QUOTE(Rorschach112 @ Jun 3 2009, 09:25 PM)

hi
- Download OTL to your desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Under Custom Scan paste this in
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%systemroot%\System32\antiwpa.dll
%systemroot%\SYSTEM32\wpa.dll
%systemroot%\setup\scripts\biestart.exe
%systemroot%\system32\drivers\royal.sys
%SYSTEMDRIVE%\*.
%SYSTEMDRIVE%\*.*
%PROGRAMFILES%\*.
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTL logfile created on: 6/3/2009 8:16:13 PM - Run 2
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\siegeltuch\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 285.50 Gb Total Space | 212.41 Gb Free Space | 74.40% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 297.81 Gb Free Space | 99.91% Space Free | Partition Type: NTFS
Drive E: | 10.00 Gb Total Space | 5.17 Gb Free Space | 51.71% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SIEGELTUCH-PC
Current User Name: siegeltuch
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== PRC - C:\Windows\System32\WLTRYSVC.EXE ()
PRC - C:\Windows\System32\bcmwltry.exe (Dell Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Windows\system32\aestsrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
PRC - C:\Windows\System32\rpcnetp.exe ()
PRC - C:\Program Files\Adobe\Adobe RoboSource Control 3.1\RSO3MiddleTierService.exe (Adobe Systems)
PRC - C:\Program Files\Adobe\Adobe RoboSource Control 3.1\RSO3Server.exe (Adobe Systems)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Windows\system32\STacSV.exe (IDT, Inc.)
PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\WLTRAY.EXE (Dell Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Adobe\Acrobat 8\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe (TechSmith Corporation)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\ehome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe (TechSmith Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\TechSmith\SnagIt 8\SnagPriv.exe (TechSmith Corporation)
PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)
PRC - C:\Windows\notepad.exe (Microsoft Corporation)
PRC - C:\Users\siegeltuch\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (AESTFilters [Auto | Running]) -- C:\Windows\system32\aestsrv.exe (Andrea Electronics Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CTAudSvcService [Auto | Running]) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Running]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-010708-104812 [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (GoToAssist [On_Demand | Stopped]) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSK80Service [Auto | Running]) -- C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (rpcnetp [Unknown | Running]) -- C:\Windows\System32\rpcnetp.dll ()
SRV - (RSO3MiddleTierService [Auto | Running]) -- C:\Program Files\Adobe\Adobe RoboSource Control 3.1\RSO3MiddleTierService.exe (Adobe Systems)
SRV - (RSO3Server [Auto | Running]) -- C:\Program Files\Adobe\Adobe RoboSource Control 3.1\RSO3Server.exe (Adobe Systems)
SRV - (sprtsvc_dellsupportcenter [Auto | Running]) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (STacSV [Auto | Running]) -- C:\Windows\system32\STacSV.exe (IDT, Inc.)
SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (WinDefend [Auto | Stopped]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (wltrysvc [Auto | Running]) -- C:\Windows\System32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [On_Demand | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) -- C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
========== Driver Services (SafeList) ========== DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (BCM43XX [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corp.)
DRV - (bcm4sbxp [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (e1express [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (iaStor [Boot | Running]) -- C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (iaStorV [Boot | Running]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (Lbd [Boot | Running]) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) -- C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (mfeavfk [On_Demand | Running]) -- C:\Windows\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\Windows\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) -- C:\Windows\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) -- C:\Windows\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) -- C:\Windows\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvlddmkm [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (OEM02Dev [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (PxHelp20 [Boot | Running]) -- C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (rimmptsk [Auto | Running]) -- C:\Windows\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) -- C:\Windows\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) -- C:\Windows\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) -- C:\Windows\system32\drivers\stwrt.sys (IDT, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (t3 [On_Demand | Stopped]) -- C:\Windows\system32\drivers\t3.sys (Creative Technology Ltd.)
DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (winachsf [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) -- C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/dell?hl=en&cl...amp;ibd=6080702IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/dell?hl=en&cl...amp;ibd=6080702IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071302000002
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.94
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/10 13:09:37 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 19:44:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 19:44:04 | 00,000,000 | ---D | M]
[2009/02/21 18:34:28 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\mozilla\Extensions
[2008/07/10 12:49:58 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/02/21 18:34:28 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2009/06/03 18:27:49 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\mozilla\Firefox\Profiles\crzvlvex.default\extensions
[2009/02/18 21:04:30 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\mozilla\Firefox\Profiles\crzvlvex.default\extensions\moveplayer@movenetworks.com
[2009/05/06 13:13:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/04/28 19:44:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/08/03 16:18:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/04/28 19:43:57 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 19:43:57 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/28 19:44:02 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/28 19:44:02 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/28 19:44:02 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/28 19:44:02 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/28 19:44:02 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/28 19:44:02 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/28 19:44:02 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 8\Acrobat\Acrobat_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" ( )
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (SupportSoft, Inc.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
O4 - HKCU..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Users\siegeltuch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SnagIt 8.lnk = C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe (TechSmith Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries 0000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries 0000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries 0000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries 0000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O18 - Protocol\Handler\httpx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\httpsx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaippx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\system32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{1edccd66-60a5-11dd-8335-001d09dd1072}\Shell - "" = AutoRun
O33 - MountPoints2\{1edccd66-60a5-11dd-8335-001d09dd1072}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O33 - MountPoints2\{fc0549bb-0064-11de-9f8c-001d09dd1072}\Shell\AutoRun\command - "" = H:\InstallTomTomHOME.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe ()
O34 - HKLM BootExecute: (*) - * [2009/06/03 20:14:56 | 00,000,000 | R--D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
NetSvcs: AeLookupSvc - C:\Windows\System32\aelupsvc.dll (Microsoft Corporation)
NetSvcs: wercplsupport - C:\Windows\System32\wercplsupport.dll (Microsoft Corporation)
NetSvcs: Themes - C:\Windows\system32\shsvcs.dll (Microsoft Corporation)
NetSvcs: CertPropSvc - C:\Windows\System32\certprop.dll (Microsoft Corporation)
NetSvcs: SCPolicySvc - C:\Windows\System32\certprop.dll (Microsoft Corporation)
NetSvcs: lanmanserver - C:\Windows\system32\srvsvc.dll (Microsoft Corporation)
NetSvcs: gpsvc - C:\Windows\System32\gpsvc.dll (Microsoft Corporation)
NetSvcs: IKEEXT - C:\Windows\System32\ikeext.dll (Microsoft Corporation)
NetSvcs: AudioSrv - C:\Windows\System32\Audiosrv.dll (Microsoft Corporation)
NetSvcs: FastUserSwitchingCompatibility -
NetSvcs: Ias -
NetSvcs: Irmon -
NetSvcs: Nla -
NetSvcs: Ntmssvc -
NetSvcs: NWCWorkstation -
NetSvcs: Nwsapagent -
NetSvcs: Rasauto - C:\Windows\System32\rasauto.dll (Microsoft Corporation)
NetSvcs: Rasman - C:\Windows\System32\rasmans.dll (Microsoft Corporation)
NetSvcs: Remoteaccess - C:\Windows\System32\mprdim.dll (Microsoft Corporation)
NetSvcs: SENS - C:\Windows\System32\sens.dll (Microsoft Corporation)
NetSvcs: Sharedaccess - C:\Windows\System32\ipnathlp.dll (Microsoft Corporation)
NetSvcs: SRService -
NetSvcs: Tapisrv - C:\Windows\System32\tapisrv.dll (Microsoft Corporation)
NetSvcs: Wmi -
NetSvcs: WmdmPmSp -
NetSvcs: TermService - C:\Windows\System32\termsrv.dll (Microsoft Corporation)
NetSvcs: wuauserv - C:\Windows\system32\wuaueng.dll (Microsoft Corporation)
NetSvcs: BITS - C:\Windows\System32\qmgr.dll (Microsoft Corporation)
NetSvcs: ShellHWDetection - C:\Windows\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: LogonHours -
NetSvcs: PCAudit -
NetSvcs: helpsvc -
NetSvcs: uploadmgr -
NetSvcs: iphlpsvc - C:\Windows\System32\iphlpsvc.dll (Microsoft Corporation)
NetSvcs: seclogon - C:\Windows\system32\seclogon.dll (Microsoft Corporation)
NetSvcs: AppInfo - C:\Windows\System32\appinfo.dll (Microsoft Corporation)
NetSvcs: msiscsi - C:\Windows\system32\iscsiexe.dll (Microsoft Corporation)
NetSvcs: MMCSS - C:\Windows\system32\mmcss.dll (Microsoft Corporation)
NetSvcs: ProfSvc - C:\Windows\system32\profsvc.dll (Microsoft Corporation)
NetSvcs: EapHost - C:\Windows\System32\eapsvc.dll (Microsoft Corporation)
NetSvcs: winmgmt - C:\Windows\system32\wbem\WMIsvc.dll (Microsoft Corporation)
NetSvcs: schedule - C:\Windows\system32\schedsvc.dll (Microsoft Corporation)
NetSvcs: SessionEnv - C:\Windows\system32\sessenv.dll (Microsoft Corporation)
NetSvcs: browser - C:\Windows\System32\browser.dll (Microsoft Corporation)
NetSvcs: hkmsvc - C:\Windows\system32\kmsvc.dll (Microsoft Corporation)
SafeBootMin: AppInfo - (Microsoft Corporation)
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: CryptSvc - (Microsoft Corporation)
SafeBootMin: DcomLaunch - (Microsoft Corporation)
SafeBootMin: EventLog - (Microsoft Corporation)
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: KeyIso - (Microsoft Corporation)
SafeBootMin: Lavasoft Ad-Aware Service - (Lavasoft)
SafeBootMin: mcmscsvc - (McAfee, Inc.)
SafeBootMin: MCODS - (McAfee, Inc.)
SafeBootMin: Netlogon - (Microsoft Corporation)
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PlugPlay - (Microsoft Corporation)
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: ProfSvc - (Microsoft Corporation)
SafeBootMin: RpcSs - (Microsoft Corporation)
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - (Microsoft Corporation)
SafeBootMin: SWPRV - (Microsoft Corporation)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: TabletInputService - (Microsoft Corporation)
SafeBootMin: TBS - (Microsoft Corporation)
SafeBootMin: TrustedInstaller - (Microsoft Corporation)
SafeBootMin: VDS - (Microsoft Corporation)
SafeBootMin: vga.sys - (Microsoft Corporation)
SafeBootMin: vgasave.sys - (Microsoft Corporation)
SafeBootMin: volmgr.sys - (Microsoft Corporation)
SafeBootMin: volmgrx.sys - (Microsoft Corporation)
SafeBootMin: Wdf01000.sys - (Microsoft Corporation)
SafeBootMin: WinDefend - (Microsoft Corporation)
SafeBootMin: WinMgmt - (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AFD - (Microsoft Corporation)
SafeBootNet: AppInfo - (Microsoft Corporation)
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: BFE - (Microsoft Corporation)
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: bowser - (Microsoft Corporation)
SafeBootNet: Browser - (Microsoft Corporation)
SafeBootNet: CryptSvc - (Microsoft Corporation)
SafeBootNet: DcomLaunch - (Microsoft Corporation)
SafeBootNet: dfsc - (Microsoft Corporation)
SafeBootNet: Dhcp - (Microsoft Corporation)
SafeBootNet: DnsCache - (Microsoft Corporation)
SafeBootNet: Dot3Svc - (Microsoft Corporation)
SafeBootNet: Eaphost - (Microsoft Corporation)
SafeBootNet: EventLog - (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: GoToAssist - (Citrix Online, a division of Citrix Systems, Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: IKEEXT - (Microsoft Corporation)
SafeBootNet: ipnat.sys - (Microsoft Corporation)
SafeBootNet: KeyIso - (Microsoft Corporation)
SafeBootNet: LanmanServer - (Microsoft Corporation)
SafeBootNet: LanmanWorkstation - (Microsoft Corporation)
SafeBootNet: Lavasoft Ad-Aware Service - (Lavasoft)
SafeBootNet: LmHosts - (Microsoft Corporation)
SafeBootNet: mcmscsvc - (McAfee, Inc.)
SafeBootNet: MCODS - (McAfee, Inc.)
SafeBootNet: Messenger - Service
SafeBootNet: MpfService - (McAfee, Inc.)
SafeBootNet: MPSDrv - (Microsoft Corporation)
SafeBootNet: MPSSvc - (Microsoft Corporation)
SafeBootNet: mrxsmb - (Microsoft Corporation)
SafeBootNet: mrxsmb10 - (Microsoft Corporation)
SafeBootNet: mrxsmb20 - (Microsoft Corporation)
SafeBootNet: NativeWifiP - (Microsoft Corporation)
SafeBootNet: NDIS - (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: Ndisuio - (Microsoft Corporation)
SafeBootNet: NetBIOS - (Microsoft Corporation)
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetBT - (Microsoft Corporation)
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Netlogon - (Microsoft Corporation)
SafeBootNet: NetMan - (Microsoft Corporation)
SafeBootNet: netprofm - (Microsoft Corporation)
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NlaSvc - (Microsoft Corporation)
SafeBootNet: Nsi - (Microsoft Corporation)
SafeBootNet: nsiproxy.sys - (Microsoft Corporation)
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PlugPlay - (Microsoft Corporation)
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: PolicyAgent - (Microsoft Corporation)
SafeBootNet: Primary disk - Driver Group
SafeBootNet: ProfSvc - (Microsoft Corporation)
SafeBootNet: rdbss - (Microsoft Corporation)
SafeBootNet: rdpencdd.sys - (Microsoft Corporation)
SafeBootNet: rdsessmgr - Service
SafeBootNet: RpcSs - (Microsoft Corporation)
SafeBootNet: sacsvr - Service
SafeBootNet: SCardSvr - (Microsoft Corporation)
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - (Microsoft Corporation)
SafeBootNet: SharedAccess - (Microsoft Corporation)
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: SWPRV - (Microsoft Corporation)
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TabletInputService - (Microsoft Corporation)
SafeBootNet: TBS - (Microsoft Corporation)
SafeBootNet: Tcpip - (Microsoft Corporation)
SafeBootNet: TDI - Driver Group
SafeBootNet: TrustedInstaller - (Microsoft Corporation)
SafeBootNet: VDS - (Microsoft Corporation)
SafeBootNet: vga.sys - (Microsoft Corporation)
SafeBootNet: vgasave.sys - (Microsoft Corporation)
SafeBootNet: volmgr.sys - (Microsoft Corporation)
SafeBootNet: volmgrx.sys - (Microsoft Corporation)
SafeBootNet: Wdf01000.sys - (Microsoft Corporation)
SafeBootNet: WinDefend - (Microsoft Corporation)
SafeBootNet: WinMgmt - (Microsoft Corporation)
SafeBootNet: Wlansvc - (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {38539595-3E29-410d-ABBD-3D6A75BC9A73} - Reg Error: Value error.
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {AAC3F1F0-5649-4670-A698-F1523729F015} - Microsoft .NET Framework 1.1 Hotfix (KB929729)
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {DE08CE0C-6471-4D99-32F9-85E05D85DF17} - Browser Customizations
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: aux - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\system32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\Windows\system32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\system32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\system32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\system32\msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\system32\VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\system32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\system32\iyuv_32.dll (Microsoft Corporation)
Drivers32: VIDC.IYUV - C:\Windows\system32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\system32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\system32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\Windows\system32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - C:\Windows\system32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\Windows\system32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\Windows\system32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\system32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\system32\msacm32.drv (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ========== [2009/06/03 20:08:46 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Users\siegeltuch\Desktop\OTL.exe
[2009/06/03 13:57:04 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/03 13:56:35 | 00,267,612 | ---- | C] () -- C:\Users\siegeltuch\Desktop\Rooter.exe
[2009/06/03 11:18:03 | 00,001,113 | ---- | C] () -- C:\Users\siegeltuch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2009/06/03 11:18:03 | 00,000,000 | ---D | C] -- C:\Users\siegeltuch\Documents\OneNote Notebooks
[2009/06/02 21:50:37 | 00,001,876 | ---- | C] () -- C:\Users\siegeltuch\Desktop\HijackThis.lnk
[2009/06/02 21:50:37 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/06/02 21:46:43 | 00,000,218 | ---- | C] () -- C:\Users\siegeltuch\Desktop\RegistryBackup_6_2_09.reg
[2009/06/02 21:38:06 | 00,001,856 | ---- | C] () -- C:\Users\Public\Desktop\WinZip.lnk
[2009/06/02 21:37:56 | 00,000,000 | ---D | C] -- C:\Program Files\WinZip
[2009/06/02 21:12:02 | 00,056,680 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.exe
[2009/06/02 20:54:33 | 37,539,92192 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/31 13:38:19 | 00,001,659 | ---- | C] () -- C:\Users\siegeltuch\Desktop\Command Prompt.lnk
[2009/05/29 21:15:47 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/05/29 21:15:47 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2009/05/29 21:15:47 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2009/05/29 21:15:47 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2009/05/29 21:15:47 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2009/05/29 21:15:47 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/05/29 21:15:46 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/05/29 21:15:46 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2009/05/29 21:15:46 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2009/05/29 21:15:46 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2009/05/29 21:15:46 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2009/05/29 21:15:46 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2009/05/29 21:15:46 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2009/05/29 21:15:46 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2009/05/29 21:15:46 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2009/05/29 21:15:46 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/05/29 21:15:46 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2009/05/29 21:15:46 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2009/05/29 21:15:46 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2009/05/29 21:15:45 | 00,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/05/29 21:15:45 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/05/29 21:15:45 | 00,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webcheck.dll
[2009/05/29 21:15:45 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2009/05/29 21:15:45 | 00,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2009/05/29 21:15:45 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2009/05/29 21:15:45 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2009/05/29 21:15:45 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
[2009/05/29 21:15:45 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/05/29 21:15:45 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2009/05/29 21:15:45 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2009/05/29 21:15:45 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2009/05/29 21:15:45 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/05/29 21:15:44 | 00,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2009/05/29 21:15:44 | 00,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2009/05/29 21:15:44 | 00,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2009/05/29 21:15:44 | 00,391,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/05/29 21:15:44 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2009/05/29 21:15:44 | 00,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2009/05/29 21:15:43 | 03,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2009/05/29 21:15:43 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/05/29 21:15:43 | 00,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2009/05/29 21:15:43 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2009/05/29 21:15:43 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2009/05/29 21:15:43 | 00,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/05/29 21:15:43 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2009/05/29 21:15:43 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2009/05/29 21:15:43 | 00,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2009/05/29 21:15:43 | 00,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2009/05/29 21:15:43 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2009/05/29 21:15:43 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2009/05/29 21:15:42 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2009/05/29 21:15:42 | 01,206,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/05/29 21:15:42 | 00,914,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/05/29 21:15:41 | 11,063,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/05/29 21:15:41 | 05,937,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/05/11 17:14:36 | 02,452,986 | ---- | C] () -- C:\Users\siegeltuch\Desktop\158720181xxf.pdf
[2009/05/08 21:49:26 | 00,000,796 | ---- | C] () -- C:\Users\siegeltuch\Desktop\Wm7 - Shortcut.lnk
[2009/05/08 21:47:27 | 00,000,552 | ---- | C] () -- C:\Windows\WM7.INI
[2009/05/08 21:47:22 | 00,209,920 | ---- | C] () -- C:\Windows\iun3401.exe
[2009/05/08 21:47:22 | 00,000,000 | ---D | C] -- C:\Program Files\WillMaker 7
[2009/05/06 13:11:53 | 00,000,013 | ---- | C] () -- C:\Windows\System32\WinSys32.crc
[2009/05/06 13:11:52 | 00,000,792 | ---- | C] () -- C:\Users\Public\Desktop\CoffeeCup HTML Editor 2008.lnk
[2009/05/06 13:10:57 | 00,913,560 | ---- | C] (WeOnlyDo! Inc.) -- C:\Windows\System32\wodFtpDLX.ocx
[2009/05/06 13:09:41 | 00,233,472 | ---- | C] (Creative Development LTD) -- C:\Windows\System32\Ilda32.dll
[2009/05/06 13:09:40 | 00,000,000 | ---D | C] -- C:\Program Files\CoffeeCup Software
[2009/03/04 09:58:04 | 00,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/02/11 18:06:27 | 00,000,071 | ---- | C] () -- C:\Windows\updates.ini
[2008/07/27 11:04:08 | 00,148,480 | R--- | C] () -- C:\Windows\System32\OemSpiE.dll
[2008/07/27 11:04:08 | 00,000,821 | R--- | C] () -- C:\Windows\Cfg02Sp.ini
[2008/07/27 11:04:08 | 00,000,819 | R--- | C] () -- C:\Windows\Cfg03Sp.ini
[2008/07/27 11:04:08 | 00,000,730 | R--- | C] () -- C:\Windows\Cfg01Sp.ini
[2008/07/27 11:04:08 | 00,000,548 | R--- | C] () -- C:\Windows\Cfg01APR.ini
[2008/07/27 11:04:08 | 00,000,455 | R--- | C] () -- C:\Windows\Cfg02Hp.ini
[2008/07/27 11:04:08 | 00,000,455 | R--- | C] () -- C:\Windows\Cfg02DO.ini
[2008/07/27 11:04:08 | 00,000,455 | R--- | C] () -- C:\Windows\Cfg01Hp.ini
[2008/07/27 11:04:08 | 00,000,455 | R--- | C] () -- C:\Windows\Cfg01DO.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg03RMi.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg03RLI.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg03Hp.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg03FMi.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg03DO.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg03DI.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg02RMi.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg02RLI.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg02FMi.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg02DI.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg01Mic.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg01LI.ini
[2008/07/27 11:04:08 | 00,000,453 | R--- | C] () -- C:\Windows\Cfg01DI.ini
[2008/07/27 11:03:49 | 00,105,472 | ---- | C] () -- C:\Windows\System32\APOMngr.dll
[2008/07/27 11:03:49 | 00,067,072 | ---- | C] () -- C:\Windows\System32\CmdRtr.dll
[2008/07/20 21:25:46 | 00,017,408 | ---- | C] () -- C:\Windows\System32\rpcnetp.dll
[2008/07/02 14:57:02 | 00,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/07/02 12:21:36 | 00,054,784 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008/04/30 17:04:58 | 00,008,192 | ---- | C] ( ) -- C:\Windows\System32\cshost.dll
[2008/01/18 03:33:29 | 00,003,584 | ---- | C] () -- C:\Windows\System32\wceprv.dll
[2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,185 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
========== Files - Modified Within 30 Days ========== [1 C:\Windows\System32\*.tmp files]
[2009/06/03 20:09:15 | 00,056,680 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.exe
[2009/06/03 20:09:15 | 00,056,680 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.dll
[2009/06/03 20:08:47 | 00,017,991 | ---- | M] () -- C:\Windows\System32\Config.MPF
[2009/06/03 20:08:46 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Users\siegeltuch\Desktop\OTL.exe
[2009/06/03 20:08:18 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/06/03 18:17:39 | 00,055,058 | ---- | M] () -- C:\Users\siegeltuch\AppData\Roaming\nvModes.001
[2009/06/03 18:17:37 | 00,055,058 | ---- | M] () -- C:\Users\siegeltuch\AppData\Roaming\nvModes.dat
[2009/06/03 18:00:08 | 00,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.dll
[2009/06/03 17:59:58 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/03 17:59:58 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/03 17:59:57 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/06/03 17:59:49 | 37,539,92192 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/03 17:59:45 | 00,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.exe
[2009/06/03 13:56:35 | 00,267,612 | ---- | M] () -- C:\Users\siegeltuch\Desktop\Rooter.exe
[2009/06/03 11:18:03 | 00,001,113 | ---- | M] () -- C:\Users\siegeltuch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2009/06/02 21:50:37 | 00,001,876 | ---- | M] () -- C:\Users\siegeltuch\Desktop\HijackThis.lnk
[2009/06/02 21:46:43 | 00,000,218 | ---- | M] () -- C:\Users\siegeltuch\Desktop\RegistryBackup_6_2_09.reg
[2009/06/02 21:38:06 | 00,001,856 | ---- | M] () -- C:\Users\Public\Desktop\WinZip.lnk
[2009/06/01 20:14:26 | 00,000,472 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/06/01 20:14:20 | 00,015,688 | ---- | M] () -- C:\Windows\System32\lsdelete.exe
[2009/05/31 13:38:19 | 00,001,659 | ---- | M] () -- C:\Users\siegeltuch\Desktop\Command Prompt.lnk
[2009/05/31 13:38:19 | 00,000,450 | -HS- | M] () -- C:\Users\siegeltuch\Desktop\desktop.ini
[2009/05/29 21:22:11 | 00,267,248 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/05/24 17:42:36 | 00,002,487 | ---- | M] () -- C:\Users\siegeltuch\Desktop\Microsoft Office Visio 2003.lnk
[2009/05/08 21:49:26 | 00,000,796 | ---- | M] () -- C:\Users\siegeltuch\Desktop\Wm7 - Shortcut.lnk
[2009/05/08 21:47:35 | 00,000,552 | ---- | M] () -- C:\Windows\WM7.INI
[2009/05/08 21:47:22 | 00,000,185 | ---- | M] () -- C:\Windows\win.ini
[2009/05/08 21:46:54 | 00,209,920 | ---- | M] () -- C:\Windows\iun3401.exe
[2009/05/07 03:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe
[2009/05/06 13:16:39 | 00,000,013 | ---- | M] () -- C:\Windows\System32\WinSys32.crc
[2009/05/06 13:11:52 | 00,000,792 | ---- | M] () -- C:\Users\Public\Desktop\CoffeeCup HTML Editor 2008.lnk
========== LOP Check ========== [2009/03/11 15:06:08 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming
[2008/07/14 20:23:41 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Absolute
[2008/08/03 17:25:41 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Adobe
[2008/08/03 17:25:28 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Adobe Systems Incorporated
[2008/07/09 17:22:17 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Creative
[2008/07/10 11:27:15 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Google
[2008/07/09 17:13:04 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Identities
[2008/07/10 11:35:07 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Macromedia
[2006/11/02 08:37:34 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Media Center Programs
[2009/06/03 11:18:04 | 00,000,000 | --SD | M] -- C:\Users\siegeltuch\AppData\Roaming\Microsoft
[2008/07/10 12:49:58 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Mozilla
[2009/03/11 15:06:08 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\MusicNet
[2009/02/20 15:51:41 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Real
[2009/06/03 19:30:14 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\Skype
[2009/06/03 18:17:41 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\skypePM
[2009/02/21 18:34:20 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\TomTom
[2009/01/29 09:52:30 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\U3
[2008/07/10 11:45:30 | 00,000,000 | ---D | M] -- C:\Users\siegeltuch\AppData\Roaming\WinRAR
[2009/06/01 20:14:26 | 00,000,472 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2008/07/02 12:41:55 | 00,000,356 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2008/07/02 12:41:55 | 00,000,348 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2009/06/03 17:59:57 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/06/03 14:02:02 | 00,032,606 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < %systemroot%\System32\antiwpa.dll > < %systemroot%\SYSTEM32\wpa.dll > < %systemroot%\setup\scripts\biestart.exe > < %systemroot%\system32\drivers\royal.sys > < %SYSTEMDRIVE%\*. >[2009/06/03 20:14:56 | 00,000,000 | R--D | M] -- C:
[2008/07/09 17:13:30 | 00,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2008/02/03 19:06:57 | 00,000,000 | -HSD | M] -- C:\Boot
[2008/07/14 20:15:28 | 00,000,000 | ---D | M] -- C:\DELL
[2008/07/02 14:51:07 | 00,000,000 | ---D | M] -- C:\doctemp
[2008/07/02 12:20:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings
[2008/07/02 14:51:05 | 00,000,000 | ---D | M] -- C:\Drivers
[2008/07/02 12:22:26 | 00,000,000 | RH-D | M] -- C:\MSOCache
[2008/01/20 22:32:31 | 00,000,000 | ---D | M] -- C:\PerfLogs
[2009/06/02 21:50:37 | 00,000,000 | R--D | M] -- C:\Program Files
[2009/06/03 13:31:45 | 00,000,000 | -H-D | M] -- C:\ProgramData
[2009/02/13 13:35:13 | 00,000,000 | ---D | M] -- C:\RoboHelp7Data
[2009/06/03 13:57:15 | 00,000,000 | ---D | M] -- C:\Rooter$
[2009/06/03 12:47:35 | 00,000,000 | -HSD | M] -- C:\System Volume Information
[2008/07/14 20:25:24 | 00,000,000 | ---D | M] -- C:\Temp
[2008/07/09 17:12:28 | 00,000,000 | R--D | M] -- C:\Users
[2009/06/03 18:00:13 | 00,000,000 | ---D | M] -- C:\Windows
< %SYSTEMDRIVE%\*.* >[2009/06/03 17:59:46 | 00,023,918 | ---- | M] () -- C:\aaw7boot.log
[2006/09/18 17:43:36 | 00,000,024 | ---- | M] () -- C:\autoexec.bat
[2008/01/20 22:24:42 | 00,333,203 | RHS- | M] () -- C:\bootmgr
[2006/09/18 17:43:37 | 00,000,010 | ---- | M] () -- C:\config.sys
[2008/07/02 14:57:14 | 00,005,533 | RH-- | M] () -- C:\dell.sdr
[2009/06/03 17:59:49 | 37,539,92192 | -HS- | M] () -- C:\hiberfil.sys
[2008/07/02 12:21:33 | 00,026,927 | ---- | M] () -- C:\newfile.enc
[2008/07/02 12:21:33 | 00,026,927 | ---- | M] () -- C:\newkey
[2009/06/03 17:59:47 | 40,696,50432 | -HS- | M] () -- C:\pagefile.sys
[2009/06/03 13:57:15 | 00,005,215 | ---- | M] () -- C:\Rooter.txt
[2008/07/02 12:21:31 | 00,002,090 | ---- | M] () -- C:\SetWiFiBT.txt
[2008/07/02 12:39:04 | 00,000,071 | ---- | M] () -- C:\SystemInfo.ini
< %PROGRAMFILES%\*. >[2009/06/02 21:50:37 | 00,000,000 | R--D | M] -- C:\Program Files
[2008/07/10 12:57:21 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
[2008/07/02 12:38:01 | 00,000,000 | ---D | M] -- C:\Program Files\AOL Install
[2009/02/09 18:25:58 | 00,000,000 | ---D | M] -- C:\Program Files\Audacity
[2008/11/22 15:51:05 | 00,000,000 | ---D | M] -- C:\Program Files\BIAS
[2009/03/02 20:19:03 | 00,000,000 | ---D | M] -- C:\Program Files\Boson Software
[2008/07/02 12:19:31 | 00,000,000 | ---D | M] -- C:\Program Files\Broadcom
[2008/07/02 12:21:50 | 00,000,000 | ---D | M] -- C:\Program Files\Cisco
[2009/02/17 14:16:44 | 00,000,000 | ---D | M] -- C:\Program Files\Cisco Press
[2008/07/02 12:34:55 | 00,000,000 | ---D | M] -- C:\Program Files\Citrix
[2009/05/06 13:16:42 | 00,000,000 | ---D | M] -- C:\Program Files\CoffeeCup Software
[2009/03/30 20:01:44 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files
[2008/07/02 07:02:19 | 00,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2008/07/27 11:32:58 | 00,000,000 | ---D | M] -- C:\Program Files\Creative
[2008/07/02 12:20:08 | 00,000,000 | ---D | M] -- C:\Program Files\Creative Live! Cam
[2008/07/02 12:31:19 | 00,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2008/07/02 12:40:23 | 00,000,000 | ---D | M] -- C:\Program Files\Dell
[2008/07/02 12:27:10 | 00,000,000 | ---D | M] -- C:\Program Files\Dell DataSafe Online
[2008/07/02 12:29:56 | 00,000,000 | ---D | M] -- C:\Program Files\Dell Support Center
[2008/07/02 14:56:58 | 00,000,000 | ---D | M] -- C:\Program Files\DellTPad
[2008/07/02 12:19:26 | 00,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
[2008/07/02 12:39:03 | 00,000,000 | ---D | M] -- C:\Program Files\EarthLink Setup
[2008/07/14 20:15:28 | 00,000,000 | ---D | M] -- C:\Program Files\Google
[2009/03/21 18:28:16 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/06/01 13:29:46 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2008/07/02 12:13:45 | 00,000,000 | ---D | M] -- C:\Program Files\Java
[2009/03/30 20:01:57 | 00,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2008/07/14 20:31:45 | 00,000,000 | ---D | M] -- C:\Program Files\LFLInstall
[2009/04/18 16:52:08 | 00,000,000 | ---D | M] -- C:\Program Files\McAfee
[2008/07/02 12:28:08 | 00,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2006/11/02 08:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2009/03/04 09:56:44 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009/05/29 21:17:48 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2008/07/02 12:24:12 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2008/07/02 12:18:35 | 00,000,000 | ---D | M] -- C:\Program Files\Modem Diagnostic Tool
[2008/01/20 22:35:17 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009/05/06 13:13:18 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2006/11/02 08:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2008/07/20 20:26:26 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2008/07/02 12:18:59 | 00,000,000 | ---D | M] -- C:\Program Files\NetWaiting
[2008/07/02 12:22:04 | 00,000,000 | ---D | M] -- C:\Program Files\NetZeroInstallers
[2009/02/20 15:42:43 | 00,000,000 | ---D | M] -- C:\Program Files\Real
[2006/11/02 08:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2008/07/02 12:34:39 | 00,000,000 | ---D | M] -- C:\Program Files\Roxio
[2008/07/02 07:02:06 | 00,000,000 | ---D | M] -- C:\Program Files\Sigmatel
[2008/08/03 16:18:43 | 00,000,000 | ---D | M] -- C:\Program Files\Skype
[2008/07/27 16:34:04 | 00,000,000 | ---D | M] -- C:\Program Files\TechSmith
[2009/02/21 18:20:07 | 00,000,000 | ---D | M] -- C:\Program Files\TomTom DesktopSuite
[2009/06/02 21:50:37 | 00,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2006/11/02 09:01:55 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/05/08 21:47:22 | 00,000,000 | ---D | M] -- C:\Program Files\WillMaker 7
[2008/01/20 22:35:18 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Calendar
[2008/01/20 22:35:15 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Collaboration
[2008/01/20 22:35:09 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2008/01/20 22:35:14 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Journal
[2009/05/14 10:21:59 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2009/03/12 10:12:31 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2006/11/02 08:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2008/01/20 22:35:14 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Photo Gallery
[2008/01/20 22:35:17 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar
[2008/07/10 11:45:13 | 00,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2009/06/02 21:37:57 | 00,000,000 | ---D | M] -- C:\Program Files\WinZip
[2008/07/02 12:25:57 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2009/01/20 15:06:33 | 00,000,000 | -H-D | M] -- C:\Program Files\Zero G Registry
< End of report >
Thanks for keeping an eye on this. Second file to follow.