [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gmer.sys -> [2008/12/14 18:07:01 | 00,085,969 | ---- | M] (GMER) (imagedrv) imagedrv [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\imagedrv.sys -> [2004/03/03 02:37:48 | 00,005,504 | ---- | M] (Ahead Software AG) (imagesrv) imagesrv [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\imagesrv.sys -> [2004/03/03 02:37:50 | 00,125,184 | ---- | M] (Ahead Software AG) (LVcKap) Logitech AEC Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Lvckap.sys -> [2007/03/06 16:50:30 | 01,669,664 | ---- | M] () (LVMVDrv) Logitech Machine Vision Engine Loader [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LVMVdrv.sys -> [2007/03/06 16:52:46 | 02,261,792 | ---- | M] (Labtec Inc.) (moufiltr) Chic Tech Mouse Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\moufiltr.sys -> [2007/05/12 18:59:32 | 00,062,592 | ---- | M] (Chic Tech.) (ms_mpu401) Microsoft MPU-401 MIDI UART Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\msmpu401.sys -> [2001/08/17 15:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) (MXOPSWD) Maxtor OneTouch Security Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mxopswd.sys -> [2007/05/03 12:37:08 | 00,022,152 | ---- | M] (Maxtor Corp.) (nmwcd) Nokia USB Phone Parent [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcd.sys -> [2006/05/29 07:26:38 | 00,127,488 | ---- | M] (Nokia) (nmwcdc) Nokia USB Generic [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdc.sys -> [2007/06/28 10:44:16 | 00,008,320 | ---- | M] (Nokia) (nmwcdcm) Nokia USB Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdcm.sys -> [2007/06/28 10:44:18 | 00,012,288 | ---- | M] (Nokia) (nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> [2006/10/22 21:22:00 | 03,994,624 | ---- | M] (NVIDIA Corporation) (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2001/08/23 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\PxHelp20.sys -> [2007/03/08 00:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) (QCDonner) Logitech QuickCam Express [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\OVCD.sys -> [2001/08/17 23:05:16 | 00,028,032 | ---- | M] (Microsoft Corporation) (rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RTL8139.sys -> [2004/08/03 23:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SE27bus.sys -> [2006/09/18 14:58:48 | 00,061,600 | R--- | M] (MCCI) (SE27mdfl) Sony Ericsson Device 039 USB WMC Modem Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SE27mdfl.sys -> [2006/09/18 14:58:52 | 00,009,360 | R--- | M] (MCCI) (SE27mdm) Sony Ericsson Device 039 USB WMC Modem Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SE27mdm.sys -> [2006/09/18 14:58:54 | 00,097,184 | R--- | M] (MCCI) (SE27mgmt) Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SE27mgmt.sys -> [2006/09/18 14:58:58 | 00,088,688 | R--- | M] (MCCI) (se27nd5) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\se27nd5.sys -> [2006/09/18 14:59:00 | 00,018,704 | R--- | M] (MCCI) (SE27obex) Sony Ericsson Device 039 USB WMC OBEX Interface [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SE27obex.sys -> [2006/09/18 14:59:02 | 00,086,560 | R--- | M] (MCCI) (se27unic) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\se27unic.sys -> [2006/09/18 14:59:08 | 00,090,800 | R--- | M] (MCCI) (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 11:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (Ser2pl) Prolific Serial port driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ser2pl.sys -> [2004/06/28 11:08:56 | 00,042,752 | ---- | M] (Prolific Technology Inc.) (SIVDRIVER) SIV Kernel Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SIVX32.sys -> [2006/05/13 19:19:38 | 00,009,216 | ---- | M] () (USB_RNDIS) Telsey USB Remote NDIS Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usb8023.sys -> [2008/04/13 19:56:49 | 00,012,800 | ---- | M] (Microsoft Corporation) (ZD1211U(3COM Corporation)) 3COM OfficeConnect Wireless 11g Compact USB Adapter(3COM Corporation) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ZD1211U.sys -> [2004/10/06 17:49:04 | 00,248,320 | ---- | M] (3COM Corporation) (ZDPNDIS5) ZDPNDIS5 NDIS Protocol Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\ZDPNDIS5.sys -> [2004/01/14 10:30:00 | 00,017,151 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://192.168.0.1:8063 -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com -> HKEY_CURRENT_USER\: Main\\"Secondary Start Pages" -> -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.msn.com/?wl=true -> HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> < FireFox Settings [Default Profile] > -> C:\Documents and Settings\WXP\Application Data\Mozilla\FireFox\Profiles\ye2pzfrx.default\prefs.js -> browser.search.defaultenginename -> "Ask" -> browser.search.defaulturl -> "http://search.conduit.com/ResultsExt.aspx?ctid=CT1434207&SearchSource=3&q=" -> browser.search.selectedEngine -> "Ask" -> browser.startup.homepage_override.mstone -> "rv:1.9.0.4" -> extensions.enabledItems -> {3f963a5b-e555-4543-90e2-c3908898db71}:8.0 -> extensions.enabledItems -> {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.0.20080718 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.4 -> < HOSTS File > (734 bytes and 19 lines) -> C:\windows\System32\drivers\etc\Hosts -> 127.0.0.1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated) {1017A80C-6F09-4548-A84D-EDD6AC9525F0} [HKLM] -> %ProgramFiles%\Lexmark Toolbar\toolband.dll [Lexmark Toolbar] -> [2006/08/09 15:37:24 | 00,184,320 | R--- | M] () {22BF413B-C6D2-4d91-82A9-A0F997BA588C} [HKLM] -> %ProgramFiles%\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (mastermind)] -> [2007/06/08 14:18:00 | 00,976,424 | ---- | M] (Skype Technologies S.A.) {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2008/08/29 07:58:16 | 00,455,960 | ---- | M] (AVG Technologies CZ, s.r.o.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2008/11/10 05:43:31 | 00,320,920 | ---- | M] (Sun Microsystems, Inc.) {9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2007/09/20 09:30:18 | 00,328,752 | ---- | M] (Microsoft Corporation) {A057A204-BACC-4D26-9990-79A187E2698E} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2008/08/19 09:41:50 | 02,055,960 | ---- | M] (AVG, Technologies CZ, s.r.o ) {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\GoogleToolbar2.dll [Google Toolbar Helper] -> [2007/08/11 03:40:35 | 02,554,944 | R--- | M] (Google Inc.) {DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2008/11/10 05:43:16 | 00,034,816 | ---- | M] (Sun Microsystems, Inc.) {E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2008/11/10 05:43:17 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" [HKLM] -> %ProgramFiles%\Lexmark Toolbar\toolband.dll [Lexmark Toolbar] -> [2006/08/09 15:37:24 | 00,184,320 | R--- | M] () "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\GoogleToolbar2.dll [&Google] -> [2007/08/11 03:40:35 | 02,554,944 | R--- | M] (Google Inc.) "{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2008/08/19 09:41:50 | 02,055,960 | ---- | M] (AVG, Technologies CZ, s.r.o ) "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\msgr.es.es-us\msntb.dll [Barra de Herramientas MSN] -> [2005/02/07 21:20:58 | 00,203,464 | ---- | M] (Microsoft Corporation) < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" [HKLM] -> %ProgramFiles%\Lexmark Toolbar\toolband.dll [Lexmark Toolbar] -> [2006/08/09 15:37:24 | 00,184,320 | R--- | M] () WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\GoogleToolbar2.dll [&Google] -> [2007/08/11 03:40:35 | 02,554,944 | R--- | M] (Google Inc.) WebBrowser\\"{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2008/08/19 09:41:50 | 02,055,960 | ---- | M] (AVG, Technologies CZ, s.r.o ) < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "" -> [] -> File not found "AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2008/11/27 12:37:18 | 01,261,336 | ---- | M] (AVG Technologies CZ, s.r.o.) "EzPrint" -> %ProgramFiles%\Lexmark 5400 Series\ezprint.exe ["C:\Program Files\Lexmark 5400 Series\ezprint.exe"] -> [2007/03/19 13:58:20 | 00,082,864 | ---- | M] (Lexmark International Inc.) "Lexmark 5400 Series Fax Server" -> ["C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s] -> File not found "LogitechQuickCamRibbon" -> %ProgramFiles%\Labtec\WebCam10\WebCam10.exe ["C:\Program Files\Labtec\WebCam10\WebCam10.exe" /hide] -> [2007/03/06 16:58:16 | 01,060,376 | ---- | M] () "LXCTCATS" -> %SystemRoot%\system32\spool\drivers\w32x86\3\lxcttime.dll [rundll32 C:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16] -> [2006/11/21 13:27:06 | 00,106,496 | ---- | M] (Lexmark International Inc.) "lxctmon.exe" -> %ProgramFiles%\Lexmark 5400 Series\lxctmon.exe ["C:\Program Files\Lexmark 5400 Series\lxctmon.exe"] -> [2007/03/19 13:58:17 | 00,291,760 | ---- | M] () "NvCplDaemon" -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2006/10/22 21:22:00 | 07,700,480 | ---- | M] (NVIDIA Corporation) "NvMediaCenter" -> %SystemRoot%\system32\nvmctray.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2006/10/22 21:22:00 | 00,086,016 | ---- | M] (NVIDIA Corporation) "nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2006/10/22 21:22:00 | 01,622,016 | ---- | M] () "WinPatrol" -> %ProgramFiles%\BillP Studios\WinPatrol\WinPatrol.exe [C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot] -> [2008/10/09 16:52:54 | 00,333,120 | ---- | M] (BillP Studios) < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "3COM" -> %ProgramFiles%\3COM Technology Corporation\3COM Wireless USB Utility\Wlan.exe [C:\Program Files\3COM Technology Corporation\3COM Wireless USB Utility\Wlan.exe] -> [2004/10/22 13:28:26 | 00,389,120 | ---- | M] (3COM) "I&F Viewer toolbar" -> %ProgramFiles%\Photo Toolkit\IvBar\phototoolkitmem.exe ["C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe" -start] -> [2006/10/27 20:34:00 | 00,065,536 | ---- | M] (VicMan Software) "Skype" -> %ProgramFiles%\Skype\Phone\Skype.exe ["C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized] -> [2007/06/08 14:18:00 | 23,233,576 | R--- | M] (Skype Technologies S.A.) < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> < WXP Startup Folder > -> C:\Documents and Settings\WXP\Start Menu\Programs\Startup -> < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [157] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Office Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2003/04/16 16:44:46 | 10,030,648 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {36ECAF82-3300-8F84-092E-AFF36D6C7040}:{86529161-034E-4F8A-88D2-3C625E612E04} [HKLM] -> %ProgramFiles%\WinHTTrack\WinHTTrackIEBar.dll [Button: Run WinHTTrack] -> [2007/11/16 13:00:40 | 00,131,072 | ---- | M] () {36ECAF82-3300-8F84-092E-AFF36D6C7040}:{86529161-034E-4F8A-88D2-3C625E612E04} [HKLM] -> %ProgramFiles%\WinHTTrack\WinHTTrackIEBar.dll [Menu: Launch WinHTTrack] -> [2007/11/16 13:00:40 | 00,131,072 | ---- | M] () {77BF5300-1474-4EC7-9980-D32B190E9B07}:{77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> %ProgramFiles%\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll [Button: Skype] -> [2007/06/08 14:18:00 | 00,976,424 | ---- | M] (Skype Technologies S.A.) {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2003/04/18 20:10:18 | 00,041,024 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\Msmsgs.exe [Button: @C:\Program Files\Messenger\Msgslang.dll,-61144] -> [2008/06/02 20:44:28 | 01,660,952 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\Msmsgs.exe [Menu: @C:\Program Files\Messenger\Msgslang.dll,-61144] -> [2008/06/02 20:44:28 | 01,660,952 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value does not exist or could not be read.] -> File not found CmdMapping\\"{36ECAF82-3300-8F84-092E-AFF36D6C7040}" [HKLM] -> %ProgramFiles%\WinHTTrack\WinHTTrackIEBar.dll [Run WinHTTrack] -> [2007/11/16 13:00:40 | 00,131,072 | ---- | M] () CmdMapping\\"{77BF5300-1474-4EC7-9980-D32B190E9B07}" [HKLM] -> %ProgramFiles%\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (button)] -> [2007/06/08 14:18:00 | 00,976,424 | ---- | M] (Skype Technologies S.A.) CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/04/18 20:10:18 | 00,041,024 | ---- | M] (Microsoft Corporation) CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\Msmsgs.exe [@C:\Program Files\Messenger\Msgslang.dll,-61144] -> [2008/06/02 20:44:28 | 01,660,952 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab[Java Plug-in 1.6.0_11] -> {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab[Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab[Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab[Java Plug-in 1.6.0_11] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab[Java Plug-in 1.6.0_11] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} [HKLM] -> https://secure.logmein.com/activex/ractrl.cab?lmi=100[Performance Viewer Activex Control] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {0F213975-0F79-47DB-A37D-2E280C1DCCCA} -> () -> {16402281-6C5E-4FA9-A072-711C779C5412} -> (3COM OfficeConnect Wireless 11g Compact USB Adapter) -> {3283B577-1E27-4F77-8035-1813E47B1832} -> (Telsey CPVA502+ USB) -> {3B22BAB6-DEEB-4D04-81B7-E08777E2E0C7} -> (3COM OfficeConnect Wireless 11g Compact USB Adapter) -> {4BD6090C-7391-4EF7-9236-0F36F90E2FAD} -> (3COM OfficeConnect Wireless 11g Compact USB Adapter) -> {6DDAFC0D-90F7-4A42-B117-1E369EFC0897} -> (Sony Ericsson Device 039 USB Ethernet Emulation (NDIS 5)) -> {9AC9BB9E-4C2E-4DE0-BA21-5B9506DADA86} -> (Realtek RTL8139 Family PCI Fast Ethernet NIC) -> {D1B32710-FFE7-404E-BDBC-02D46E4EF68D} -> (3COM OfficeConnect Wireless 11g Compact USB Adapter) -> {E2E2D090-8206-4DD4-8B4C-83D079FF06F2} -> (3COM OfficeConnect Wireless 11g Compact USB Adapter) -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> [2008/08/12 21:10:25 | 00,113,664 | ---- | M] (Google) avgrsstx.dll -> %SystemRoot%\system32\avgrsstx.dll -> [2008/08/19 09:41:58 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) *MultiFile Done* -> -> < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 01:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 15:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 11:55:06 | 05,674,352 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 01:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\Program Files\Ares\Ares.exe" -> C:\Program Files\Ares\Ares.exe [C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows] -> File not found "C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2008/08/29 01:28:59 | 00,641,304 | ---- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\Azureus\Azureus.exe" -> C:\Program Files\Azureus\Azureus.exe [C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus] -> [2008/10/10 02:00:50 | 00,199,608 | ---- | M] (Vuze Inc.) "C:\Program Files\BitComet\BitComet.exe" -> C:\Program Files\BitComet\BitComet.exe [C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client] -> File not found "C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent] -> [2008/09/13 02:04:44 | 00,634,160 | ---- | M] (BitTorrent, Inc.) "C:\Program Files\Grisoft\AVG Free\avgamsvr.exe" -> C:\Program Files\Grisoft\AVG Free\avgamsvr.exe [C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe] -> File not found "C:\Program Files\Grisoft\AVG Free\avgcc.exe" -> C:\Program Files\Grisoft\AVG Free\avgcc.exe [C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe] -> File not found "C:\Program Files\Grisoft\AVG Free\avginet.exe" -> C:\Program Files\Grisoft\AVG Free\avginet.exe [C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe] -> File not found "C:\Program Files\Internet Explorer\iexplore.exe" -> C:\Program Files\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer] -> [2008/10/15 08:06:26 | 00,633,632 | ---- | M] (Microsoft Corporation) "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2007/06/01 15:51:24 | 14,778,432 | ---- | M] (Apple Inc.) "C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\Msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/06/02 20:44:28 | 01,660,952 | ---- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 15:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 11:55:06 | 05,674,352 | ---- | M] (Microsoft Corporation) "C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [2007/06/08 14:18:00 | 23,233,576 | R--- | M] (Skype Technologies S.A.) "C:\Program Files\TELE2\AccessConfig.exe" -> C:\Program Files\TELE2\AccessConfig.exe [C:\Program Files\TELE2\AccessConfig.exe:*:Enabled:Configurar Acceso] -> File not found "C:\Program Files\TorrentQ\TorrentQ.exe" -> C:\Program Files\TorrentQ\TorrentQ.exe [C:\Program Files\TorrentQ\TorrentQ.exe:*:Enabled:Torrent P2P application] -> File not found "C:\Program Files\TVAnts\Tvants.exe" -> C:\Program Files\TVAnts\Tvants.exe [C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts] -> [2007/07/07 08:20:06 | 02,158,592 | ---- | M] (Zhejiang University) "C:\Program Files\uTorrent\uTorrent.exe" -> C:\Program Files\uTorrent\uTorrent.exe [C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent] -> File not found "C:\Program Files\Winamp Remote\bin\Orb.exe" -> C:\Program Files\Winamp Remote\bin\Orb.exe [C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb] -> File not found "C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" -> C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe [C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client] -> File not found "C:\Program Files\Winamp Remote\bin\OrbTray.exe" -> C:\Program Files\Winamp Remote\bin\OrbTray.exe [C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray] -> File not found "C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\lxctcoms.exe" -> C:\WINDOWS\system32\lxctcoms.exe [C:\WINDOWS\system32\lxctcoms.exe:*:Enabled:Lexmark Communications System] -> [2007/03/19 13:58:47 | 00,537,520 | ---- | M] ( ) < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 19:40:46 | 00,062,976 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> D:\AUTOEXEC.DOS [C:\ECS\MSCDEX /V /D:ECSCD003 /M:10 | ] -> D:\AUTOEXEC.DOS [ FAT32 ] -> [2001/03/26 15:38:16 | 00,000,036 | -HS- | M] () D:\AUTOEXEC.BAT [rem - By Windows Setup - C:\WINDOWS\COMMAND\MSCDEX /V /D:ECSCD003 /M:10 | mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi) | mode con codepage select=850 | keyb sp,,C:\WINDOWS\COMMAND\keyboard.sys | ] -> D:\AUTOEXEC.BAT [ FAT32 ] -> [2001/03/26 16:57:38 | 00,000,207 | -H-- | M] () D:\AUTOEXEC.CAM [rem - By Windows Setup - C:\WINDOWS\COMMAND\MSCDEX /V /D:ECSCD003 /M:10 | mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi) | mode con codepage select=850 | keyb sp,,C:\WINDOWS\COMMAND\keyboard.sys | ] -> D:\AUTOEXEC.CAM [ FAT32 ] -> [2001/03/26 16:57:38 | 00,000,207 | -H-- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> [Files/Folders - Created Within 30 Days] OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/12/16 01:16:44 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/12/16 01:15:32 | 00,647,677 | ---- | C] () gmer.ini -> %SystemRoot%\gmer.ini -> [2008/12/14 18:07:04 | 00,000,250 | ---- | C] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2008/12/14 18:07:01 | 00,085,969 | ---- | C] (GMER) gmer.dll -> %SystemRoot%\gmer.dll -> [2008/12/14 18:07:00 | 00,884,736 | ---- | C] () gmer.exe -> %SystemRoot%\gmer.exe -> [2008/12/14 18:07:00 | 00,811,008 | ---- | C] () gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2008/12/14 18:07:00 | 00,000,080 | ---- | C] () GMER -> %SystemDrive%\GMER -> [2008/12/14 18:04:52 | 00,000,000 | ---D | C] gmer.zip -> %UserProfile%\Desktop\gmer.zip -> [2008/12/14 18:04:02 | 00,747,873 | R--- | C] () avg_free_stf_en_8_176a1399.exe -> %UserProfile%\Desktop\avg_free_stf_en_8_176a1399.exe -> [2008/12/14 12:49:05 | 53,682,216 | ---- | C] (AVG Technologies) CCleaner.lnk -> %UserProfile%\Desktop\CCleaner.lnk -> [2008/12/13 11:04:26 | 00,001,548 | ---- | C] () ccsetup214_slim.exe -> %UserProfile%\Desktop\ccsetup214_slim.exe -> [2008/12/13 11:02:38 | 00,911,000 | ---- | C] (Piriform Ltd) rsit -> %SystemDrive%\rsit -> [2008/12/12 19:20:02 | 00,000,000 | ---D | C] RSIT.exe -> %UserProfile%\Desktop\RSIT.exe -> [2008/12/12 19:19:39 | 00,305,705 | ---- | C] () decree absolute.doc -> %UserProfile%\My Documents\decree absolute.doc -> [2008/12/12 15:59:20 | 00,024,576 | ---- | C] () Malwarebytes -> %AppData%\Malwarebytes -> [2008/12/12 15:17:04 | 00,000,000 | ---D | C] mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/12/12 15:16:59 | 00,015,504 | ---- | C] (Malwarebytes Corporation) Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2008/12/12 15:16:59 | 00,000,572 | ---- | C] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/12/12 15:16:56 | 00,038,496 | ---- | C] (Malwarebytes Corporation) Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2008/12/12 15:16:54 | 00,000,000 | ---D | C] Malwarebytes' Anti-Malware -> %UserProfile%\Desktop\Malwarebytes' Anti-Malware -> [2008/12/12 15:16:53 | 00,000,000 | ---D | C] mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2008/12/12 15:15:04 | 02,539,168 | ---- | C] (Malwarebytes Corporation ) linzi boyfriends staying over (2).doc -> %UserProfile%\My Documents\linzi boyfriends staying over (2).doc -> [2008/12/10 20:34:07 | 00,026,624 | ---- | C] () WinPatrol -> %AppData%\WinPatrol -> [2008/12/07 20:12:32 | 00,000,000 | ---D | C] BillP Studios -> %ProgramFiles%\BillP Studios -> [2008/12/07 20:11:46 | 00,000,000 | ---D | C] wpsetup.exe -> %UserProfile%\Desktop\wpsetup.exe -> [2008/12/07 20:11:23 | 00,726,384 | ---- | C] (BillP Studios) HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2008/12/07 19:21:43 | 00,001,734 | ---- | C] () Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/12/07 19:21:39 | 00,000,000 | ---D | C] ~$INERARIO COMPLETO 1 2 3 PARTES.doc -> %UserProfile%\My Documents\~$INERARIO COMPLETO 1 2 3 PARTES.doc -> [2008/12/01 14:51:26 | 00,000,162 | -H-- | C] () ITINERARIO COMPLETO 1 2 3 PARTES.doc -> %UserProfile%\My Documents\ITINERARIO COMPLETO 1 2 3 PARTES.doc -> [2008/12/01 14:47:00 | 00,279,040 | ---- | C] () PORTADA ITINERARIO.doc -> %UserProfile%\My Documents\PORTADA ITINERARIO.doc -> [2008/12/01 14:47:00 | 00,024,576 | ---- | C] () linzi no kids.doc -> %UserProfile%\My Documents\linzi no kids.doc -> [2008/11/29 14:27:24 | 00,034,816 | ---- | C] () lorna kids.doc -> %UserProfile%\My Documents\lorna kids.doc -> [2008/11/29 14:26:58 | 00,028,160 | ---- | C] () zeze 2008.nra -> %UserProfile%\My Documents\zeze 2008.nra -> [2008/11/28 16:30:02 | 00,006,863 | ---- | C] () My Invoices -> %UserProfile%\My Documents\My Invoices -> [2008/11/19 10:26:46 | 00,000,000 | ---D | C] [Files/Folders - Modified Within 30 Days] 2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> 4 C:\windows\*.tmp files -> C:\windows\*.tmp -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2006/12/29 21:06:01 | 00,000,000 | ---D | M] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/12/12 13:42:42 | 00,004,232 | ---- | M] () qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/12/12 13:42:42 | 00,005,407 | ---- | M] () C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2007/01/04 04:28:42 | 00,000,000 | ---D | M] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2007/01/05 20:43:59 | 00,008,206 | ---- | M] () C:\Documents and Settings\WXP\Local Settings\Temp\ -> C:\Documents and Settings\WXP\Local Settings\Temp -> [2008/12/16 01:17:08 | 00,000,000 | ---D | M] i4jdel0.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\i4jdel0.exe -> [2008/12/12 14:54:12 | 00,004,608 | ---- | M] () jre-6u11-windows-i586-p-iftw.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\jre-6u11-windows-i586-p-iftw.exe -> [2008/11/26 04:49:07 | 00,607,640 | ---- | M] (Sun Microsystems, Inc.) SkypeSetup.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\SkypeSetup.exe -> [2008/12/13 16:49:45 | 22,285,608 | ---- | M] (Skype Technologies S.A.) ytb.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\ytb.exe -> [2008/11/25 20:08:36 | 00,329,479 | ---- | M] (Yahoo! Inc.) _is43.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\_is43.exe -> [2006/05/25 03:10:42 | 00,455,600 | R--- | M] (Macrovision Corporation) _is44.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\_is44.exe -> [2006/05/25 03:10:42 | 00,455,600 | R--- | M] (Macrovision Corporation) 101 C:\Documents and Settings\WXP\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\WXP\Local Settings\Temp\*.tmp -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\ -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries -> [2008/12/13 16:54:26 | 00,000,000 | ---D | M] ScanningProcess.exe -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\ScanningProcess.exe -> [2008/12/13 16:54:23 | 00,139,264 | ---- | M] (Kaspersky Lab.) C:\Documents and Settings\WXP\Local Settings\Temp\Temporary Directory 1 for Msn Messenger 7.5.0160 Espanol(www.dookyweb.com).zip\ -> C:\Documents and Settings\WXP\Local Settings\Temp\Temporary Directory 1 for Msn Messenger 7.5.0160 Espanol(www.dookyweb.com).zip\ -> [2008/08/23 14:54:45 | 00,000,000 | -H-D | M] Install_MSN_Messenger_es.EXE -> C:\Documents and Settings\WXP\Local Settings\Temp\Temporary Directory 1 for Msn Messenger 7.5.0160 Espanol(www.dookyweb.com).zip\Install_MSN_Messenger_es.EXE -> [2005/07/21 20:48:02 | 07,814,856 | R--- | M] (Microsoft Corporation) C:\Documents and Settings\WXP\Local Settings\Temp\ -> C:\Documents and Settings\WXP\Local Settings\Temp -> [2008/12/16 01:17:08 | 00,000,000 | ---D | M] swt-gdip-win32-3448.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\swt-gdip-win32-3448.dll -> [2008/10/23 11:34:24 | 00,077,824 | ---- | M] (Eclipse Foundation) swt-win32-3448.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\swt-win32-3448.dll -> [2008/10/23 11:34:23 | 00,335,872 | ---- | M] (Eclipse Foundation) 101 C:\Documents and Settings\WXP\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\WXP\Local Settings\Temp\*.tmp -> C:\Documents and Settings\WXP\Local Settings\Temp\{4E8F9E3F-EC8B-41CA-84D8-CAF3ED56660A}\ -> C:\Documents and Settings\WXP\Local Settings\Temp\{4E8F9E3F-EC8B-41CA-84D8-CAF3ED56660A} -> [2007/08/02 18:48:17 | 00,000,000 | ---D | M] ISSetup.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\{4E8F9E3F-EC8B-41CA-84D8-CAF3ED56660A}\ISSetup.dll -> [2007/02/19 07:51:56 | 00,552,214 | R--- | M] (Macrovision Corporation) _Setup.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\{4E8F9E3F-EC8B-41CA-84D8-CAF3ED56660A}\_Setup.dll -> [2006/05/18 02:21:04 | 00,385,968 | R--- | M] (Macrovision Corporation) C:\Documents and Settings\WXP\Local Settings\Temp\{8CAFBD5B-36CA-4115-8786-40383A1F9CFC}\ -> C:\Documents and Settings\WXP\Local Settings\Temp\{8CAFBD5B-36CA-4115-8786-40383A1F9CFC} -> [2007/08/02 18:48:58 | 00,000,000 | ---D | M] ISSetup.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\{8CAFBD5B-36CA-4115-8786-40383A1F9CFC}\ISSetup.dll -> [2007/02/19 06:29:18 | 00,552,214 | R--- | M] (Macrovision Corporation) _Setup.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\{8CAFBD5B-36CA-4115-8786-40383A1F9CFC}\_Setup.dll -> [2006/05/18 02:21:04 | 00,385,968 | R--- | M] (Macrovision Corporation) C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\ -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries -> [2008/12/13 16:54:26 | 00,000,000 | ---D | M] FSSync.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\FSSync.dll -> [2008/12/13 16:54:22 | 00,038,400 | ---- | M] (Kaspersky Lab) ikave.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\ikave.dll -> [2008/12/13 16:54:23 | 00,065,536 | ---- | M] () kave.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\kave.dll -> [2008/12/13 16:54:23 | 00,282,624 | ---- | M] (Kaspersky Lab.) kosglue-7.0.25.0.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\kosglue-7.0.25.0.dll -> [2008/12/13 16:54:24 | 00,729,152 | ---- | M] (Kaspersky Lab) msvcm80.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\msvcm80.dll -> [2008/12/13 16:54:22 | 00,479,232 | ---- | M] (Microsoft Corporation) msvcp80.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\msvcp80.dll -> [2008/12/13 16:54:23 | 00,548,864 | ---- | M] (Microsoft Corporation) msvcr80.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\msvcr80.dll -> [2008/12/13 16:54:23 | 00,626,688 | ---- | M] (Microsoft Corporation) prLoader.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\prLoader.dll -> [2008/12/13 16:54:24 | 00,184,320 | ---- | M] (Kaspersky Lab) prremote.dll -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\binaries\prremote.dll -> [2008/12/13 16:54:24 | 00,090,112 | ---- | M] (Kaspersky Lab) C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\engine\bases\ -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\engine\bases -> [2008/12/13 16:55:49 | 00,000,000 | ---D | M] sfdb.dat -> C:\Documents and Settings\WXP\Local Settings\Temp\jkos-WXP\engine\bases\sfdb.dat -> [2008/12/14 00:42:45 | 00,775,612 | ---- | M] () C:\windows\Temp\ -> C:\WINDOWS\Temp -> [2008/12/16 01:22:34 | 00,000,000 | ---D | M] alcupd.exe -> C:\WINDOWS\Temp\alcupd.exe -> [2004/02/28 03:14:00 | 00,208,896 | ---- | M] (Realtek Semiconductor Corp.) DeleteUSB.exe -> C:\WINDOWS\Temp\DeleteUSB.exe -> [2003/06/11 13:40:46 | 00,126,976 | ---- | M] () PLUninst.exe -> C:\WINDOWS\Temp\PLUninst.exe -> [2003/06/27 17:50:24 | 00,126,976 | ---- | M] () RTLCPL.exe -> C:\WINDOWS\Temp\RTLCPL.exe -> [2004/06/19 01:15:00 | 07,506,432 | ---- | M] (Realtek Semiconductor Corp.) soundman.exe -> C:\WINDOWS\Temp\soundman.exe -> [2004/06/19 01:31:00 | 00,067,584 | ---- | M] (Realtek Semiconductor Corp.) 5 C:\windows\Temp\*.tmp files -> C:\windows\Temp\*.tmp -> C:\windows\Temp\gis705b9c\ -> C:\WINDOWS\Temp\gis705b9c -> [2008/12/13 13:04:25 | 00,000,000 | ---D | M] GoogleUpdater.exe -> C:\WINDOWS\Temp\gis705b9c\GoogleUpdater.exe -> [2008/08/13 15:36:42 | 00,125,624 | ---- | M] (Google) GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis705b9c\GoogleUpdaterAdminPrefs.exe -> [2008/08/13 15:36:42 | 00,187,064 | ---- | M] (Google) GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis705b9c\GoogleUpdaterInstallMgr.exe -> [2008/08/13 15:36:42 | 00,666,296 | ---- | M] (Google) GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis705b9c\GoogleUpdaterService.exe -> [2008/08/13 15:36:43 | 00,138,680 | ---- | M] (Google) GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis705b9c\GoogleUpdaterSetup.exe -> [2008/08/13 15:36:42 | 00,125,624 | ---- | M] (Google Inc.) gtfirstboot.exe -> C:\WINDOWS\Temp\gis705b9c\gtfirstboot.exe -> [2008/08/13 15:36:42 | 00,065,536 | ---- | M] () C:\windows\Temp\gis954fa\ -> C:\WINDOWS\Temp\gis954fa -> [2008/10/20 13:44:07 | 00,000,000 | ---D | M] GoogleUpdater.exe -> C:\WINDOWS\Temp\gis954fa\GoogleUpdater.exe -> [2008/10/20 08:45:07 | 00,161,264 | ---- | M] (Google) GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis954fa\GoogleUpdaterService.exe -> [2008/10/20 08:45:07 | 00,168,432 | ---- | M] (Google) C:\windows\Temp\gis954fa\2.4.1368.5602\ -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602 -> [2008/10/20 08:45:07 | 00,000,000 | ---D | M] GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602\GoogleUpdaterAdminPrefs.exe -> [2008/10/20 08:45:06 | 00,228,336 | ---- | M] (Google) GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602\GoogleUpdaterInstallMgr.exe -> [2008/10/20 08:45:07 | 00,834,032 | ---- | M] (Google) GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602\GoogleUpdaterSetup.exe -> [2008/10/20 08:45:07 | 00,175,600 | ---- | M] (Google Inc.) C:\windows\Temp\PL-2303_loggedDrv\ -> C:\WINDOWS\Temp\PL-2303_loggedDrv -> [2008/07/14 10:03:45 | 00,000,000 | ---D | M] InstallDriver.exe -> C:\WINDOWS\Temp\PL-2303_loggedDrv\InstallDriver.exe -> [2003/07/03 09:36:08 | 00,208,896 | ---- | M] () pnpreg.exe -> C:\WINDOWS\Temp\PL-2303_loggedDrv\pnpreg.exe -> [2000/06/10 01:07:58 | 00,008,464 | ---- | M] (Microsoft Corporation) QRemover.exe -> C:\WINDOWS\Temp\PL-2303_loggedDrv\QRemover.exe -> [2003/05/07 10:27:54 | 00,139,264 | ---- | M] () C:\windows\Temp\ -> C:\WINDOWS\Temp -> [2008/12/16 01:22:38 | 00,000,000 | ---D | M] audio3d.dll -> C:\WINDOWS\Temp\audio3d.dll -> [2003/08/20 04:36:00 | 00,065,536 | ---- | M] (Sensaura Ltd) crlds3d.dll -> C:\WINDOWS\Temp\crlds3d.dll -> [2002/11/22 00:07:00 | 00,765,952 | ---- | M] (Sensaura Ltd) newdev.dll -> C:\WINDOWS\Temp\newdev.dll -> [2004/08/04 00:56:46 | 00,248,832 | ---- | M] (Microsoft Corporation) RtlCPAPI.dll -> C:\WINDOWS\Temp\RtlCPAPI.dll -> [2004/02/10 00:18:00 | 00,155,648 | ---- | M] () 5 C:\windows\Temp\*.tmp files -> C:\windows\Temp\*.tmp -> C:\windows\Temp\gis705b9c\ -> C:\WINDOWS\Temp\gis705b9c -> [2008/12/13 13:04:25 | 00,000,000 | ---D | M] ci.dll -> C:\WINDOWS\Temp\gis705b9c\ci.dll -> [2008/08/13 15:36:42 | 00,877,056 | ---- | M] (Google) cires_en.dll -> C:\WINDOWS\Temp\gis705b9c\cires_en.dll -> [2008/08/13 15:36:42 | 00,125,952 | ---- | M] () npCIDetect11.dll -> C:\WINDOWS\Temp\gis705b9c\npCIDetect11.dll -> [2008/08/13 15:36:42 | 00,083,968 | ---- | M] (Google) C:\windows\Temp\gis954fa\2.4.1368.5602\ -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602 -> [2008/10/20 08:45:07 | 00,000,000 | ---D | M] ci.dll -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602\ci.dll -> [2008/10/20 08:45:07 | 01,119,232 | ---- | M] (Google) cires.dll -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602\cires.dll -> [2008/10/20 08:45:07 | 00,094,208 | ---- | M] () npCIDetect13.dll -> C:\WINDOWS\Temp\gis954fa\2.4.1368.5602\npCIDetect13.dll -> [2008/10/20 08:45:07 | 00,094,208 | ---- | M] (Google) C:\windows\Temp\is-6J085.tmp\ -> C:\windows\Temp\is-6J085.tmp\ -> [2007/08/23 10:52:26 | 00,000,000 | ---D | M] SecurityUtil.dll -> C:\WINDOWS\Temp\is-6J085.tmp\SecurityUtil.dll -> [2005/09/27 10:23:36 | 00,086,016 | ---- | M] () C:\windows\Temp\nse13.tmp\ -> C:\windows\Temp\nse13.tmp\ -> [2008/04/03 10:27:35 | 00,000,000 | ---D | M] NSIS_Picasa.dll -> C:\WINDOWS\Temp\nse13.tmp\NSIS_Picasa.dll -> [2008/04/03 10:27:35 | 00,051,200 | ---- | M] () C:\windows\Temp\nsm23.tmp\ -> C:\windows\Temp\nsm23.tmp\ -> [2008/10/06 16:11:10 | 00,000,000 | ---D | M] NSIS_Picasa.dll -> C:\WINDOWS\Temp\nsm23.tmp\NSIS_Picasa.dll -> [2008/10/06 16:11:10 | 00,051,200 | ---- | M] () C:\windows\Temp\nsu51.tmp\ -> C:\windows\Temp\nsu51.tmp\ -> [2007/10/11 18:08:45 | 00,000,000 | ---D | M] NSIS_Picasa.dll -> C:\WINDOWS\Temp\nsu51.tmp\NSIS_Picasa.dll -> [2007/10/11 18:08:45 | 00,055,808 | ---- | M] () C:\windows\Temp\nsw2D.tmp\ -> C:\windows\Temp\nsw2D.tmp\ -> [2007/08/29 19:15:38 | 00,000,000 | ---D | M] NSIS_Picasa.dll -> C:\WINDOWS\Temp\nsw2D.tmp\NSIS_Picasa.dll -> [2007/08/29 19:15:38 | 00,055,808 | ---- | M] () C:\windows\Temp\ -> C:\WINDOWS\Temp -> [2008/12/16 01:22:40 | 00,000,000 | ---D | M] Perflib_Perfdata_1ec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_1ec.dat -> [2008/08/24 12:38:33 | 00,016,384 | ---- | M] () Perflib_Perfdata_44c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_44c.dat -> [2008/12/15 18:56:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_484.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_484.dat -> [2008/12/08 22:04:53 | 00,016,384 | ---- | M] () Perflib_Perfdata_4d8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4d8.dat -> [2008/12/13 10:43:25 | 00,016,384 | ---- | M] () Perflib_Perfdata_520.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_520.dat -> [2008/09/30 19:51:32 | 00,016,384 | ---- | M] () Perflib_Perfdata_524.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_524.dat -> [2008/10/07 15:59:35 | 00,016,384 | ---- | M] () Perflib_Perfdata_528.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_528.dat -> [2008/10/16 14:24:02 | 00,016,384 | ---- | M] () Perflib_Perfdata_534.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_534.dat -> [2007/12/27 14:51:50 | 00,016,384 | ---- | M] () Perflib_Perfdata_538.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_538.dat -> [2008/03/07 17:23:42 | 00,016,384 | ---- | M] () Perflib_Perfdata_548.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_548.dat -> [2008/03/07 18:32:02 | 00,016,384 | ---- | M] () Perflib_Perfdata_598.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_598.dat -> [2007/11/20 06:20:23 | 00,016,384 | ---- | M] () Perflib_Perfdata_5b0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5b0.dat -> [2007/10/27 02:38:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_5c0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5c0.dat -> [2007/11/04 12:20:01 | 00,016,384 | ---- | M] () Perflib_Perfdata_5cc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5cc.dat -> [2007/11/20 06:37:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_5dc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5dc.dat -> [2007/11/04 12:57:33 | 00,016,384 | ---- | M] () Perflib_Perfdata_5e0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5e0.dat -> [2007/11/04 12:51:04 | 00,016,384 | ---- | M] () Perflib_Perfdata_608.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_608.dat -> [2007/11/04 10:54:31 | 00,016,384 | ---- | M] () Perflib_Perfdata_614.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_614.dat -> [2007/11/20 15:12:44 | 00,016,384 | ---- | M] () Perflib_Perfdata_61c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_61c.dat -> [2007/11/04 12:45:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_624.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_624.dat -> [2007/11/19 21:06:15 | 00,016,384 | ---- | M] () Perflib_Perfdata_668.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_668.dat -> [2008/09/28 19:39:32 | 00,016,384 | ---- | M] () Perflib_Perfdata_66c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_66c.dat -> [2007/12/15 18:51:27 | 00,016,384 | ---- | M] () Perflib_Perfdata_670.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_670.dat -> [2007/12/16 15:33:22 | 00,016,384 | ---- | M] () Perflib_Perfdata_674.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_674.dat -> [2007/12/13 19:30:43 | 00,016,384 | ---- | M] () Perflib_Perfdata_678.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_678.dat -> [2007/12/13 10:26:53 | 00,016,384 | ---- | M] () Perflib_Perfdata_67c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_67c.dat -> [2007/12/17 02:19:47 | 00,016,384 | ---- | M] () Perflib_Perfdata_680.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_680.dat -> [2007/12/12 13:33:02 | 00,016,384 | ---- | M] () Perflib_Perfdata_684.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_684.dat -> [2007/11/03 17:06:37 | 00,016,384 | ---- | M] () Perflib_Perfdata_688.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_688.dat -> [2008/01/04 15:37:34 | 00,016,384 | ---- | M] () Perflib_Perfdata_68c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_68c.dat -> [2008/01/24 16:19:22 | 00,016,384 | ---- | M] () Perflib_Perfdata_690.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_690.dat -> [2007/10/23 16:41:03 | 00,016,384 | ---- | M] () Perflib_Perfdata_694.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_694.dat -> [2007/12/26 20:39:56 | 00,016,384 | ---- | M] () Perflib_Perfdata_698.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_698.dat -> [2008/02/23 16:34:47 | 00,016,384 | ---- | M] () Perflib_Perfdata_69c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_69c.dat -> [2008/04/13 15:33:35 | 00,016,384 | ---- | M] () Perflib_Perfdata_6a0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6a0.dat -> [2008/02/05 20:09:00 | 00,016,384 | ---- | M] () Perflib_Perfdata_6a4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6a4.dat -> [2008/08/17 11:42:18 | 00,016,384 | ---- | M] () Perflib_Perfdata_6a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6a8.dat -> [2008/12/14 11:06:31 | 00,016,384 | ---- | M] () Perflib_Perfdata_6ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6ac.dat -> [2008/12/12 13:50:09 | 00,016,384 | ---- | M] () Perflib_Perfdata_6b0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6b0.dat -> [2008/12/14 13:18:59 | 00,016,384 | ---- | M] () Perflib_Perfdata_6b4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6b4.dat -> [2008/12/12 13:58:35 | 00,016,384 | ---- | M] () Perflib_Perfdata_6bc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6bc.dat -> [2008/10/10 19:18:19 | 00,016,384 | ---- | M] () Perflib_Perfdata_6c0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6c0.dat -> [2008/08/23 11:28:34 | 00,016,384 | ---- | M] () Perflib_Perfdata_6c4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6c4.dat -> [2008/10/09 10:05:10 | 00,016,384 | ---- | M] () Perflib_Perfdata_6c8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6c8.dat -> [2008/09/06 18:13:33 | 00,016,384 | ---- | M] () Perflib_Perfdata_6cc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6cc.dat -> [2008/06/07 09:49:25 | 00,016,384 | ---- | M] () Perflib_Perfdata_6d0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat -> [2008/10/12 20:21:51 | 00,016,384 | ---- | M] () Perflib_Perfdata_6d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6d4.dat -> [2008/10/10 22:55:22 | 00,016,384 | ---- | M] () Perflib_Perfdata_6d8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6d8.dat -> [2008/10/15 13:34:07 | 00,016,384 | ---- | M] () Perflib_Perfdata_6dc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6dc.dat -> [2007/10/26 09:15:29 | 00,016,384 | ---- | M] () Perflib_Perfdata_6e0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6e0.dat -> [2007/10/14 00:07:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_6e4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6e4.dat -> [2007/10/11 00:50:10 | 00,016,384 | ---- | M] () Perflib_Perfdata_6e8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6e8.dat -> [2007/10/20 11:22:48 | 00,016,384 | ---- | M] () Perflib_Perfdata_6ec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6ec.dat -> [2007/10/17 08:33:07 | 00,016,384 | ---- | M] () Perflib_Perfdata_6f0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6f0.dat -> [2007/11/19 09:42:45 | 00,016,384 | ---- | M] () Perflib_Perfdata_6f4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6f4.dat -> [2007/10/13 09:47:59 | 00,016,384 | ---- | M] () Perflib_Perfdata_6f8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6f8.dat -> [2007/10/20 09:46:20 | 00,016,384 | ---- | M] () Perflib_Perfdata_6fc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6fc.dat -> [2007/10/12 17:46:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_700.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_700.dat -> [2007/10/19 00:56:10 | 00,016,384 | ---- | M] () Perflib_Perfdata_704.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_704.dat -> [2007/10/09 00:29:07 | 00,016,384 | ---- | M] () Perflib_Perfdata_708.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_708.dat -> [2007/10/09 10:44:09 | 00,016,384 | ---- | M] () Perflib_Perfdata_710.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_710.dat -> [2008/12/09 18:03:01 | 00,016,384 | ---- | M] () Perflib_Perfdata_714.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_714.dat -> [2007/10/10 09:00:32 | 00,016,384 | ---- | M] () Perflib_Perfdata_718.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_718.dat -> [2007/10/15 16:19:53 | 00,016,384 | ---- | M] () Perflib_Perfdata_71c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_71c.dat -> [2007/10/20 10:34:33 | 00,016,384 | ---- | M] () Perflib_Perfdata_720.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_720.dat -> [2007/10/10 16:01:42 | 00,016,384 | ---- | M] () Perflib_Perfdata_724.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_724.dat -> [2007/10/12 08:53:21 | 00,016,384 | ---- | M] () Perflib_Perfdata_728.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_728.dat -> [2007/10/29 12:47:44 | 00,016,384 | ---- | M] () Perflib_Perfdata_72c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_72c.dat -> [2007/10/19 14:24:19 | 00,016,384 | ---- | M] () Perflib_Perfdata_730.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_730.dat -> [2007/10/16 19:45:35 | 00,016,384 | ---- | M] () Perflib_Perfdata_734.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_734.dat -> [2007/10/11 20:26:27 | 00,016,384 | ---- | M] () Perflib_Perfdata_738.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_738.dat -> [2007/10/11 17:45:33 | 00,016,384 | ---- | M] () Perflib_Perfdata_73c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_73c.dat -> [2007/10/14 13:15:20 | 00,016,384 | ---- | M] () Perflib_Perfdata_740.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_740.dat -> [2007/10/29 11:11:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_744.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_744.dat -> [2007/10/09 17:57:35 | 00,016,384 | ---- | M] () Perflib_Perfdata_748.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_748.dat -> [2007/10/10 16:44:23 | 00,016,384 | ---- | M] () Perflib_Perfdata_74c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_74c.dat -> [2007/10/30 08:36:41 | 00,016,384 | ---- | M] () Perflib_Perfdata_750.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_750.dat -> [2007/10/15 09:05:23 | 00,016,384 | ---- | M] () Perflib_Perfdata_754.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_754.dat -> [2007/10/09 02:03:34 | 00,016,384 | ---- | M] () Perflib_Perfdata_758.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_758.dat -> [2007/10/14 23:57:05 | 00,016,384 | ---- | M] () Perflib_Perfdata_75c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_75c.dat -> [2007/10/21 09:28:29 | 00,016,384 | ---- | M] () Perflib_Perfdata_760.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_760.dat -> [2007/10/12 09:21:17 | 00,016,384 | ---- | M] () Perflib_Perfdata_764.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_764.dat -> [2007/10/17 08:50:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_768.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_768.dat -> [2007/10/16 20:13:03 | 00,016,384 | ---- | M] () Perflib_Perfdata_76c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_76c.dat -> [2007/10/22 11:25:03 | 00,016,384 | ---- | M] () Perflib_Perfdata_770.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_770.dat -> [2007/10/19 16:41:50 | 00,016,384 | ---- | M] () Perflib_Perfdata_778.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_778.dat -> [2008/11/02 14:54:13 | 00,016,384 | ---- | M] () Perflib_Perfdata_780.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_780.dat -> [2008/06/10 20:55:38 | 00,016,384 | ---- | M] () Perflib_Perfdata_784.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_784.dat -> [2007/11/01 23:11:43 | 00,016,384 | ---- | M] () Perflib_Perfdata_78c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_78c.dat -> [2008/07/13 20:19:49 | 00,016,384 | ---- | M] () Perflib_Perfdata_7a4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7a4.dat -> [2007/12/05 19:48:52 | 00,016,384 | ---- | M] () Perflib_Perfdata_7a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7a8.dat -> [2007/10/30 15:43:14 | 00,016,384 | ---- | M] () Perflib_Perfdata_7d0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7d0.dat -> [2007/11/27 19:25:15 | 00,016,384 | ---- | M] () Perflib_Perfdata_964.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_964.dat -> [2008/02/22 01:27:19 | 00,016,384 | ---- | M] () Perflib_Perfdata_b4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b4.dat -> [2007/11/16 19:49:36 | 00,016,384 | ---- | M] () Perflib_Perfdata_b4c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b4c.dat -> [2007/10/08 23:46:05 | 00,016,384 | ---- | M] () Perflib_Perfdata_c0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c0.dat -> [2007/11/22 20:36:50 | 00,016,384 | ---- | M] () Perflib_Perfdata_e68.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e68.dat -> [2007/08/13 18:52:46 | 00,016,384 | ---- | M] () 5 C:\windows\Temp\*.tmp files -> C:\windows\Temp\*.tmp -> C:\windows\Temp\Cookies\ -> C:\WINDOWS\Temp\Cookies -> [2008/12/01 15:01:07 | 00,000,000 | -HSD | M] index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [2008/12/01 15:01:07 | 00,016,384 | -HS- | M] () C:\windows\Temp\History\History.IE5\ -> C:\windows\Temp\History\History.IE5\ -> [2008/12/13 13:04:26 | 00,000,000 | -HSD | M] index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2008/12/01 15:01:07 | 00,032,768 | -HS- | M] () C:\windows\Temp\Temporary Internet Files\Content.IE5\ -> C:\windows\Temp\Temporary Internet Files\Content.IE5\ -> [2008/12/13 13:04:28 | 00,000,000 | -HSD | M] index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/12/01 15:01:07 | 00,032,768 | -HS- | M] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/12/16 01:15:32 | 00,647,677 | ---- | M] () Microsoft Office Word 2003.lnk -> %UserProfile%\Desktop\Microsoft Office Word 2003.lnk -> [2008/12/16 01:14:21 | 00,002,497 | ---- | M] () Microsoft Office Outlook 2003.lnk -> %UserProfile%\Desktop\Microsoft Office Outlook 2003.lnk -> [2008/12/16 01:06:23 | 00,002,521 | ---- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/12/15 18:57:35 | 00,021,760 | ---- | M] () nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [2008/12/15 18:57:13 | 00,088,566 | ---- | M] () RegCure Program Check.job -> %SystemRoot%\tasks\RegCure Program Check.job -> [2008/12/15 18:57:07 | 00,000,434 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/12/15 18:56:53 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/12/15 18:56:50 | 00,002,048 | --S- | M] () hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2008/12/15 18:56:49 | 10,732,70784 | -HS- | M] () incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/12/15 17:07:37 | 30,718,807 | ---- | M] () gmer.ini -> %SystemRoot%\gmer.ini -> [2008/12/14 18:12:46 | 00,000,250 | ---- | M] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2008/12/14 18:07:01 | 00,085,969 | ---- | M] (GMER) gmer.dll -> %SystemRoot%\gmer.dll -> [2008/12/14 18:07:00 | 00,884,736 | ---- | M] () gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2008/12/14 18:07:00 | 00,000,080 | ---- | M] () gmer.zip -> %UserProfile%\Desktop\gmer.zip -> [2008/12/14 18:04:02 | 00,747,873 | R--- | M] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/12/14 18:00:19 | 00,091,203 | ---- | M] () avg_free_stf_en_8_176a1399.exe -> %UserProfile%\Desktop\avg_free_stf_en_8_176a1399.exe -> [2008/12/14 13:00:05 | 53,682,216 | ---- | M] (AVG Technologies) Mis carpetas para compartir.lnk -> %UserProfile%\My Documents\Mis carpetas para compartir.lnk -> [2008/12/13 23:25:54 | 00,000,581 | ---- | M] () CCleaner.lnk -> %UserProfile%\Desktop\CCleaner.lnk -> [2008/12/13 11:04:26 | 00,001,548 | ---- | M] () ccsetup214_slim.exe -> %UserProfile%\Desktop\ccsetup214_slim.exe -> [2008/12/13 11:02:46 | 00,911,000 | ---- | M] (Piriform Ltd) RSIT.exe -> %UserProfile%\Desktop\RSIT.exe -> [2008/12/12 19:19:40 | 00,305,705 | ---- | M] () decree absolute.doc -> %UserProfile%\My Documents\decree absolute.doc -> [2008/12/12 15:59:21 | 00,024,576 | ---- | M] () Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2008/12/12 15:16:59 | 00,000,572 | ---- | M] () mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2008/12/12 15:15:16 | 02,539,168 | ---- | M] (Malwarebytes Corporation ) linzi boyfriends staying over (2).doc -> %UserProfile%\My Documents\linzi boyfriends staying over (2).doc -> [2008/12/10 20:34:07 | 00,026,624 | ---- | M] () MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2008/12/10 00:24:37 | 17,593,280 | ---- | M] (Microsoft Corporation) wpsetup.exe -> %UserProfile%\Desktop\wpsetup.exe -> [2008/12/07 20:11:24 | 00,726,384 | ---- | M] (BillP Studios) HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2008/12/07 19:21:43 | 00,001,734 | ---- | M] () NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [2008/12/05 13:38:06 | 00,000,202 | ---- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/12/03 19:59:06 | 00,038,496 | ---- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/12/03 19:59:02 | 00,015,504 | ---- | M] (Malwarebytes Corporation) ~$INERARIO COMPLETO 1 2 3 PARTES.doc -> %UserProfile%\My Documents\~$INERARIO COMPLETO 1 2 3 PARTES.doc -> [2008/12/01 14:51:26 | 00,000,162 | -H-- | M] () ITINERARIO COMPLETO 1 2 3 PARTES.doc -> %UserProfile%\My Documents\ITINERARIO COMPLETO 1 2 3 PARTES.doc -> [2008/12/01 14:47:00 | 00,279,040 | ---- | M] () PORTADA ITINERARIO.doc -> %UserProfile%\My Documents\PORTADA ITINERARIO.doc -> [2008/12/01 14:47:00 | 00,024,576 | ---- | M] () linzi no kids.doc -> %UserProfile%\My Documents\linzi no kids.doc -> [2008/11/29 16:04:55 | 00,034,816 | ---- | M] () lorna kids.doc -> %UserProfile%\My Documents\lorna kids.doc -> [2008/11/29 15:05:39 | 00,028,160 | ---- | M] () cdplayer.ini -> %SystemRoot%\cdplayer.ini -> [2008/11/28 18:12:10 | 00,014,685 | ---- | M] () zeze 2008.nra -> %UserProfile%\My Documents\zeze 2008.nra -> [2008/11/28 16:30:02 | 00,006,863 | ---- | M] () Microsoft Office Excel 2003.lnk -> %UserProfile%\Desktop\Microsoft Office Excel 2003.lnk -> [2008/11/19 09:47:36 | 00,002,495 | ---- | M] () WavCodec.wff -> %AppData%\WavCodec.wff -> [2008/11/17 15:32:24 | 00,001,028 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/11/17 15:13:51 | 00,077,312 | ---- | M] () < End of report > [/code]