[code] OTScanIt2 logfile created on: 2009-01-16 08:03:19 - Run 1 OTScanIt2 by OldTimer - Version 1.0.6.2 Folder = C:\Documents and Settings\T&A\Desktop\OTScanIt2 Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd 1023.53 Mb Total Physical Memory | 597.88 Mb Available Physical Memory | 58.41% Memory free 1.65 Gb Paging File | 1.15 Gb Available in Paging File | 69.45% Paging File free Paging file location(s): c:\pagefile.sys 768 1536; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 55.87 Gb Total Space | 11.83 Gb Free Space | 21.17% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded Drive G: | 111.79 Gb Total Space | 56.02 Gb Free Space | 50.11% Space Free | Partition Type: NTFS H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: TNT1 Current User Name: T&A Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days [Processes - Safe List] applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> [2007-09-29 02:56:34 | 00,483,328 | ---- | M] (ATI Technologies Inc.) ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> [2007-09-29 02:56:34 | 00,483,328 | ---- | M] (ATI Technologies Inc.) calmain.exe -> %ProgramFiles%\Canon\CAL\CALMAIN.exe -> [2005-06-02 15:54:34 | 00,086,606 | ---- | M] (Canon Inc.) fameh32.exe -> %ProgramFiles%\Shaw Secure\Common\FAMEH32.EXE -> [2008-09-23 05:37:18 | 00,404,064 | ---- | M] (F-Secure Corporation) fch32.exe -> %ProgramFiles%\Shaw Secure\Common\FCH32.EXE -> [2008-09-23 05:37:18 | 00,125,592 | ---- | M] (F-Secure Corporation) fsaua.exe -> %ProgramFiles%\Shaw Secure\FSAUA\program\fsaua.exe -> [2008-09-23 05:34:32 | 00,490,080 | ---- | M] (F-Secure Corporation) fsav32.exe -> %ProgramFiles%\Shaw Secure\Anti-Virus\fsav32.exe -> [2008-09-23 05:35:12 | 00,344,160 | ---- | M] (F-Secure Corporation) fsdfwd.exe -> %ProgramFiles%\Shaw Secure\FWES\program\fsdfwd.exe -> [2008-09-23 05:35:40 | 00,510,560 | ---- | M] (F-Secure Corporation) fsgk32.exe -> %ProgramFiles%\Shaw Secure\Anti-Virus\fsgk32.exe -> [2009-01-12 08:38:09 | 00,439,432 | ---- | M] (F-Secure Corp.) fsgk32st.exe -> %ProgramFiles%\Shaw Secure\Anti-Virus\fsgk32st.exe -> [2008-09-23 05:35:14 | 00,215,648 | ---- | M] (F-Secure Corporation) fsguidll.exe -> %ProgramFiles%\Shaw Secure\FSGUI\fsguidll.exe -> [2008-09-23 05:36:54 | 00,604,768 | ---- | M] (F-Secure Corporation) fsm32.exe -> %ProgramFiles%\Shaw Secure\Common\FSM32.EXE -> [2008-09-23 05:37:18 | 00,182,936 | ---- | M] (F-Secure Corporation) fsma32.exe -> %ProgramFiles%\Shaw Secure\Common\FSMA32.EXE -> [2008-09-23 05:37:18 | 00,117,400 | ---- | M] (F-Secure Corporation) fsmb32.exe -> %ProgramFiles%\Shaw Secure\Common\FSMB32.EXE -> [2008-09-23 05:37:20 | 00,232,088 | ---- | M] (F-Secure Corporation) fsorsp.exe -> %ProgramFiles%\Shaw Secure\ORSP Client\fsorsp.exe -> [2008-09-23 05:37:54 | 00,055,904 | ---- | M] (F-Secure Corporation) fspc.exe -> %ProgramFiles%\Shaw Secure\FSPC\fspc.exe -> [2008-09-23 05:37:28 | 00,686,688 | ---- | M] (F-Secure Corporation) fsqh.exe -> %ProgramFiles%\Shaw Secure\Anti-Virus\fsqh.exe -> [2008-09-23 05:35:14 | 00,043,680 | ---- | M] (F-Secure Corporation) fssm32.exe -> %ProgramFiles%\Shaw Secure\Anti-Virus\fssm32.exe -> [2009-01-12 08:38:09 | 00,519,304 | ---- | M] (F-Secure Corp.) fsus.exe -> %ProgramFiles%\Shaw Secure\FSAUA\program\fsus.exe -> [2008-11-14 10:11:54 | 00,174,688 | ---- | M] (F-Secure Corporation) guard.exe -> %ProgramFiles%\ewido anti-spyware 4.0\guard.exe -> [2006-06-16 06:38:44 | 00,172,032 | ---- | M] (Anti-Malware Development a.s.) incd.exe -> %ProgramFiles%\Nero\Nero 7\InCD\InCD.exe -> [2007-02-12 12:19:46 | 01,050,112 | ---- | M] (Nero AG) incdsrv.exe -> %ProgramFiles%\Nero\Nero 7\InCD\InCDsrv.exe -> [2007-02-12 12:18:50 | 00,924,160 | ---- | M] (Nero AG) ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) ispnews.exe -> %ProgramFiles%\Shaw Secure\FSGUI\ispnews.exe -> [2005-05-31 04:45:06 | 00,356,352 | ---- | M] (F-Secure Corporation) ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008-11-20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) lexbces.exe -> %SystemRoot%\system32\LEXBCES.EXE -> [2004-03-04 08:30:48 | 00,311,296 | ---- | M] (Lexmark International, Inc.) lexpps.exe -> %SystemRoot%\system32\LEXPPS.EXE -> [2004-03-04 08:26:20 | 00,174,592 | ---- | M] (Lexmark International, Inc.) lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2006-10-19 13:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008-08-29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) nbhgui.exe -> %ProgramFiles%\Nero\Nero 7\InCD\NBHGui.exe -> [2007-02-12 12:23:18 | 01,620,480 | ---- | M] (Nero AG) nprotect.exe -> %ProgramFiles%\Norton AntiVirus\AdvTools\NPROTECT.EXE -> [2002-08-14 05:03:00 | 00,135,168 | ---- | M] (Symantec Corporation) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009-01-09 09:03:22 | 00,485,376 | ---- | M] (OldTimer Tools) qttask.exe -> %ProgramFiles%\QuickTime\QTTask.exe -> [2008-11-04 10:30:50 | 00,413,696 | ---- | M] (Apple Inc.) [Win32 Services - Safe List] (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007-10-24 00:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> [2007-09-29 02:56:34 | 00,483,328 | ---- | M] (ATI Technologies Inc.) (ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [2004-10-26 21:10:00 | 00,516,096 | ---- | M] () (Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008-08-29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) (CCALib8) Canon Camera Access Library 8 [Win32_Own | Auto | Running] -> %ProgramFiles%\Canon\CAL\CALMAIN.exe -> [2005-06-02 15:54:34 | 00,086,606 | ---- | M] (Canon Inc.) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007-10-24 00:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) (ewido anti-spyware 4.0 guard) ewido anti-spyware 4.0 guard [Win32_Own | Auto | Running] -> %ProgramFiles%\ewido anti-spyware 4.0\guard.exe -> [2006-06-16 06:38:44 | 00,172,032 | ---- | M] (Anti-Malware Development a.s.) (F-Secure Gatekeeper Handler Starter) F-Secure Gatekeeper Handler Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Shaw Secure\Anti-Virus\fsgk32st.exe -> [2008-09-23 05:35:14 | 00,215,648 | ---- | M] (F-Secure Corporation) (FSAUA) F-Secure Automatic Update Agent [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Shaw Secure\FSAUA\program\fsaua.exe -> [2008-09-23 05:34:32 | 00,490,080 | ---- | M] (F-Secure Corporation) (FSDFWD) F-Secure Anti-Virus Firewall Daemon [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Shaw Secure\FWES\program\fsdfwd.exe -> [2008-09-23 05:35:40 | 00,510,560 | ---- | M] (F-Secure Corporation) (FSMA) FSMA [Win32_Own | Auto | Running] -> %ProgramFiles%\Shaw Secure\Common\FSMA32.EXE -> [2008-09-23 05:37:18 | 00,117,400 | ---- | M] (F-Secure Corporation) (FSORSPClient) F-Secure ORSP Client [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Shaw Secure\ORSP Client\fsorsp.exe -> [2008-09-23 05:37:54 | 00,055,904 | ---- | M] (F-Secure Corporation) (GameConsoleService) GameConsoleService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\WildGames\Game Console - WildGames\GameConsoleService.exe -> [2008-03-28 15:04:58 | 00,165,416 | ---- | M] (WildTangent, Inc.) (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) (InCDsrv) InCD Helper [Win32_Own | Auto | Running] -> %ProgramFiles%\Nero\Nero 7\InCD\InCDsrv.exe -> [2007-02-12 12:18:50 | 00,924,160 | ---- | M] (Nero AG) (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) (LexBceS) LexBce Server [Win32_Own | Auto | Running] -> %SystemRoot%\system32\LEXBCES.EXE -> [2004-03-04 08:30:48 | 00,311,296 | ---- | M] (Lexmark International, Inc.) (LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2006-10-19 13:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) (NBService) NBService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBService.exe -> [2007-01-05 13:41:10 | 00,774,144 | ---- | M] (Nero AG) (NMIndexingService) NMIndexingService [Win32_Own | Disabled | Stopped] -> %CommonProgramFiles%\Ahead\Lib\NMIndexingService.exe -> [2006-12-23 17:54:04 | 00,262,144 | ---- | M] (Nero AG) (NProtectService) Norton Unerase Protection [Win32_Own | Auto | Running] -> %ProgramFiles%\Norton AntiVirus\AdvTools\NPROTECT.EXE -> [2002-08-14 05:03:00 | 00,135,168 | ---- | M] (Symantec Corporation) (SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> [2004-05-21 03:46:50 | 00,206,048 | ---- | M] (Symantec Corporation) (UMWdf) Windows User Mode Driver Framework [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\system32\wdfmgr.exe -> [2004-09-22 18:46:10 | 00,038,912 | ---- | M] (Microsoft Corporation) (usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007-10-18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) (WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007-10-25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (61883) 61883 Unit Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\61883.sys -> [2004-08-03 22:10:10 | 00,048,128 | ---- | M] (Microsoft Corporation) (AFS2K) AFS2K [Kernel | System | Running] -> %SystemRoot%\system32\drivers\AFS2K.SYS -> [2004-10-07 17:16:04 | 00,035,840 | ---- | M] (Oak Technology Inc.) (AmdK7) AMD K7 Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\amdk7.sys -> [2004-08-03 21:59:20 | 00,037,376 | ---- | M] (Microsoft Corporation) (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> [2007-09-29 03:06:00 | 02,456,064 | ---- | M] (ATI Technologies Inc.) (Avc) AVC Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\avc.sys -> [2004-08-03 22:10:10 | 00,038,912 | ---- | M] (Microsoft Corporation) (BANTExt) Belarc SMBios Access [Kernel | System | Running] -> %SystemRoot%\system32\drivers\BANTExt.sys -> [2003-03-06 14:48:08 | 00,003,840 | ---- | M] () (cmpci) C-Media PCI Audio Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\cmaudio.sys -> [2002-11-18 15:51:40 | 00,377,358 | ---- | M] (C-Media Inc) (ctljystk) Creative SBLive! Gameport [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctljystk.sys -> [2001-08-17 04:19:20 | 00,003,712 | ---- | M] (Creative Technology Ltd.) (CVirtA) Cisco Systems VPN Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CVirtA.sys -> [2003-04-10 09:45:58 | 00,005,088 | ---- | M] (Cisco Systems, Inc.) (dvd43llh) dvd43llh [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\dvd43llh.sys -> [2008-05-10 16:11:16 | 00,018,816 | ---- | M] (RIF) (ewido anti-spyware 4.0 driver) ewido anti-spyware 4.0 driver [Kernel | System | Running] -> %ProgramFiles%\ewido anti-spyware 4.0\guard.sys -> [2006-06-16 06:38:54 | 00,003,968 | ---- | M] () (F-Secure Filter) F-Secure File System Filter [Kernel | Disabled | Stopped] -> %ProgramFiles%\Shaw Secure\Anti-Virus\win2k\fsfilter.sys -> [2008-09-23 05:35:18 | 00,039,776 | ---- | M] () (F-Secure Gatekeeper) F-Secure Gatekeeper [Kernel | On_Demand | Running] -> %ProgramFiles%\Shaw Secure\Anti-Virus\minifilter\fsgk.sys -> [2009-01-12 08:39:07 | 00,083,080 | ---- | M] () (F-Secure HIPS) F-Secure HIPS [Kernel | System | Running] -> %ProgramFiles%\Shaw Secure\HIPS\drivers\fshs.sys -> [2008-09-23 05:37:06 | 00,066,720 | ---- | M] (F-Secure Corporation) (F-Secure Recognizer) F-Secure File System Recognizer [Kernel | Disabled | Stopped] -> %ProgramFiles%\Shaw Secure\Anti-Virus\win2k\fsrec.sys -> [2008-09-23 05:35:18 | 00,025,184 | ---- | M] () (fsbts) fsbts [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\fsbts.sys -> [2008-11-15 11:02:01 | 00,030,856 | ---- | M] () (FSFW) F-Secure Firewall Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\fsdfw.sys -> [2008-09-23 05:35:38 | 00,079,904 | ---- | M] (F-Secure Corporation) (gameenum) Game Port Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\gameenum.sys -> [2004-08-03 22:08:21 | 00,010,624 | ---- | M] (Microsoft Corporation) (GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008-04-17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) (i740) i740 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\i740nt5.sys -> [2001-08-17 04:49:06 | 00,058,592 | ---- | M] (Intel Corporation) (InCDfs) InCD File System [File_System | Disabled | Running] -> %SystemRoot%\system32\drivers\InCDfs.sys -> [2007-02-12 12:14:42 | 00,112,384 | ---- | M] (Nero AG) (InCDPass) InCDPass [Kernel | System | Running] -> %SystemRoot%\system32\drivers\InCDPass.sys -> [2007-02-12 12:17:24 | 00,031,360 | ---- | M] (Nero AG) (incdrm) InCD Reader [Kernel | System | Running] -> %SystemRoot%\system32\drivers\InCDRm.sys -> [2007-02-12 12:17:40 | 00,033,792 | ---- | M] (Nero AG) (kbdhid) Keyboard HID Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\kbdhid.sys -> [2004-08-03 21:58:34 | 00,014,848 | ---- | M] (Microsoft Corporation) (L8042Kbd) Logitech SetPoint Keyboard Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\L8042Kbd.sys -> [2004-06-08 12:36:28 | 00,013,105 | ---- | M] (Logitech, Inc.) (L8042mou) Logitech SetPoint PS/2 Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\L8042mou.Sys -> [2004-06-08 12:35:18 | 00,054,817 | ---- | M] (Logitech, Inc.) (LHidKe) Logitech SetPoint HID Mouse Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LHidKE.Sys -> [2004-06-08 12:34:48 | 00,024,637 | ---- | M] (Logitech, Inc.) (LHidUsbK) Logitech SetPoint USB Receiver Device Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LHidUsbK.sys -> [2004-06-08 12:35:26 | 00,038,081 | ---- | M] (Logitech, Inc.) (LMouKE) Logitech SetPoint Mouse Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LMouKE.Sys -> [2004-06-08 12:35:08 | 00,071,533 | ---- | M] (Logitech, Inc.) (LUsbKbd) Logitech SetPoint USB Keyboard Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LUsbKbd.sys -> [2004-06-08 12:36:20 | 00,014,975 | ---- | M] (Logitech, Inc.) (MSDV) Microsoft DV Camera and VCR [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\msdv.sys -> [2004-08-03 22:09:58 | 00,051,328 | ---- | M] (Microsoft Corporation) (MxlW2k) MxlW2k [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\MxlW2k.sys -> [2005-01-03 00:11:07 | 00,028,352 | ---- | M] (MusicMatch, Inc.) (NPDriver) Norton Unerase Protection Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\NPDRIVER.SYS -> [2002-08-14 05:03:00 | 00,034,578 | ---- | M] (Symantec Corporation) (pavboot) pavboot [File_System | Boot | Running] -> %SystemRoot%\system32\drivers\pavboot.sys -> [2008-06-19 17:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) (Pcouffin) VSO Software pcouffin [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pcouffin.sys -> [2006-11-15 19:53:39 | 00,047,360 | ---- | M] (VSO Software) (pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2003-09-26 03:53:00 | 00,010,368 | ---- | M] (Padus, Inc.) (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2002-08-29 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2007-03-29 02:00:00 | 00,043,528 | ---- | M] (Sonic Solutions) (Rio8Drv) Rio800 driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rio8drv.sys -> [2002-08-29 04:00:00 | 00,012,032 | ---- | M] (S3/Diamond Multimedia Systems) (Secdrv) Secdrv [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007-11-13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (SMC1211) SMC EZ Card 10/100 PCI (SMC1211 Series) NT 5.0 Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SMC1211.sys -> [2001-07-11 10:06:12 | 00,023,153 | ---- | M] (SMC Networks Inc.) (SoC PC-Camera Service) SoC PC-Camera [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc027.sys -> [2004-06-16 02:05:46 | 00,136,832 | R--- | M] () (sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sptd.sys -> [2007-07-17 17:58:08 | 00,682,232 | ---- | M] () (SVKP) SVKP [Kernel | Auto | Running] -> %SystemRoot%\system32\SVKP.sys -> [2006-09-08 17:58:18 | 00,002,368 | ---- | M] (AntiCracking) (SYMDNS) SYMDNS [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\symdns.sys -> [2004-05-21 03:46:24 | 00,011,040 | ---- | M] (Symantec Corporation) (SymEvent) SymEvent [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SYMEVENT.SYS -> [2004-12-20 18:58:18 | 00,110,352 | ---- | M] (Symantec Corporation) (SYMFW) SYMFW [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\symfw.sys -> [2004-05-21 03:46:26 | 00,170,368 | ---- | M] (Symantec Corporation) (SYMIDS) SYMIDS [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\symids.sys -> [2004-05-21 03:46:28 | 00,030,848 | ---- | M] (Symantec Corporation) (SYMIDSCO) SYMIDSCO [Kernel | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SymcData\ids-diskless\20040407.001\SymIDSCo.sys -> [2004-05-24 21:27:36 | 00,250,360 | ---- | M] (Symantec Corporation) (SYMNDIS) SYMNDIS [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\symndis.sys -> [2004-05-21 03:46:26 | 00,047,328 | ---- | M] (Symantec Corporation) (SYMREDRV) SYMREDRV [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\symredrv.sys -> [2004-05-21 03:46:30 | 00,025,792 | ---- | M] (Symantec Corporation) (SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\symtdi.sys -> [2004-05-21 03:46:32 | 00,267,328 | ---- | M] (Symantec Corporation) (tmcomm) tmcomm [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\tmcomm.sys -> [2007-12-07 22:13:39 | 00,102,664 | ---- | M] (Trend Micro Inc.) (USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaapl.sys -> [2008-10-01 13:01:28 | 00,032,000 | ---- | M] (Apple, Inc.) (WmBEnum) Logitech Virtual Bus Enumerator Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\WmBEnum.sys -> [2001-09-13 09:02:36 | 00,010,112 | ---- | M] (Logitech Inc.) (WmFilter) Logitech WingMan HID Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\WmFilter.sys -> [2001-09-13 09:02:38 | 00,019,360 | ---- | M] (Logitech Inc.) (WmVirHid) Logitech Virtual Hid Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\WmVirHid.sys -> [2001-09-13 09:02:34 | 00,005,728 | ---- | M] (Logitech Inc.) (WmXlCore) Logitech WingMan Translation Layer Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\WmXlCore.sys -> [2001-09-13 09:02:34 | 00,039,328 | ---- | M] (Logitech Inc.) (WS2IFSL) Windows Socket 2.0 Non-IFS Service Provider Support Environment [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ws2ifsl.sys -> [2002-08-29 04:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"Local Page" -> http://www.google.com/ -> HKEY_LOCAL_MACHINE\: Search\\"Local Page Restore" -> http://www.iesearch.com/ -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\"Search Page_bak" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.ca/ -> HKEY_CURRENT_USER\: Main\\"Start Page Restore" -> http://www.google.ca/ -> HKEY_CURRENT_USER\: Main\\"Start Page_bak" -> http://www.google.ca/ -> HKEY_CURRENT_USER\: SearchURL\\"provider" -> -> HKEY_CURRENT_USER\: URLSearchHooks\\"_{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-18\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\] > -> -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Page_Transitions" -> -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Search Page_bak" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Start Page" -> http://www.google.ca/ -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Start Page Restore" -> http://www.google.ca/ -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: Main\\"Start Page_bak" -> http://www.google.ca/ -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: SearchURL\\"provider" -> -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: URLSearchHooks\\"_{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\: "ProxyEnable" -> 0 -> < FireFox Settings [Default Profile] > -> C:\Documents and Settings\T&A\Application Data\Mozilla\FireFox\Profiles\j75h875p.default\prefs.js -> browser.search.selectedEngine -> "Ask" -> browser.startup.homepage -> "http://www.google.ca/" -> browser.startup.homepage_override.mstone -> "rv:1.9.0.5" -> extensions.enabledItems -> {FFA36170-80B1-4535-B0E3-A4569E497DD0}:2.0.3 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5 -> < HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 127.0.0.1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006-10-22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated) {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %SystemDrive%\PROGRA~1\SPYBOT~1\SDHelper.dll [] -> File not found {7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2006-08-31 19:33:06 | 00,322,368 | ---- | M] (Microsoft Corporation) SOFTWARE [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{F2CF5485-4E02-4F68-819C-B92DE9277049}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{F2CF5485-4E02-4F68-819C-B92DE9277049}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008-10-15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) "F-Secure Manager" -> ["C:\Program Files\Shaw Secure\Common\FSM32.EXE" /splash] -> File not found "F-Secure TNB" -> %ProgramFiles%\Shaw Secure\FSGUI\tnbutil.exe ["C:\Program Files\Shaw Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW] -> [2008-09-23 05:37:00 | 00,957,024 | ---- | M] (F-Secure Corporation) "InCD" -> %ProgramFiles%\Nero\Nero 7\InCD\InCD.exe [C:\Program Files\Nero\Nero 7\InCD\InCD.exe] -> [2007-02-12 12:19:46 | 01,050,112 | ---- | M] (Nero AG) "iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008-11-20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) "Logitech Hardware Abstraction Layer" -> %SystemRoot%\KHALMNPR.Exe [KHALMNPR.EXE] -> [2004-06-08 12:31:38 | 00,029,696 | ---- | M] (Logitech Inc.) "News Service" -> %ProgramFiles%\Shaw Secure\FSGUI\ispnews.exe ["C:\Program Files\Shaw Secure\FSGUI\ispnews.exe"] -> [2005-05-31 04:45:06 | 00,356,352 | ---- | M] (F-Secure Corporation) "QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2008-11-04 10:30:50 | 00,413,696 | ---- | M] (Apple Inc.) "SecurDisc" -> %ProgramFiles%\Nero\Nero 7\InCD\NBHGui.exe [C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe] -> [2007-02-12 12:23:18 | 01,620,480 | ---- | M] (Nero AG) < Run [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "HP Deskjet 500" -> [HP_DeskJet_500.exe] -> File not found "Symantec NetDriver Warning" -> %SystemDrive%\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE [C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE] -> File not found "Symantec Network Driver Update Warning" -> %SystemDrive%\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE [C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE] -> File not found "Windows Frame Works" -> [frmwrks32.exe] -> File not found < RunOnce [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "HP Deskjet 500" -> [HP_DeskJet_500.exe] -> File not found "tscuninstall" -> %SystemRoot%\system32\tscupgrd.exe [%systemroot%\system32\tscupgrd.exe] -> [2004-08-03 21:59:27 | 00,044,544 | ---- | M] (Microsoft Corporation) < Run [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "HP Deskjet 500" -> [HP_DeskJet_500.exe] -> File not found "Symantec NetDriver Warning" -> %SystemDrive%\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE [C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE] -> File not found "Symantec Network Driver Update Warning" -> %SystemDrive%\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE [C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE] -> File not found "Windows Frame Works" -> [frmwrks32.exe] -> File not found < RunOnce [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "HP Deskjet 500" -> [HP_DeskJet_500.exe] -> File not found "tscuninstall" -> %SystemRoot%\system32\tscupgrd.exe [%systemroot%\system32\tscupgrd.exe] -> [2004-08-03 21:59:27 | 00,044,544 | ---- | M] (Microsoft Corporation) < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < Kaylee Nicole Startup Folder > -> C:\Documents and Settings\Kaylee Nicole\Start Menu\Programs\Startup -> < T&A Startup Folder > -> C:\Documents and Settings\T&A\Start Menu\Programs\Startup -> < Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveAutoRun" -> [67108863] -> File not found \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found \\"DisableRegistryTools" -> [0] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveAutoRun" -> [67108863] -> File not found \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"DisableRegistryTools" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"NoDriveAutoRun" -> [67108863] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"NoDriveAutoRun" -> [67108863] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveAutoRun" -> [67108863] -> File not found \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"DisableRegistryTools" -> [0] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &Search -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000] -> [2008-10-28 16:07:58 | 09,362,248 | R--- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000] -> [2008-10-28 16:07:58 | 09,362,248 | R--- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000] -> [2008-10-28 16:07:58 | 09,362,248 | R--- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> &Search -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000] -> [2008-10-28 16:07:58 | 09,362,248 | R--- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_02\bin\NPJPI150_02.dll [Menu: Sun Java Console] -> [2005-03-04 02:54:17 | 00,069,746 | ---- | M] (Sun Microsystems, Inc.) {200DB664-75B5-47c0-8B45-A44ACCF73C00}:{D68926FD-18FD-4B0E-A1C7-917D13FAB760} [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Button: Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) {200DB664-75B5-47c0-8B45-A44ACCF73F01}:{D68926FD-18FD-4B0E-A1C7-917D13FAB760} [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Menu: Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) {200DB664-75B5-47c0-8B45-A44ACCF73F02}:{878137C3-9DAC-4a48-9625-78A054E86C1E} [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Menu: &Suspend Webpage Filter] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) {200DB664-75B5-47c0-8B45-A44ACCF73F03}:{A7FC740A-AC46-46d2-9262-E368D619AD17} [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Menu: &Deny this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) {200DB664-75B5-47c0-8B45-A44ACCF73F04}:{C459289E-2150-486b-8556-12C706799CAC} [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Menu: &Allow this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) {d9288080-1baa-4bc4-9cf8-a92d743db949}:Exec [HKLM] -> %UserProfile%\Start Menu\Programs\IMVU\Run IMVU.lnk [Button: Run IMVU] -> File not found {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006-10-10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003-02-28 18:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{119DBEDA-9c41-4F97-94B4-B6BCD01133CF}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73C00}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F01}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F02}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Suspend Webpage Filter] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F03}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Deny this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F04}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Allow this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{300DB664-75B5-47c0-8B45-A44ACCF73C00}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\"{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}" [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found CmdMapping\\"{d9288080-1baa-4bc4-9cf8-a92d743db949}" [HKLM] -> %UserProfile%\Start Menu\Programs\IMVU\Run IMVU.lnk [Run IMVU] -> File not found CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2006-10-10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003-02-28 18:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73C00}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F01}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F02}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Suspend Webpage Filter] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F03}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Deny this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F04}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Allow this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003-02-28 18:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73C00}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F01}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F02}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Suspend Webpage Filter] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F03}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Deny this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F04}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Allow this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003-02-28 18:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{119DBEDA-9c41-4F97-94B4-B6BCD01133CF}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73C00}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F01}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [Parental...] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F02}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Suspend Webpage Filter] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F03}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Deny this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{200DB664-75B5-47c0-8B45-A44ACCF73F04}" [HKLM] -> %ProgramFiles%\Shaw Secure\FSPC\fspcmsie.dll [&Allow this website] -> [2008-09-23 05:37:28 | 00,150,112 | ---- | M] (F-Secure Corporation) CmdMapping\\"{300DB664-75B5-47c0-8B45-A44ACCF73C00}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\"{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}" [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found CmdMapping\\"{d9288080-1baa-4bc4-9cf8-a92d743db949}" [HKLM] -> %UserProfile%\Start Menu\Programs\IMVU\Run IMVU.lnk [Run IMVU] -> File not found CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2006-10-10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\] > -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-448539723-1482476501-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {00000055-9980-0010-8000-00AA00389B71} [HKLM] -> http://codecs.microsoft.com/codecs/i386/fhg.CAB [Reg Error: Key does not exist or could not be opened.] -> {00B71CFB-6864-4346-A978-C0A14556272C} [HKLM] -> http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab [Checkers Class] -> {02BCC737-B171-4746-94C9-0D8A0B2C0089} [HKLM] -> http://office.microsoft.com/templates/ieawsdc.cab [Microsoft Office Template and Media Control] -> {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> http://www.apple.com/qtactivex/qtplugin.cab [QuickTime Object] -> {14B87622-7E19-4EA8-93B3-97215F77A6BC} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab [MessengerStatsClient Class] -> {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://active.macromedia.com/director/cabs/sw.cab [Shockwave ActiveX Control] -> {17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409 [Windows Genuine Advantage Validation Tool] -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} [HKLM] -> http://www.pandasecurity.com/activescan/cabs/as2stubie.cab [ActiveScan 2.0 Installer Class] -> {33363249-0000-0010-8000-00AA00389B71} [HKLM] -> http://codecs.microsoft.com/codecs/i386/i263_32.cab [Reg Error: Key does not exist or could not be opened.] -> {33564D57-9980-0010-8000-00AA00389B71} [HKLM] -> http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab [Reg Error: Key does not exist or could not be opened.] -> {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} [HKLM] -> http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab [Reg Error: Key does not exist or could not be opened.] -> {48DD0448-9209-4F81-9F6D-D83562940134} [HKLM] -> http://lads.myspace.com/upload/MySpaceUploader1006.cab [MySpace Uploader Control] -> {4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab [MSN Photo Upload Tool] -> {5CB1506E-1DEA-4E63-89A7-E40E52AEA1FD} [HKLM] -> http://fulfillment.puretracks.com/onager.cab [OnagerCtrl Class] -> {5D6F45B3-9043-443D-A792-115447494D24} [HKLM] -> http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab [UnoCtrl Class] -> {74D05D43-3236-11D4-BDCD-00C04F9A3B61} [HKLM] -> http://a840.g.akamai.net/7/840/537/2005102501/housecall.trendmicro.com/housecall/xscan53.cab [HouseCall Control] -> {76716694-EADA-4810-8C3B-4826328A317F} [HKLM] -> http://content.dll1.com/Connectus/SmartCouponPrinter/SmartCouponPrinter20080612.cab [SmartCouponPrinter Control] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab [Java Plug-in 1.5.0_02] -> {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab [MessengerStatsClient Class] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key does not exist or could not be opened.] -> {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [HKLM] -> http://www.pandasoftware.com/activescan/as5/asinst.cab [ActiveScan Installer Class] -> {9F1C11AA-197B-4942-BA54-47A8489BB47F} [HKLM] -> http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37830.7130902778 [Reg Error: Key does not exist or could not be opened.] -> {B8BE5E93-A60C-4D26-A2DC-220313175592} [HKLM] -> http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab [ZoneIntro Class] -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab [MessengerStatsClient Class] -> {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab [Java Plug-in 1.5.0_02] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> DirectAnimation Java Classes [HKLM] -> file://C:\WINDOWS\Java\classes\dajava.cab [Reg Error: Key does not exist or could not be opened.] -> Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab [Reg Error: Key does not exist or could not be opened.] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {295C7F09-5E28-40D4-9ECB-074DD9AB6E2F} -> (1394 Net Adapter) -> {60EC3129-E596-4A23-9635-AEA27348448D} -> (SMC EZ Card 10/100 PCI (SMC1211 Series)) -> {979A9355-AAF1-466D-8760-0690C53FE8F9} -> (1394 Net Adapter) -> {E77BB131-D899-40E8-A8A6-12781DB2A664} -> () -> IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> [2007-09-29 02:57:56 | 00,122,880 | ---- | M] (ATI Technologies Inc.) < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" [HKLM] -> %ProgramFiles%\ewido anti-spyware 4.0\shellexecutehook.dll [ewido anti-spyware 4.0] -> [2006-06-16 06:38:50 | 00,073,728 | ---- | M] (Anti-Malware Development a.s.) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006-10-10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004-08-03 23:56:56 | 00,140,800 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007-10-02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007-10-18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006-10-10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004-08-03 23:56:56 | 00,140,800 | ---- | M] (Microsoft Corporation) "C:\Documents and Settings\T&A\Desktop\nancy drew short cuts\BitDownload\BitDownload.exe" -> C:\Documents and Settings\T&A\Desktop\nancy drew short cuts\BitDownload\BitDownload.exe [C:\Documents and Settings\T&A\Desktop\nancy drew short cuts\BitDownload\BitDownload.exe:*:Enabled:Warez3] -> File not found "C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008-08-29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) "C:\Program Files\eXeem\eXeem.exe" -> C:\Program Files\eXeem\eXeem.exe [C:\Program Files\eXeem\eXeem.exe:*:Enabled:eXeem] -> File not found "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008-11-20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) "C:\Program Files\Java\j2re1.4.2_05\bin\javaw.exe" -> C:\Program Files\Java\j2re1.4.2_05\bin\javaw.exe [C:\Program Files\Java\j2re1.4.2_05\bin\javaw.exe:*:Enabled:javaw] -> File not found "C:\Program Files\Java\jre1.5.0_02\bin\javaw.exe" -> C:\Program Files\Java\jre1.5.0_02\bin\javaw.exe [C:\Program Files\Java\jre1.5.0_02\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary] -> [2005-03-04 01:07:06 | 00,049,250 | ---- | M] (Sun Microsystems, Inc.) "C:\Program Files\Kazaa Lite K++\Kazaa.kpp" -> C:\Program Files\Kazaa Lite K++\Kazaa.kpp [C:\Program Files\Kazaa Lite K++\Kazaa.kpp:*:Enabled:Kazaa] -> File not found "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" -> C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare] -> File not found "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> File not found "C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2004-10-13 08:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) "C:\Program Files\Morpheus\Morpheus.exe" -> C:\Program Files\Morpheus\Morpheus.exe [C:\Program Files\Morpheus\Morpheus.exe:*:Enabled:M5Shell] -> File not found "C:\Program Files\Mozilla Firefox\firefox.exe" -> C:\Program Files\Mozilla Firefox\firefox.exe [C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox] -> [2008-12-18 22:52:57 | 00,307,704 | ---- | M] (Mozilla Corporation) "C:\Program Files\NetMeeting\conf.exe" -> C:\Program Files\NetMeeting\conf.exe [C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®] -> [2004-08-03 23:56:48 | 01,032,192 | ---- | M] (Microsoft Corporation) "C:\Program Files\SightSpeed\SightSpeed.exe" -> C:\Program Files\SightSpeed\SightSpeed.exe [C:\Program Files\SightSpeed\SightSpeed.exe:*:Enabled:SightSpeed] -> File not found "C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007-10-02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007-10-18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\LEXPPS.EXE" -> C:\WINDOWS\system32\LEXPPS.EXE [C:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE] -> [2004-03-04 08:26:20 | 00,174,592 | ---- | M] (Lexmark International, Inc.) "C:\WINDOWS\system32\PnkBstrA.exe" -> C:\WINDOWS\system32\PnkBstrA.exe [C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA] -> File not found "C:\WINDOWS\system32\PnkBstrB.exe" -> C:\WINDOWS\system32\PnkBstrB.exe [C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB] -> File not found < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [System32\DRIVERS\cdrom.sys] -> [2004-08-03 21:59:52 | 00,049,536 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2005-12-28 11:42:37 | 00,000,050 | ---- | M] () C:\autorun.inf [] -> %SystemDrive%\autorun.inf [ NTFS ] -> [2008-12-25 13:52:53 | 00,000,000 | RHSD | M] < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> [Files/Folders - Created Within 30 Days] 24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009-01-16 08:01:22 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009-01-16 07:56:45 | 00,656,730 | ---- | C] () Kaylee A Dark and Stormy Night.doc -> %UserProfile%\My Documents\Kaylee A Dark and Stormy Night.doc -> [2009-01-15 08:28:00 | 00,020,992 | ---- | C] () Shortcut to Contaminated area Woodley Road Ladysmith Harbour May 20 2008 045.jpg.lnk -> %UserProfile%\Desktop\Shortcut to Contaminated area Woodley Road Ladysmith Harbour May 20 2008 045.jpg.lnk -> [2009-01-14 19:32:23 | 00,000,443 | ---- | C] () sarsfx.exe -> %UserProfile%\Desktop\sarsfx.exe -> [2009-01-13 18:44:08 | 01,181,383 | ---- | C] () When You Were Young lyrics.doc -> %UserProfile%\My Documents\When You Were Young lyrics.doc -> [2009-01-13 07:26:30 | 00,020,992 | ---- | C] () ~$en You Were Young.doc -> %UserProfile%\My Documents\~$en You Were Young.doc -> [2009-01-13 07:18:35 | 00,000,162 | -H-- | C] () troys project -> %UserProfile%\Desktop\troys project -> [2009-01-12 20:15:29 | 00,000,000 | ---D | C] canada-map.gif -> %UserProfile%\Desktop\canada-map.gif -> [2009-01-12 20:02:10 | 00,059,179 | ---- | C] () pavboot.sys -> %SystemRoot%\System32\drivers\pavboot.sys -> [2009-01-12 19:35:58 | 00,028,544 | ---- | C] (Panda Security, S.L.) Panda Security -> %ProgramFiles%\Panda Security -> [2009-01-12 19:35:12 | 00,000,000 | ---D | C] AntiRootkit.zip -> %UserProfile%\Desktop\AntiRootkit.zip -> [2009-01-12 19:12:10 | 00,311,591 | ---- | C] () CF24175.exe -> %SystemRoot%\System32\CF24175.exe -> [2009-01-12 18:58:04 | 00,388,608 | ---- | C] (Microsoft Corporation) CF23029.exe -> %SystemRoot%\System32\CF23029.exe -> [2009-01-12 18:52:36 | 00,388,608 | ---- | C] (Microsoft Corporation) CF22085.exe -> %SystemRoot%\System32\CF22085.exe -> [2009-01-12 18:47:26 | 00,388,608 | ---- | C] (Microsoft Corporation) temp -> %SystemRoot%\temp -> [2009-01-12 18:23:49 | 00,000,000 | ---D | C] CF16448.exe -> %SystemRoot%\System32\CF16448.exe -> [2009-01-12 18:18:40 | 00,388,608 | ---- | C] (Microsoft Corporation) CF13676.exe -> %SystemRoot%\System32\CF13676.exe -> [2009-01-12 18:04:31 | 00,388,608 | ---- | C] (Microsoft Corporation) CF10714.exe -> %SystemRoot%\System32\CF10714.exe -> [2009-01-12 17:49:22 | 00,388,608 | ---- | C] (Microsoft Corporation) CF10280.exe -> %SystemRoot%\System32\CF10280.exe -> [2009-01-12 17:47:10 | 00,388,608 | ---- | C] (Microsoft Corporation) CF10149.exe -> %SystemRoot%\System32\CF10149.exe -> [2009-01-12 17:46:30 | 00,388,608 | ---- | C] (Microsoft Corporation) kaylee homework -> %UserProfile%\Desktop\kaylee homework -> [2009-01-11 15:08:09 | 00,000,000 | ---D | C] When You Were Young.doc -> %UserProfile%\My Documents\When You Were Young.doc -> [2009-01-11 14:35:23 | 00,023,040 | ---- | C] () You sit there in your heartache.doc -> %UserProfile%\My Documents\You sit there in your heartache.doc -> [2009-01-11 14:35:14 | 00,020,992 | ---- | C] () CF19462.exe -> %SystemRoot%\System32\CF19462.exe -> [2009-01-11 11:54:45 | 00,388,608 | ---- | C] (Microsoft Corporation) CF18568.exe -> %SystemRoot%\System32\CF18568.exe -> [2009-01-11 11:49:51 | 00,388,608 | ---- | C] (Microsoft Corporation) gmer.ini -> %SystemRoot%\gmer.ini -> [2009-01-11 10:40:02 | 00,000,250 | ---- | C] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2009-01-11 10:39:59 | 00,085,969 | ---- | C] (GMER) gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2009-01-11 10:39:55 | 00,000,080 | ---- | C] () gmer.dll -> %SystemRoot%\gmer.dll -> [2009-01-11 10:39:54 | 00,884,736 | ---- | C] () gmer.exe -> %SystemRoot%\gmer.exe -> [2009-01-11 10:39:54 | 00,811,008 | ---- | C] () gmer.zip -> %UserProfile%\Desktop\gmer.zip -> [2009-01-11 10:30:14 | 00,747,873 | ---- | C] () Sophos -> %ProgramFiles%\Sophos -> [2009-01-10 22:22:00 | 00,000,000 | ---D | C] CF23389.exe -> %SystemRoot%\System32\CF23389.exe -> [2009-01-10 16:43:46 | 00,388,608 | ---- | C] (Microsoft Corporation) CF10474.exe -> %SystemRoot%\System32\CF10474.exe -> [2009-01-10 15:38:11 | 00,388,608 | ---- | C] (Microsoft Corporation) CF3998.exe -> %SystemRoot%\System32\CF3998.exe -> [2009-01-10 15:04:48 | 00,388,608 | ---- | C] (Microsoft Corporation) CF3505.exe -> %SystemRoot%\System32\CF3505.exe -> [2009-01-10 15:02:17 | 00,388,608 | ---- | C] (Microsoft Corporation) Boot.bak -> %SystemDrive%\Boot.bak -> [2009-01-10 14:25:39 | 00,000,211 | ---- | C] () cmldr -> %SystemDrive%\cmldr -> [2009-01-10 14:25:36 | 00,260,272 | ---- | C] () cmdcons -> %SystemDrive%\cmdcons -> [2009-01-10 14:25:34 | 00,000,000 | RHSD | C] CF25425.exe -> %SystemRoot%\System32\CF25425.exe -> [2009-01-10 14:07:14 | 00,388,608 | ---- | C] (Microsoft Corporation) SWXCACLS.exe -> %SystemRoot%\SWXCACLS.exe -> [2009-01-10 13:52:01 | 00,212,480 | ---- | C] (SteelWerX) SWREG.exe -> %SystemRoot%\SWREG.exe -> [2009-01-10 13:52:01 | 00,161,792 | ---- | C] (SteelWerX) SWSC.exe -> %SystemRoot%\SWSC.exe -> [2009-01-10 13:52:01 | 00,136,704 | ---- | C] (SteelWerX) sed.exe -> %SystemRoot%\sed.exe -> [2009-01-10 13:52:01 | 00,098,816 | ---- | C] () fdsv.exe -> %SystemRoot%\fdsv.exe -> [2009-01-10 13:52:01 | 00,089,504 | ---- | C] (Smallfrogs Studio) grep.exe -> %SystemRoot%\grep.exe -> [2009-01-10 13:52:01 | 00,080,412 | ---- | C] () zip.exe -> %SystemRoot%\zip.exe -> [2009-01-10 13:52:01 | 00,068,096 | ---- | C] () VFIND.exe -> %SystemRoot%\VFIND.exe -> [2009-01-10 13:52:01 | 00,049,152 | ---- | C] () NIRCMD.exe -> %SystemRoot%\NIRCMD.exe -> [2009-01-10 13:52:01 | 00,029,696 | ---- | C] (NirSoft) CF22483.exe -> %SystemRoot%\System32\CF22483.exe -> [2009-01-10 13:51:54 | 00,388,608 | ---- | C] (Microsoft Corporation) CF13894.exe -> %SystemRoot%\System32\CF13894.exe -> [2009-01-10 13:08:05 | 00,388,608 | ---- | C] (Microsoft Corporation) CF21308.exe -> %SystemRoot%\System32\CF21308.exe -> [2009-01-10 10:58:42 | 00,388,608 | ---- | C] (Microsoft Corporation) CF22378.exe -> %SystemRoot%\System32\CF22378.exe -> [2009-01-09 15:33:27 | 00,388,608 | ---- | C] (Microsoft Corporation) CF21604.exe -> %SystemRoot%\System32\CF21604.exe -> [2009-01-09 15:29:32 | 00,388,608 | ---- | C] (Microsoft Corporation) CF17261.exe -> %SystemRoot%\System32\CF17261.exe -> [2009-01-09 15:07:21 | 00,388,608 | ---- | C] (Microsoft Corporation) CF9701.exe -> %SystemRoot%\System32\CF9701.exe -> [2009-01-09 14:28:44 | 00,388,608 | ---- | C] (Microsoft Corporation) CF5563.exe -> %SystemRoot%\System32\CF5563.exe -> [2009-01-09 14:07:40 | 00,388,608 | ---- | C] (Microsoft Corporation) iTunes.lnk -> %UserProfile%\Desktop\iTunes.lnk -> [2009-01-07 21:09:22 | 00,002,137 | ---- | C] () trend micro -> %ProgramFiles%\trend micro -> [2009-01-06 07:23:48 | 00,000,000 | ---D | C] rsit -> %SystemDrive%\rsit -> [2009-01-06 07:23:47 | 00,000,000 | ---D | C] RSIT.exe -> %UserProfile%\Desktop\RSIT.exe -> [2009-01-06 07:22:45 | 00,781,851 | ---- | C] () Kaylee's games -> %UserProfile%\Desktop\Kaylee's games -> [2009-01-01 22:09:48 | 00,000,000 | ---D | C] Malwarebytes -> %AppData%\Malwarebytes -> [2008-12-31 23:24:09 | 00,000,000 | ---D | C] Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2008-12-31 23:24:01 | 00,000,696 | ---- | C] () mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008-12-31 23:23:59 | 00,015,504 | ---- | C] (Malwarebytes Corporation) mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008-12-31 23:23:51 | 00,038,496 | ---- | C] (Malwarebytes Corporation) Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2008-12-31 23:23:48 | 00,000,000 | ---D | C] Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2008-12-31 23:23:46 | 00,000,000 | ---D | C] Hijackthis.lnk -> %UserProfile%\Desktop\Hijackthis.lnk -> [2008-12-29 18:52:16 | 00,000,650 | ---- | C] () Hijackthis -> %ProgramFiles%\Hijackthis -> [2008-12-29 18:52:13 | 00,000,000 | ---D | C] sidekick 3 user manual.pdf -> %UserProfile%\My Documents\sidekick 3 user manual.pdf -> [2008-12-25 17:49:28 | 04,596,787 | ---- | C] () sidekick - getting srarted.pdf -> %UserProfile%\My Documents\sidekick - getting srarted.pdf -> [2008-12-25 17:46:58 | 01,065,707 | ---- | C] () autorun.inf -> %SystemDrive%\autorun.inf -> [2008-12-25 13:52:53 | 00,000,000 | RHSD | C] exit -> %UserProfile%\exit -> [2008-12-24 11:43:17 | 00,000,000 | ---- | C] () attrib -> %UserProfile%\attrib -> [2008-12-24 11:27:37 | 00,000,000 | ---- | C] () attrib -> %SystemDrive%\attrib -> [2008-12-24 10:47:07 | 00,000,000 | ---- | C] () CF22035.exe -> %SystemRoot%\System32\CF22035.exe -> [2008-12-23 22:09:16 | 00,388,608 | ---- | C] (Microsoft Corporation) Qoobox -> %SystemDrive%\Qoobox -> [2008-12-23 22:06:15 | 00,000,000 | ---D | C] ERDNT -> %SystemRoot%\ERDNT -> [2008-12-23 22:06:15 | 00,000,000 | ---D | C] CF21408.exe -> %SystemRoot%\System32\CF21408.exe -> [2008-12-23 22:06:11 | 00,388,608 | ---- | C] (Microsoft Corporation) Flash_Disinfector.exe -> %UserProfile%\Desktop\Flash_Disinfector.exe -> [2008-12-23 21:55:36 | 00,132,597 | ---- | C] () cleanautorun.exe -> %UserProfile%\Desktop\cleanautorun.exe -> [2008-12-21 22:44:06 | 00,458,752 | ---- | C] (Proland Software) DQ Tycoon -> %ProgramFiles%\DQ Tycoon -> [2008-12-21 19:56:22 | 00,000,000 | ---D | C] Kaylee The Lioness.doc -> %UserProfile%\My Documents\Kaylee The Lioness.doc -> [2008-12-18 10:48:18 | 00,020,480 | ---- | C] () Memory Poem.doc -> %UserProfile%\My Documents\Memory Poem.doc -> [2008-12-18 10:36:14 | 00,020,480 | ---- | C] () pbsvc.exe -> %UserProfile%\Desktop\pbsvc.exe -> [2008-12-17 21:50:55 | 00,682,280 | ---- | C] () [Files/Folders - Modified Within 30 Days] 6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 1 C:\Documents and Settings\T&A\My Documents\*.tmp files -> C:\Documents and Settings\T&A\My Documents\*.tmp -> 67 C:\Documents and Settings\T&A\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\T&A\Local Settings\Temp\*.tmp -> 67 C:\Documents and Settings\T&A\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\T&A\Local Settings\Temp\*.tmp -> OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009-01-16 07:56:48 | 00,656,730 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009-01-16 06:13:07 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009-01-16 06:13:05 | 00,002,048 | --S- | M] () ntuser.dat -> %UserProfile%\ntuser.dat -> [2009-01-15 21:44:27 | 09,961,472 | ---- | M] () ntuser.ini -> %UserProfile%\ntuser.ini -> [2009-01-15 21:44:01 | 00,000,278 | -HS- | M] () iTunes.lnk -> %UserProfile%\Desktop\iTunes.lnk -> [2009-01-15 20:22:13 | 00,002,137 | ---- | M] () spider.sav -> %UserProfile%\My Documents\spider.sav -> [2009-01-15 19:06:02 | 00,000,520 | ---- | M] () iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2009-01-15 18:23:27 | 00,002,137 | ---- | M] () Scheduled scanning task.job -> %SystemRoot%\tasks\Scheduled scanning task.job -> [2009-01-15 16:03:10 | 00,000,526 | ---- | M] () Kaylee A Dark and Stormy Night.doc -> %UserProfile%\My Documents\Kaylee A Dark and Stormy Night.doc -> [2009-01-15 08:28:01 | 00,020,992 | ---- | M] () dellstat.ini -> %SystemRoot%\dellstat.ini -> [2009-01-14 20:27:07 | 00,000,469 | ---- | M] () Shortcut to Contaminated area Woodley Road Ladysmith Harbour May 20 2008 045.jpg.lnk -> %UserProfile%\Desktop\Shortcut to Contaminated area Woodley Road Ladysmith Harbour May 20 2008 045.jpg.lnk -> [2009-01-14 19:32:23 | 00,000,443 | ---- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009-01-14 09:30:01 | 00,002,206 | ---- | M] () IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009-01-14 01:11:05 | 02,109,926 | -H-- | M] () qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009-01-13 22:54:10 | 00,005,887 | ---- | M] () qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009-01-13 22:54:10 | 00,004,617 | ---- | M] () sarsfx.exe -> %UserProfile%\Desktop\sarsfx.exe -> [2009-01-13 18:44:10 | 01,181,383 | ---- | M] () Disk Cleanup.job -> %SystemRoot%\tasks\Disk Cleanup.job -> [2009-01-13 18:08:00 | 00,000,256 | ---- | M] () drm_dyndata_7330014.dll -> %UserProfile%\Local Settings\Temp\drm_dyndata_7330014.dll -> [2009-01-13 14:05:21 | 00,212,992 | ---- | M] (Sony DADC Austria AG) drm_dyndata_7380009.dll -> %UserProfile%\Local Settings\Temp\drm_dyndata_7380009.dll -> [2009-01-13 13:36:52 | 00,204,800 | ---- | M] (Sony DADC Austria AG) When You Were Young lyrics.doc -> %UserProfile%\My Documents\When You Were Young lyrics.doc -> [2009-01-13 07:26:30 | 00,020,992 | ---- | M] () When You Were Young.doc -> %UserProfile%\My Documents\When You Were Young.doc -> [2009-01-13 07:21:57 | 00,023,040 | ---- | M] () ~$en You Were Young.doc -> %UserProfile%\My Documents\~$en You Were Young.doc -> [2009-01-13 07:18:36 | 00,000,162 | -H-- | M] () Microsoft Word.lnk -> %UserProfile%\Desktop\Microsoft Word.lnk -> [2009-01-12 20:59:16 | 00,002,483 | ---- | M] () canada-map.gif -> %UserProfile%\Desktop\canada-map.gif -> [2009-01-12 20:01:48 | 00,059,179 | ---- | M] () win.ini -> %SystemRoot%\win.ini -> [2009-01-12 19:31:41 | 00,001,140 | ---- | M] () PAVARK.exe -> %UserProfile%\Local Settings\Temp\PAVARK.exe -> [2009-01-12 19:12:52 | 00,744,853 | ---- | M] () AntiRootkit.zip -> %UserProfile%\Desktop\AntiRootkit.zip -> [2009-01-12 19:12:13 | 00,311,591 | ---- | M] () CF24175.exe -> %SystemRoot%\System32\CF24175.exe -> [2009-01-12 18:58:01 | 00,388,608 | ---- | M] (Microsoft Corporation) CF23029.exe -> %SystemRoot%\System32\CF23029.exe -> [2009-01-12 18:52:10 | 00,388,608 | ---- | M] (Microsoft Corporation) CF22085.exe -> %SystemRoot%\System32\CF22085.exe -> [2009-01-12 18:47:21 | 00,388,608 | ---- | M] (Microsoft Corporation) catchme.dll -> %UserProfile%\Local Settings\Temp\catchme.dll -> [2009-01-12 18:25:14 | 00,053,248 | ---- | M] () CF16448.exe -> %SystemRoot%\System32\CF16448.exe -> [2009-01-12 18:18:36 | 00,388,608 | ---- | M] (Microsoft Corporation) CF13676.exe -> %SystemRoot%\System32\CF13676.exe -> [2009-01-12 18:04:26 | 00,388,608 | ---- | M] (Microsoft Corporation) CF10714.exe -> %SystemRoot%\System32\CF10714.exe -> [2009-01-12 17:49:19 | 00,388,608 | ---- | M] (Microsoft Corporation) CF10280.exe -> %SystemRoot%\System32\CF10280.exe -> [2009-01-12 17:47:06 | 00,388,608 | ---- | M] (Microsoft Corporation) CF10149.exe -> %SystemRoot%\System32\CF10149.exe -> [2009-01-12 17:46:26 | 00,388,608 | ---- | M] (Microsoft Corporation) Backup.job -> %SystemRoot%\tasks\Backup.job -> [2009-01-12 17:06:00 | 00,000,256 | ---- | M] () You sit there in your heartache.doc -> %UserProfile%\My Documents\You sit there in your heartache.doc -> [2009-01-11 14:35:15 | 00,020,992 | ---- | M] () CF19462.exe -> %SystemRoot%\System32\CF19462.exe -> [2009-01-11 11:54:20 | 00,388,608 | ---- | M] (Microsoft Corporation) CF18568.exe -> %SystemRoot%\System32\CF18568.exe -> [2009-01-11 11:49:46 | 00,388,608 | ---- | M] (Microsoft Corporation) gmer.ini -> %SystemRoot%\gmer.ini -> [2009-01-11 10:40:02 | 00,000,250 | ---- | M] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2009-01-11 10:39:59 | 00,085,969 | ---- | M] (GMER) gmer.dll -> %SystemRoot%\gmer.dll -> [2009-01-11 10:39:55 | 00,884,736 | ---- | M] () gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2009-01-11 10:39:55 | 00,000,080 | ---- | M] () gmer.zip -> %UserProfile%\Desktop\gmer.zip -> [2009-01-11 10:30:17 | 00,747,873 | ---- | M] () CF23389.exe -> %SystemRoot%\System32\CF23389.exe -> [2009-01-10 16:43:43 | 00,388,608 | ---- | M] (Microsoft Corporation) CF10474.exe -> %SystemRoot%\System32\CF10474.exe -> [2009-01-10 15:37:46 | 00,388,608 | ---- | M] (Microsoft Corporation) CF3998.exe -> %SystemRoot%\System32\CF3998.exe -> [2009-01-10 15:04:44 | 00,388,608 | ---- | M] (Microsoft Corporation) CF3505.exe -> %SystemRoot%\System32\CF3505.exe -> [2009-01-10 15:02:13 | 00,388,608 | ---- | M] (Microsoft Corporation) boot.ini -> %SystemDrive%\boot.ini -> [2009-01-10 14:25:39 | 00,000,281 | RHS- | M] () CF25425.exe -> %SystemRoot%\System32\CF25425.exe -> [2009-01-10 14:06:50 | 00,388,608 | ---- | M] (Microsoft Corporation) CF22483.exe -> %SystemRoot%\System32\CF22483.exe -> [2009-01-10 13:51:50 | 00,388,608 | ---- | M] (Microsoft Corporation) CF13894.exe -> %SystemRoot%\System32\CF13894.exe -> [2009-01-10 13:08:00 | 00,388,608 | ---- | M] (Microsoft Corporation) CF21308.exe -> %SystemRoot%\System32\CF21308.exe -> [2009-01-10 10:58:37 | 00,388,608 | ---- | M] (Microsoft Corporation) sccfg.sys -> %SystemDrive%\sccfg.sys -> [2009-01-10 10:37:51 | 00,000,020 | ---- | M] () MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2009-01-09 17:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) CF22378.exe -> %SystemRoot%\System32\CF22378.exe -> [2009-01-09 15:33:23 | 00,388,608 | ---- | M] (Microsoft Corporation) cmd.execf -> %UserProfile%\Local Settings\Temp\cmd.execf -> [2009-01-09 15:29:26 | 00,388,608 | ---- | M] (Microsoft Corporation) CF21604.exe -> %SystemRoot%\System32\CF21604.exe -> [2009-01-09 15:29:26 | 00,388,608 | ---- | M] (Microsoft Corporation) CF17261.exe -> %SystemRoot%\System32\CF17261.exe -> [2009-01-09 15:07:15 | 00,388,608 | ---- | M] (Microsoft Corporation) Thumbs.db -> %UserProfile%\My Documents\Thumbs.db -> [2009-01-09 15:05:06 | 00,276,480 | -HS- | M] () CF9701.exe -> %SystemRoot%\System32\CF9701.exe -> [2009-01-09 14:28:41 | 00,388,608 | ---- | M] (Microsoft Corporation) CF5563.exe -> %SystemRoot%\System32\CF5563.exe -> [2009-01-09 14:07:34 | 00,388,608 | ---- | M] (Microsoft Corporation) RSIT.exe -> %UserProfile%\Desktop\RSIT.exe -> [2009-01-06 07:22:52 | 00,781,851 | ---- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009-01-04 18:38:22 | 00,038,496 | ---- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009-01-04 18:38:18 | 00,015,504 | ---- | M] (Malwarebytes Corporation) Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2008-12-31 23:24:01 | 00,000,696 | ---- | M] () Hijackthis.lnk -> %UserProfile%\Desktop\Hijackthis.lnk -> [2008-12-29 18:52:16 | 00,000,650 | ---- | M] () My Sharing Folders.lnk -> %UserProfile%\My Documents\My Sharing Folders.lnk -> [2008-12-26 12:12:52 | 00,000,602 | ---- | M] () NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [2008-12-25 18:48:49 | 00,000,069 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008-12-25 18:46:41 | 00,084,480 | ---- | M] () sidekick 3 user manual.pdf -> %UserProfile%\My Documents\sidekick 3 user manual.pdf -> [2008-12-25 17:49:28 | 04,596,787 | ---- | M] () sidekick - getting srarted.pdf -> %UserProfile%\My Documents\sidekick - getting srarted.pdf -> [2008-12-25 17:46:58 | 01,065,707 | ---- | M] () exit -> %UserProfile%\exit -> [2008-12-24 11:43:17 | 00,000,000 | ---- | M] () attrib -> %UserProfile%\attrib -> [2008-12-24 11:29:05 | 00,000,000 | ---- | M] () attrib -> %SystemDrive%\attrib -> [2008-12-24 10:47:07 | 00,000,000 | ---- | M] () wuaucpl.cpl.manifest -> %SystemRoot%\System32\wuaucpl.cpl.manifest -> [2008-12-24 10:34:47 | 00,000,749 | RH-- | M] () WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest -> [2008-12-24 10:34:47 | 00,000,749 | RH-- | M] () sapi.cpl.manifest -> %SystemRoot%\System32\sapi.cpl.manifest -> [2008-12-24 10:34:47 | 00,000,749 | RH-- | M] () nwc.cpl.manifest -> %SystemRoot%\System32\nwc.cpl.manifest -> [2008-12-24 10:34:47 | 00,000,749 | RH-- | M] () ncpa.cpl.manifest -> %SystemRoot%\System32\ncpa.cpl.manifest -> [2008-12-24 10:34:47 | 00,000,749 | RH-- | M] () cdplayer.exe.manifest -> %SystemRoot%\System32\cdplayer.exe.manifest -> [2008-12-24 10:34:47 | 00,000,749 | RH-- | M] () CF22035.exe -> %SystemRoot%\System32\CF22035.exe -> [2008-12-23 22:09:10 | 00,388,608 | ---- | M] (Microsoft Corporation) CF21408.exe -> %SystemRoot%\System32\CF21408.exe -> [2008-12-23 22:05:57 | 00,388,608 | ---- | M] (Microsoft Corporation) Flash_Disinfector.exe -> %UserProfile%\Desktop\Flash_Disinfector.exe -> [2008-12-23 21:55:37 | 00,132,597 | ---- | M] () drm_dyndata_7350007.dll -> %UserProfile%\Local Settings\Temp\drm_dyndata_7350007.dll -> [2008-12-22 15:30:35 | 00,212,992 | ---- | M] (Sony DADC Austria AG) cleanautorun.exe -> %UserProfile%\Desktop\cleanautorun.exe -> [2008-12-21 22:44:12 | 00,458,752 | ---- | M] (Proland Software) Kaylee The Lioness.doc -> %UserProfile%\My Documents\Kaylee The Lioness.doc -> [2008-12-18 18:19:46 | 00,020,480 | ---- | M] () Memory Poem.doc -> %UserProfile%\My Documents\Memory Poem.doc -> [2008-12-18 18:18:57 | 00,020,480 | ---- | M] () imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008-12-18 07:12:45 | 00,001,393 | ---- | M] () pbsvc.exe -> %UserProfile%\Desktop\pbsvc.exe -> [2008-12-17 21:51:01 | 00,682,280 | ---- | M] () System.dll -> %UserProfile%\Local Settings\Temp\nsn79E.tmp\System.dll -> [2008-12-13 22:51:55 | 00,009,728 | ---- | M] () System.dll -> %UserProfile%\Local Settings\Temp\nss79A.tmp\System.dll -> [2008-12-13 22:49:42 | 00,009,728 | ---- | M] () System.dll -> %UserProfile%\Local Settings\Temp\nsf797.tmp\System.dll -> [2008-12-13 22:48:39 | 00,009,728 | ---- | M] () index.dat -> %UserProfile%\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008-12-07 18:52:38 | 00,032,768 | ---- | M] () index.dat -> %UserProfile%\Local Settings\Temp\History\History.IE5\index.dat -> [2008-12-07 18:52:38 | 00,016,384 | ---- | M] () index.dat -> %UserProfile%\Local Settings\Temp\Cookies\index.dat -> [2008-12-07 18:52:38 | 00,016,384 | ---- | M] () ~swd1.dat -> %UserProfile%\Local Settings\Temp\501Fwrd.~lk\6344wrdata.~lk\~swd1.dat -> [2008-11-30 20:55:56 | 27,388,151 | ---- | M] () swt-gdip-win32-3448.dll -> %UserProfile%\Local Settings\Temp\swt-gdip-win32-3448.dll -> [2008-11-29 15:41:08 | 00,077,824 | ---- | M] (Eclipse Foundation) swt-win32-3448.dll -> %UserProfile%\Local Settings\Temp\swt-win32-3448.dll -> [2008-11-29 15:41:06 | 00,335,872 | ---- | M] (Eclipse Foundation) swt-gdip-win32-3430.dll -> %UserProfile%\Local Settings\Temp\swt-gdip-win32-3430.dll -> [2008-11-28 11:31:59 | 00,077,824 | ---- | M] (Eclipse Foundation) swt-win32-3430.dll -> %UserProfile%\Local Settings\Temp\swt-win32-3430.dll -> [2008-11-28 11:31:56 | 00,323,584 | ---- | M] (Eclipse Foundation) CmdLineExt.dll -> %UserProfile%\Local Settings\Temp\CmdLineExt.dll -> [2008-10-14 17:30:10 | 00,107,888 | ---- | M] (Sony DADC Austria AG.) drm_dyndata_7370008.dll -> %UserProfile%\Local Settings\Temp\drm_dyndata_7370008.dll -> [2008-10-12 12:42:23 | 00,204,800 | ---- | M] (Sony DADC Austria AG) bfguni.exe -> %UserProfile%\Local Settings\Temp\bfguni.exe -> [2008-09-21 18:16:42 | 00,119,453 | ---- | M] (Big Fish Games) data.dat -> %AllUsersProfile%\Application Data\Microsoft\Office\Data\data.dat -> [2008-09-15 16:10:41 | 00,001,388 | ---- | M] () AutoRun.exe -> %UserProfile%\Local Settings\Temp\AutoRun.exe -> [2008-01-11 08:05:48 | 00,703,552 | ---- | M] (Electronic Arts Inc.) AutoRunGUI.dll -> %UserProfile%\Local Settings\Temp\AutoRunGUI.dll -> [2008-01-11 07:17:04 | 00,662,592 | ---- | M] (Electronic Arts Inc.) ISSetup.dll -> %UserProfile%\Local Settings\Temp\{69DA2135-A277-4BC1-864F-6FCFAD381528}\ISSetup.dll -> [2007-04-05 13:36:12 | 00,492,032 | R--- | M] (Macrovision Corporation) _is1D7.exe -> %UserProfile%\Local Settings\Temp\_is1D7.exe -> [2007-02-27 15:08:44 | 00,456,416 | R--- | M] (Macrovision Corporation) _is54D.exe -> %UserProfile%\Local Settings\Temp\_is54D.exe -> [2007-01-20 03:46:42 | 00,455,600 | R--- | M] (Macrovision Corporation) ISSetup.dll -> %UserProfile%\Local Settings\Temp\{5D58A337-26C8-4D5D-801F-00C543FB42C9}\ISSetup.dll -> [2007-01-20 03:43:24 | 00,492,032 | R--- | M] (Macrovision Corporation) _Setup.dll -> %UserProfile%\Local Settings\Temp\{5D58A337-26C8-4D5D-801F-00C543FB42C9}\_Setup.dll -> [2006-05-17 11:21:06 | 00,152,496 | R--- | M] (Macrovision Corporation) data.dat -> %AllUsersProfile%\Application Data\Microsoft\Windows Genuine Advantage\data\data.dat -> [2004-11-28 21:52:51 | 00,002,756 | ---- | M] () setup_wm.exe -> %UserProfile%\Local Settings\Temp\setup_wm.exe -> [2004-09-22 18:46:04 | 00,819,200 | ---- | M] (Microsoft Corporation) VP6VFW.dll -> %UserProfile%\Local Settings\Temp\VP6VFW.dll -> [2004-08-18 01:17:21 | 00,442,368 | R--- | M] (On2.com) VP6Install.exe -> %UserProfile%\Local Settings\Temp\VP6Install.exe -> [2004-08-18 01:17:20 | 00,023,040 | R--- | M] () ISUNINST.EXE -> %UserProfile%\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\ISUNINST.EXE -> [1998-10-29 16:45:06 | 00,306,688 | R--- | M] (InstallShield Software Corporation) 5d7f9b.DLL -> %UserProfile%\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\5d7f9b.DLL -> [1998-09-22 19:05:48 | 00,129,536 | R--- | M] (InstallShield Software Corporation) CTL3D32.DLL -> %UserProfile%\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\CTL3D32.DLL -> [1995-07-13 17:46:26 | 00,027,136 | R--- | M] (Microsoft Corporation) [Alternate Data Streams] @Alternate Data Stream - 0 bytes -> %AllUsersProfile%\Application Data\TEMP:48FEA089 @Alternate Data Stream - 0 bytes -> %SystemRoot%\System32\Thumbs.db:encryptable @Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable @Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable @Alternate Data Stream - 100 bytes -> %AllUsersProfile%\Application Data\TEMP:3313A48D @Alternate Data Stream - 100 bytes -> %AllUsersProfile%\Application Data\TEMP:8E7F155B @Alternate Data Stream - 100 bytes -> %AllUsersProfile%\Application Data\TEMP:98DFF516 @Alternate Data Stream - 102 bytes -> %AllUsersProfile%\Application Data\TEMP:241FA548 @Alternate Data Stream - 102 bytes -> %AllUsersProfile%\Application Data\TEMP:483AC68A @Alternate Data Stream - 103 bytes -> %AllUsersProfile%\Application Data\TEMP:409A775B @Alternate Data Stream - 103 bytes -> %AllUsersProfile%\Application Data\TEMP:4DCAC4BC @Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:63CFD724 @Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:8247A199 @Alternate Data Stream - 105 bytes -> %AllUsersProfile%\Application Data\TEMP:10D98D98 @Alternate Data Stream - 105 bytes -> %AllUsersProfile%\Application Data\TEMP:6BD304B9 @Alternate Data Stream - 106 bytes -> %AllUsersProfile%\Application Data\TEMP:831C6B2D @Alternate Data Stream - 107 bytes -> %AllUsersProfile%\Application Data\TEMP:94F67F32 @Alternate Data Stream - 109 bytes -> %AllUsersProfile%\Application Data\TEMP:55E3C0E0 @Alternate Data Stream - 109 bytes -> %AllUsersProfile%\Application Data\TEMP:84151293 @Alternate Data Stream - 110 bytes -> %AllUsersProfile%\Application Data\TEMP:8366033F @Alternate Data Stream - 111 bytes -> %AllUsersProfile%\Application Data\TEMP:2BC498A4 @Alternate Data Stream - 112 bytes -> %AllUsersProfile%\Application Data\TEMP:270A3983 @Alternate Data Stream - 112 bytes -> %AllUsersProfile%\Application Data\TEMP:3A6BC948 @Alternate Data Stream - 112 bytes -> %AllUsersProfile%\Application Data\TEMP:81653DC8 @Alternate Data Stream - 112 bytes -> %AllUsersProfile%\Application Data\TEMP:945FE29C @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:13AA281B @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:453190EC @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:7776B809 @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:D7DA89B1 @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:E866ED4D @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:F42B5B0E @Alternate Data Stream - 114 bytes -> %AllUsersProfile%\Application Data\TEMP:7C411C08 @Alternate Data Stream - 114 bytes -> %AllUsersProfile%\Application Data\TEMP:C20426BD @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:331B76C7 @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:6FA38600 @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:C7B98566 @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:D507B5A8 @Alternate Data Stream - 116 bytes -> %AllUsersProfile%\Application Data\TEMP:1F67CD26 @Alternate Data Stream - 117 bytes -> %AllUsersProfile%\Application Data\TEMP:55F44B88 @Alternate Data Stream - 117 bytes -> %AllUsersProfile%\Application Data\TEMP:9547F1DB @Alternate Data Stream - 118 bytes -> %AllUsersProfile%\Application Data\TEMP:260575F1 @Alternate Data Stream - 119 bytes -> %AllUsersProfile%\Application Data\TEMP:A6346EE9 @Alternate Data Stream - 121 bytes -> %AllUsersProfile%\Application Data\TEMP:FDDE312D @Alternate Data Stream - 122 bytes -> %AllUsersProfile%\Application Data\TEMP:70E897B5 @Alternate Data Stream - 122 bytes -> %AllUsersProfile%\Application Data\TEMP:7C412B92 @Alternate Data Stream - 122 bytes -> %AllUsersProfile%\Application Data\TEMP:9398DBB4 @Alternate Data Stream - 123 bytes -> %AllUsersProfile%\Application Data\TEMP:A56D6987 @Alternate Data Stream - 123 bytes -> %AllUsersProfile%\Application Data\TEMP:F5E623BF @Alternate Data Stream - 124 bytes -> %AllUsersProfile%\Application Data\TEMP:0ED4AC2F @Alternate Data Stream - 124 bytes -> %AllUsersProfile%\Application Data\TEMP:B2735F9E @Alternate Data Stream - 125 bytes -> %AllUsersProfile%\Application Data\TEMP:43301D1D @Alternate Data Stream - 125 bytes -> %AllUsersProfile%\Application Data\TEMP:9E3E060F @Alternate Data Stream - 125 bytes -> %AllUsersProfile%\Application Data\TEMP:A3750BE5 @Alternate Data Stream - 125 bytes -> %AllUsersProfile%\Application Data\TEMP:B12D1A7D @Alternate Data Stream - 126 bytes -> %AllUsersProfile%\Application Data\TEMP:0BF96601 @Alternate Data Stream - 127 bytes -> %AllUsersProfile%\Application Data\TEMP:AA0E2C50 @Alternate Data Stream - 129 bytes -> %AllUsersProfile%\Application Data\TEMP:D2C57161 @Alternate Data Stream - 20 bytes -> %UserProfile%\Local Settings\Temp\PAVARK.exe:License @Alternate Data Stream - 211 bytes -> %AllUsersProfile%\Application Data\TEMP:24FECE50 @Alternate Data Stream - 213 bytes -> %AllUsersProfile%\Application Data\TEMP:3F403D65 @Alternate Data Stream - 214 bytes -> %AllUsersProfile%\Application Data\TEMP:7A0EFE63 @Alternate Data Stream - 215 bytes -> %AllUsersProfile%\Application Data\TEMP:848CC150 @Alternate Data Stream - 217 bytes -> %AllUsersProfile%\Application Data\TEMP:3766E957 @Alternate Data Stream - 219 bytes -> %AllUsersProfile%\Application Data\TEMP:B2FEAB71 @Alternate Data Stream - 225 bytes -> %AllUsersProfile%\Application Data\TEMP:E11EAB84 @Alternate Data Stream - 228 bytes -> %AllUsersProfile%\Application Data\TEMP:1F96ED45 @Alternate Data Stream - 228 bytes -> %AllUsersProfile%\Application Data\TEMP:A00BCDEF @Alternate Data Stream - 231 bytes -> %AllUsersProfile%\Application Data\TEMP:60C897F3 @Alternate Data Stream - 233 bytes -> %AllUsersProfile%\Application Data\TEMP:417B6FAC < End of report > [/code]