Hi!
Downloaded COMODO and Avira AntVir, updated to SP3 and then ran HJT. Herewith the log for HJT:
##########################################################
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:38:05 PM, on 2009/10/10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\BtUsrBdg.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.za/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [BTUSRBDG] BtUsrBdg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone:
http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone:
http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone:
http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone:
http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone:
http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone:
http://www.mcafeeasap.com (HKLM)
O16 - DPF: RaptisoftGameLoader -
http://www.miniclip.com/hamsterball/raptisoftgameloader.cabO16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius.com/download/software/...tiveXPlugin.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{F4EEC7DC-3402-4F75-83AC-43EA187F7BD4}: NameServer = 196.43.34.190,196.43.46.190
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\Player\__CDS2.dll (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EngineServer - Unknown owner - C:\Program Files\McAfee\Managed VirusScan\VScan\EngineServer.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McShield - Unknown owner - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe (file missing)
--
End of file - 8236 bytes
####################################################
Many thanks!
######################################################
Then ran OTL, and herewith the logs:
##########################
OTL.Txt
###########################
OTL logfile created on: 2009/10/10 10:46:14 PM - Run 2
OTL by OldTimer - Version 3.0.19.0 Folder = C:\Documents and Settings\Annalie\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00001C09 | Country: South Africa | Language: ENS | Date Format: yyyy/MM/dd
511.48 Mb Total Physical Memory | 231.93 Mb Available Physical Memory | 45.34% Memory free
1.22 Gb Paging File | 0.88 Gb Available in Paging File | 71.85% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.68 Gb Total Space | 29.31 Gb Free Space | 38.22% Space Free | Partition Type: NTFS
Drive D: | 200.94 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-STUDY
Current User Name: Annalie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Annalie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe (Nokia Corporation)
PRC - C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)
PRC - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe (Microsoft Corporation)
PRC - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\WINDOWS\System32\BtUsrBdg.exe (Extended Systems, Inc.)
========== Win32 Services (SafeList) ========== SRV - (AntiVirSchedulerService [Auto | Running]) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService [Auto | Running]) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe ()
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (btwdins [Auto | Running]) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cmdAgent [Auto | Running]) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (EngineServer [Auto | Stopped]) -- File not found
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (McShield [On_Demand | Stopped]) -- File not found
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (ALCXSENS [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (avgio [System | Running]) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (avgntflt [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\avgntflt.sys (Avira GmbH)
DRV - (avipbb [System | Running]) -- C:\WINDOWS\System32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (basic2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys (Conexant)
DRV - (BsStor [Boot | Running]) -- C:\WINDOWS\System32\drivers\BsStor.sys (B.H.A Co.,Ltd.)
DRV - (BtAudio [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btaudio.sys (Broadcom Corporation.)
DRV - (BTCOMM [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\Btcomm.sys (Extended Systems Inc.)
DRV - (BTDriver [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNBDG [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btkrnbdg.sys (Extended Systems, Inc.)
DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\btwhid.sys (Broadcom Corporation.)
DRV - (cdrbsvsd [System | Running]) -- C:\WINDOWS\System32\drivers\cdrbsvsd.sys (B.H.A Corporation)
DRV - (cmdGuard [System | Running]) -- C:\WINDOWS\System32\DRIVERS\cmdguard.sys (COMODO)
DRV - (cmdHlp [System | Running]) -- C:\WINDOWS\System32\DRIVERS\cmdhlp.sys (COMODO)
DRV - (EIO [Auto | Running]) -- C:\WINDOWS\System32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (Fallback [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys (Conexant)
DRV - (Fsks [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys (Conexant)
DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys (Conexant Systems, Inc.)
DRV - (hsf_msft [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys (Conexant)
DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys (Conexant Systems, Inc.)
DRV - (Inspect [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (K56 [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys (Conexant)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MASPINT [Auto | Running]) -- C:\WINDOWS\System32\drivers\MASPINT.SYS (MicroStaff Co.,Ltd.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MfeAVFK [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\MfeAVFK.sys (McAfee, Inc.)
DRV - (MfeBOPK [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\MfeBOPK.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\WINDOWS\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (MfeRKDK [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\MfeRKDK.sys (McAfee, Inc.)
DRV - (mfetdik [System | Running]) -- C:\WINDOWS\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (Ndisusb [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\genelan.sys (Genesys Logic)
DRV - (nv_agp [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (nvatabus [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (NVENET [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\NVENET.sys (NVIDIA Corporation)
DRV - (NwlnkIpx [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Rksample [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys (Conexant)
DRV - (ROOTMODEM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (sdcplh [System | Running]) -- C:\WINDOWS\System32\drivers\sdcplh.sys (Macrovision Europe Ltd)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys ()
DRV - (sisidex [Boot | Running]) -- C:\WINDOWS\system32\drivers\sisidex.sys (Windows ® 2000 DDK provider)
DRV - (sisperf [Boot | Running]) -- C:\WINDOWS\system32\drivers\sisperf.sys (Silicon Integrated Systems Corp.)
DRV - (SoftFax [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys (Conexant)
DRV - (sonypvs1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sonypvs1.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (ssmdrv [System | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (Tones [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys (Conexant)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (V124 [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_V124.sys (Conexant)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFCXTS2.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=homeIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.za/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/02/12 10:56:58 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/21 12:34:46 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/09 16:01:34 | 00,000,000 | ---D | M]
[2008/09/06 10:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\mozilla\Extensions
[2008/09/06 10:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/02/13 12:48:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\mozilla\Firefox\Profiles\k8wjhlrg.default\extensions
[2009/10/10 11:34:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/13 12:24:36 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/04/08 13:37:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/18 21:19:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/02/12 10:57:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/30 11:49:26 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/09/13 12:24:26 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/13 12:24:26 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/09/13 12:24:32 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2008/04/01 09:57:41 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2008/04/01 09:57:41 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2008/04/01 09:57:41 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2007/12/29 13:55:51 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2008/04/01 09:57:41 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2008/04/01 09:57:41 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/19 16:57:43 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/06/19 16:57:43 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/19 16:57:43 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/06/19 16:57:43 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/19 16:57:43 | 00,000,759 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2009/06/19 16:57:43 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/19 16:57:43 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/19 16:57:43 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: (326171 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 11162 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BTUSRBDG] C:\WINDOWS\System32\BtUsrBdg.exe (Extended Systems, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)
O4 - HKLM..\Run: [gcasServ] C:\Program Files\Microsoft AntiSpyware\gcasServ.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries 0000000004 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries 0000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries 0000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //FWEvent.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 61 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: rmbprivatebank.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 59 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71}
http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/...tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: RaptisoftGameLoader
http://www.miniclip.com/hamsterball/raptisoftgameloader.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\httpx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\httpsx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ippx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaippx00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {9EF34FF2-3396-4527-9D27-04C8C1C67806} - C:\Program Files\Microsoft AntiSpyware\shellextension.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/30 19:05:31 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1997/01/29 16:35:22 | 00,026,624 | R--- | M] () - D:\AUTOSET.EXE -- [ CDFS ]
O32 - AutoRun File - [1997/11/12 03:10:00 | 00,150,016 | R--- | M] (Indigo Rose Corporation) - D:\automenu.exe -- [ CDFS ]
O32 - AutoRun File - [1998/07/20 17:06:54 | 00,002,789 | R--- | M] () - D:\automenu.ini -- [ CDFS ]
O32 - AutoRun File - [1998/07/20 17:00:46 | 00,000,049 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} - Security Update for Microsoft .NET Framework 2.0 (KB922770)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4b218e3e-bc98-4770-93d3-2731b9329278} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
ActiveX: {4d64f3ba-f112-4efe-a02e-96680859937c} - KB918899
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5b7bf89d-d196-4c32-a303-a57b8ab7f18d} - KB918439
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {967B098A-042D-4367-BAC9-8BC11684174F} - Security Update for Microsoft .NET Framework 2.0 (KB917283)
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player 9 ActiveX
ActiveX: {dd772a76-bef3-44d7-8b39-502c8504c1f1} - KB925486
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {f15ee071-deb7-4cbb-951f-431c98338d8e} - KB911567
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\INF\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: VIDC.IV41 - C:\WINDOWS\System32\IR41_32.AX (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ========== [1 C:\WINDOWS\*.tmp files]
[2009/09/21 23:06:44 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/10/10 22:24:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2009/10/09 18:43:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Comodo
[2009/09/23 23:25:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/09/17 08:09:17 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2009/10/10 22:24:30 | 00,000,000 | ---D | C] -- C:\Program Files\Avira
[2009/10/09 18:43:17 | 00,000,000 | ---D | C] -- C:\Program Files\COMODO
[2009/09/20 22:33:36 | 00,000,000 | ---D | C] -- C:\Program Files\erunt
[2009/09/26 00:20:26 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/09/17 08:10:08 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2009/09/20 20:43:57 | 00,000,000 | ---D | C] -- C:\Program Files\SysRestorePoint
[2009/09/21 23:13:18 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/10/10 22:24:36 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/10/10 22:24:36 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/10/10 22:24:36 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/10/10 22:24:36 | 00,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/10/10 22:24:36 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/10/10 11:36:58 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/10/09 18:43:20 | 00,179,792 | ---- | C] (COMODO) -- C:\WINDOWS\System32\guard32.dll
[2009/10/09 18:43:20 | 00,132,296 | ---- | C] (COMODO) -- C:\WINDOWS\System32\drivers\cmdguard.sys
[2009/10/09 18:43:20 | 00,087,104 | ---- | C] (COMODO) -- C:\WINDOWS\System32\drivers\inspect.sys
[2009/10/09 18:43:20 | 00,025,160 | ---- | C] (COMODO) -- C:\WINDOWS\System32\drivers\cmdhlp.sys
[2009/10/09 14:28:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/10/09 12:29:40 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpns.dll
[2009/10/09 12:27:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\peernet
[2009/10/09 12:27:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\provisioning
[2009/10/09 12:25:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2009/10/09 12:21:06 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2009/10/09 12:21:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2009/10/09 10:43:32 | 40,519,952 | ---- | C] (COMODO) -- C:\Program Files\CIS_Setup_3.12.111745.560_XP_Vista_x32.exe
[2009/10/09 07:05:27 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/10/07 18:53:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/10/07 18:45:41 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xmlprov.dll
[2009/10/07 18:45:41 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
[2009/10/07 18:44:34 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/10/07 18:44:34 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/10/07 18:44:34 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/10/07 18:44:34 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/09/30 18:36:33 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/09/30 18:33:25 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/09/26 00:20:28 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/26 00:20:26 | 00,018,520 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/26 00:16:14 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Annalie\Desktop\mbam-setup.exe
[2009/09/26 00:10:58 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Annalie\Desktop\TFC.exe
[2009/09/26 00:04:02 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/09/25 18:06:38 | 00,520,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Annalie\Desktop\OTL.exe
[2009/09/25 10:46:47 | 00,000,000 | ---D | C] -- C:\_OTM
[2009/09/25 10:45:17 | 00,408,064 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Annalie\Desktop\OTM.exe
[2009/09/24 22:52:23 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/09/21 23:26:39 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/09/21 23:12:27 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Program Files\HJTInstall.exe
[2009/09/20 22:37:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/09/03 22:24:26 | 04,958,032 | ---- | C] (Perfect Software LLC) -- C:\Documents and Settings\Annalie\Application Data\pdinstall.exe
========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\*.tmp files]
[2009/10/10 22:42:02 | 00,520,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Annalie\Desktop\OTL.exe
[2009/10/10 22:25:02 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/10/10 22:25:02 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/10/10 22:24:55 | 00,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/10/10 22:16:17 | 00,002,497 | ---- | M] () -- C:\Documents and Settings\Annalie\Desktop\Word.lnk
[2009/10/10 22:06:29 | 00,086,168 | ---- | M] () -- C:\Documents and Settings\Annalie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/10 11:20:35 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/10 11:20:32 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/09 18:46:48 | 00,000,808 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\COMODO Internet Security.lnk
[2009/10/09 18:43:16 | 00,179,792 | ---- | M] (COMODO) -- C:\WINDOWS\System32\guard32.dll
[2009/10/09 18:43:16 | 00,132,296 | ---- | M] (COMODO) -- C:\WINDOWS\System32\drivers\cmdguard.sys
[2009/10/09 18:43:16 | 00,087,104 | ---- | M] (COMODO) -- C:\WINDOWS\System32\drivers\inspect.sys
[2009/10/09 18:43:16 | 00,025,160 | ---- | M] (COMODO) -- C:\WINDOWS\System32\drivers\cmdhlp.sys
[2009/10/09 16:43:07 | 00,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/09 16:02:47 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/10/09 16:01:39 | 00,001,686 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/10/09 15:51:58 | 00,013,740 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/09 14:32:44 | 00,474,832 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/09 14:32:44 | 00,403,836 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/10/09 14:32:44 | 00,063,246 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/10/09 14:29:49 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009/10/09 12:29:41 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/10/09 12:23:34 | 00,250,032 | RHS- | M] () -- C:\ntldr
[2009/10/09 12:23:34 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/10/09 12:07:43 | 33,961,728 | ---- | M] () -- C:\Program Files\avira_antivir_personal_en.exe
[2009/10/09 11:01:40 | 40,519,952 | ---- | M] (COMODO) -- C:\Program Files\CIS_Setup_3.12.111745.560_XP_Vista_x32.exe
[2009/10/08 12:39:05 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/10/08 09:10:15 | 00,608,344 | ---- | M] () -- C:\Documents and Settings\Annalie\Desktop\MCPR.exe
[2009/10/07 18:51:10 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/10/07 18:43:41 | 03,327,820 | R--- | M] () -- C:\Documents and Settings\Annalie\Desktop\Combo-Fix.exe
[2009/09/30 22:57:14 | 00,408,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Annalie\Desktop\OTM.exe
[2009/09/30 09:43:55 | 00,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2009/09/29 10:57:05 | 00,037,888 | ---- | M] () -- C:\Documents and Settings\Annalie\My Documents\Salary Slip - Philipina and George and Thembile 2008.doc
[2009/09/28 00:38:07 | 00,002,119 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5at.gif
[2009/09/28 00:38:07 | 00,000,607 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5zn.gif
[2009/09/28 00:38:07 | 00,000,598 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5by.gif
[2009/09/26 00:20:31 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/26 00:18:11 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Annalie\Desktop\mbam-setup.exe
[2009/09/26 00:09:02 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Annalie\Desktop\TFC.exe
[2009/09/24 22:58:31 | 00,440,832 | ---- | M] () -- C:\Documents and Settings\Annalie\Desktop\CKScanner.exe
[2009/09/22 22:37:49 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Annalie\Desktop\HijackThis.lnk
[2009/09/21 23:13:09 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\HJTInstall.exe
[2009/09/21 23:06:42 | 00,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/09/20 22:33:01 | 00,513,320 | ---- | M] () -- C:\Program Files\erunt.zip
[2009/09/18 17:11:33 | 21,031,280 | ---- | M] () -- C:\Documents and Settings\Annalie\Desktop\aaw2007.exe
[2009/09/17 08:35:21 | 02,201,600 | ---- | M] () -- C:\Documents and Settings\Annalie\My Documents\Katys Photo competition.ppt
[2009/09/14 02:12:36 | 00,229,888 | ---- | M] () -- C:\WINDOWS\PEV.exe
========== Files - No Company Name ==========[2009/10/10 22:24:55 | 00,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/10/09 18:46:48 | 00,000,808 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\COMODO Internet Security.lnk
[2009/10/09 11:50:21 | 33,961,728 | ---- | C] () -- C:\Program Files\avira_antivir_personal_en.exe
[2009/10/08 09:10:10 | 00,608,344 | ---- | C] () -- C:\Documents and Settings\Annalie\Desktop\MCPR.exe
[2009/10/07 18:44:34 | 00,229,888 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/10/07 18:44:34 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/10/07 18:44:34 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/10/07 18:44:34 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/10/07 18:42:13 | 03,327,820 | R--- | C] () -- C:\Documents and Settings\Annalie\Desktop\Combo-Fix.exe
[2009/09/30 18:36:37 | 00,000,194 | ---- | C] () -- C:\Boot.bak
[2009/09/30 18:36:34 | 00,245,920 | ---- | C] () -- C:\cmldr
[2009/09/28 00:38:07 | 00,002,119 | ---- | C] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5at.gif
[2009/09/28 00:38:07 | 00,000,607 | ---- | C] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5zn.gif
[2009/09/28 00:38:07 | 00,000,598 | ---- | C] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5by.gif
[2009/09/26 00:20:31 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/24 22:58:42 | 00,440,832 | ---- | C] () -- C:\Documents and Settings\Annalie\Desktop\CKScanner.exe
[2009/09/21 23:13:18 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Annalie\Desktop\HijackThis.lnk
[2009/09/21 23:06:42 | 00,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/09/20 22:32:58 | 00,513,320 | ---- | C] () -- C:\Program Files\erunt.zip
[2009/09/17 08:35:21 | 02,201,600 | ---- | C] () -- C:\Documents and Settings\Annalie\My Documents\Katys Photo competition.ppt
[2008/09/26 09:15:24 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/25 11:53:41 | 00,038,434 | ---- | C] () -- C:\Documents and Settings\Annalie\Application Data\Comma Separated Values (Windows).ADR
[2008/09/25 11:47:09 | 00,038,432 | ---- | C] () -- C:\Documents and Settings\Annalie\Application Data\Tab Separated Values (Windows).ADR
[2008/02/09 18:44:33 | 00,000,173 | ---- | C] () -- C:\WINDOWS\SOFTPEG.INI
[2007/12/29 13:56:13 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2007/12/29 13:56:13 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2007/07/14 16:18:25 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Gamchest.INI
[2007/04/01 09:00:28 | 02,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007/04/01 08:41:52 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2006/06/17 14:36:41 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2006/06/17 10:06:12 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/06/16 19:12:00 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\ESICOMMN.dll
[2006/01/10 19:33:17 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2006/01/05 22:46:40 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2005/08/19 18:45:22 | 00,000,419 | ---- | C] () -- C:\WINDOWS\PCPHOTO.INI
[2005/02/17 12:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004/12/24 15:26:45 | 00,030,208 | ---- | C] () -- C:\WINDOWS\System32\WNASPI32.DLL
[2004/12/24 15:26:45 | 00,000,291 | ---- | C] () -- C:\WINDOWS\msfsetup.ini
[2004/09/01 19:28:13 | 00,086,168 | ---- | C] () -- C:\Documents and Settings\Annalie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2004/09/01 10:13:28 | 00,000,172 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2004/09/01 09:55:31 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\Annalie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/08/30 20:51:32 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/30 20:50:18 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/08/30 20:35:31 | 00,338,944 | ---- | C] () -- C:\WINDOWS\System32\Lffpx7.dll
[2004/08/30 20:35:31 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
[2004/08/30 20:33:12 | 00,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2004/08/30 20:14:40 | 00,001,589 | ---- | C] () -- C:\WINDOWS\System32\drivers\glexport.sys
[2004/08/30 20:01:02 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2004/08/30 20:01:01 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2004/08/30 19:56:20 | 01,108,964 | -H-- | C] () -- C:\Documents and Settings\Annalie\Local Settings\Application Data\IconCache.db
[2004/08/30 19:55:57 | 00,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2004/08/30 19:16:36 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Annalie\Application Data\desktop.ini
[2004/08/04 09:56:42 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2003/12/02 15:55:14 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2003/03/31 14:00:00 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003/03/31 14:00:00 | 00,001,686 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/03/31 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 13:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1997/06/14 02:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ========== [2009/10/10 22:24:30 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/09/04 12:09:23 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/09/21 23:06:55 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2006/01/24 07:47:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2006/06/17 14:32:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Buena Vista Games
[2005/02/08 17:20:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2004/09/02 15:44:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2009/10/09 15:52:22 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Annalie\Application Data
[2009/07/02 19:08:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Ahead
[2005/01/27 08:19:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Cyberlink
[2007/11/07 15:25:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Datalayer
[2004/08/30 20:36:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\InterTrust
[2007/01/11 10:41:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\MSN6
[2008/05/02 18:15:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\NetMedia Providers
[2007/11/05 20:03:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Nokia
[2007/06/05 08:31:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Nokia Multimedia Player
[2006/06/16 18:43:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\PC Suite
[2008/05/02 18:15:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Publish Providers
[2005/08/14 18:21:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Raptisoft
[2007/07/21 12:57:25 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Annalie\Application Data\SecuROM
[2009/03/02 09:00:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Sibelius Software
[2008/05/02 18:15:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Sony
[2009/08/10 14:04:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\U3
[2009/09/08 12:10:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\Uniblue
[2006/06/16 19:31:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Annalie\Application Data\XTND_BTUIObjects
[2003/03/31 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/10 11:20:35 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== ========== Custom Scans ========== < %systemroot%\System32\antiwpa.dll > < %systemroot%\SYSTEM32\wpa.dll > < %systemroot%\setup\scripts\biestart.exe > < %systemroot%\system32\drivers\royal.sys > < %systemroot%\system32\oobe\AntiWPA_Crypt.dll > < %TEMP%\antiwpa_crypt.dll > < %TEMP%\antiwpa.dll /s > < %PROGRAMFILES%\antiwpa.dll /s > < %systemroot%\system32\crypt.dll > < %TEMP%\crypt.dll > < %SYSTEMDRIVE%\*. >[2009/10/10 22:42:02 | 00,000,000 | ---D | M] -- C:
[2009/09/26 00:04:02 | 00,000,000 | ---D | M] -- C:\_OTL
[2009/09/25 10:46:47 | 00,000,000 | ---D | M] -- C:\_OTM
[2008/01/18 17:14:50 | 00,000,000 | ---D | M] -- C:\btinbox
[2009/09/30 18:36:37 | 00,000,000 | RHSD | M] -- C:\cmdcons
[2009/07/05 22:07:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings
[2006/05/01 10:09:56 | 00,000,000 | ---D | M] -- C:\Drivers
[2004/08/30 20:46:53 | 00,000,000 | R--D | M] -- C:\MSOCache
[2006/05/01 10:45:18 | 00,000,000 | ---D | M] -- C:\MWASPI
[2009/07/15 19:48:59 | 00,000,000 | ---D | M] -- C:\NVIDIA
[2005/08/19 09:04:47 | 00,000,000 | ---D | M] -- C:\ppwork
[2009/10/10 22:24:30 | 00,000,000 | R--D | M] -- C:\Program Files
[2009/10/07 18:53:48 | 00,000,000 | ---D | M] -- C:\Qoobox
[2009/10/09 07:05:27 | 00,000,000 | -HSD | M] -- C:\RECYCLER
[2009/09/24 22:52:23 | 00,000,000 | ---D | M] -- C:\Rooter$
[2009/10/09 14:28:22 | 00,000,000 | -HSD | M] -- C:\System Volume Information
[2009/10/10 22:25:02 | 00,000,000 | ---D | M] -- C:\WINDOWS
< %SYSTEMDRIVE%\*.* >[2007/10/14 19:21:08 | 00,000,000 | ---- | M] () -- C:\AILog.txt
[2004/08/30 19:05:31 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/09/07 11:28:39 | 00,002,418 | ---- | M] () -- C:\avenger.txt
[2007/06/06 12:46:48 | 00,000,192 | ---- | M] () -- C:\BcBtRmv.log
[2004/08/30 18:59:13 | 00,000,194 | ---- | M] () -- C:\Boot.bak
[2009/10/09 12:29:41 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2003/08/14 06:27:02 | 00,000,509 | ---- | M] () -- C:\BsCLiP.iss
[2004/08/30 20:35:51 | 00,000,032 | ---- | M] () -- C:\BsGold.log
[2002/08/29 01:05:52 | 00,245,920 | ---- | M] () -- C:\cmldr
[2009/10/07 18:53:45 | 00,010,620 | ---- | M] () -- C:\ComboFix.txt
[2004/08/30 19:05:31 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/07/13 21:20:24 | 00,000,166 | ---- | M] () -- C:\INSTALL.LOG
[2004/08/30 19:05:31 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2006/04/27 10:59:18 | 00,000,172 | -H-- | M] () -- C:\IPH.PH
[2004/08/30 19:05:31 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/10/09 12:23:34 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/10/09 12:23:34 | 00,250,032 | RHS- | M] () -- C:\ntldr
[2009/10/10 11:20:29 | 80,530,6368 | -HS- | M] () -- C:\pagefile.sys
< %PROGRAMFILES%\*. >[2009/10/10 22:24:30 | 00,000,000 | R--D | M] -- C:\Program Files
[2008/06/26 11:34:53 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
[2008/09/25 17:34:12 | 00,000,000 | ---D | M] -- C:\Program Files\Ahead
[2004/08/30 20:41:27 | 00,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2009/10/10 22:24:30 | 00,000,000 | ---D | M] -- C:\Program Files\Avira
[2004/08/30 20:01:04 | 00,000,000 | ---D | M] -- C:\Program Files\AvRack
[2005/12/17 15:15:37 | 00,000,000 | ---D | M] -- C:\Program Files\B's Recorder GOLD7
[2006/06/17 14:32:33 | 00,000,000 | ---D | M] -- C:\Program Files\Buena Vista Games
[2009/04/22 12:14:54 | 00,000,000 | ---D | M] -- C:\Program Files\Bullfrog
[2006/01/28 19:02:40 | 00,000,000 | ---D | M] -- C:\Program Files\Code 27
[2009/10/07 18:48:53 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/10/09 18:43:17 | 00,000,000 | ---D | M] -- C:\Program Files\COMODO
[2004/08/30 19:02:35 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2004/08/30 20:33:21 | 00,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2005/02/08 17:20:59 | 00,000,000 | ---D | M] -- C:\Program Files\CyberLink DVD Solution
[2007/04/27 15:54:14 | 00,000,000 | ---D | M] -- C:\Program Files\EA GAMES
[2007/10/14 14:13:02 | 00,000,000 | ---D | M] -- C:\Program Files\EA SPORTS
[2007/07/14 16:21:09 | 00,000,000 | ---D | M] -- C:\Program Files\eGames
[2007/07/21 12:52:44 | 00,000,000 | ---D | M] -- C:\Program Files\Electronic Arts
[2009/09/20 22:33:36 | 00,000,000 | ---D | M] -- C:\Program Files\erunt
[2008/03/03 12:59:01 | 00,000,000 | ---D | M] -- C:\Program Files\Experimental uninstall Sibelius Software
[2006/06/16 19:27:35 | 00,000,000 | ---D | M] -- C:\Program Files\Extended Systems
[2006/06/24 11:48:55 | 00,000,000 | ---D | M] -- C:\Program Files\Google
[2007/12/29 13:44:19 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/10/09 12:27:39 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/03/30 11:49:24 | 00,000,000 | ---D | M] -- C:\Program Files\Java
[2009/09/24 22:58:16 | 00,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/01/15 20:44:23 | 00,000,000 | ---D | M] -- C:\Program Files\LucasArts
[2009/09/27 19:45:24 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2006/01/08 12:20:14 | 00,000,000 | ---D | M] -- C:\Program Files\Maxis
[2009/10/09 18:41:43 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/09/17 08:10:08 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2009/10/01 10:36:39 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft AntiSpyware
[2004/08/30 19:05:40 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2007/10/14 16:19:27 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2009/09/23 12:53:14 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Home Publishing 2000
[2004/08/30 20:49:33 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2004/08/30 20:49:49 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2009/10/09 18:41:43 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009/10/10 22:20:11 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2005/12/17 23:02:47 | 00,000,000 | ---D | M] -- C:\Program Files\MSI
[2004/08/30 19:02:07 | 00,000,000 | ---D | M] -- C:\Program Files\MSN
[2004/08/30 19:01:55 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/08/06 12:26:00 | 00,000,000 | ---D | M] -- C:\Program Files\Neopsalmist
[2009/10/09 12:25:35 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2006/06/16 18:43:26 | 00,000,000 | ---D | M] -- C:\Program Files\Nokia
[2004/08/30 19:04:27 | 00,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/10/09 12:25:31 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2004/12/24 15:23:17 | 00,000,000 | ---D | M] -- C:\Program Files\PIXELA
[2007/12/29 13:56:07 | 00,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2004/08/30 20:01:04 | 00,000,000 | ---D | M] -- C:\Program Files\Realtek Sound Manager
[2009/03/02 08:59:23 | 00,000,000 | ---D | M] -- C:\Program Files\Sibelius Software
[2008/05/02 18:11:35 | 00,000,000 | ---D | M] -- C:\Program Files\Sony
[2004/12/24 15:22:35 | 00,000,000 | ---D | M] -- C:\Program Files\Sony Corporation
[2008/05/02 18:11:11 | 00,000,000 | ---D | M] -- C:\Program Files\Sony Setup
[2009/09/21 22:56:51 | 00,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2006/04/27 10:43:33 | 00,000,000 | ---D | M] -- C:\Program Files\Surreal
[2009/09/20 20:45:23 | 00,000,000 | ---D | M] -- C:\Program Files\SysRestorePoint
[2006/06/17 09:46:29 | 00,000,000 | ---D | M] -- C:\Program Files\The Creative Assembly
[2009/09/21 23:13:18 | 00,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2007/12/29 13:56:11 | 00,000,000 | ---D | M] -- C:\Program Files\Ubi Soft
[2004/08/30 19:16:40 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2008/01/18 16:56:58 | 00,000,000 | ---D | M] -- C:\Program Files\WIDCOMM
[2009/10/09 18:41:38 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/10/09 12:25:31 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2004/09/01 08:48:17 | 00,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2004/08/30 19:05:40 | 00,000,000 | ---D | M] -- C:\Program Files\xerox
< %systemroot%\system32\drivers\*.dat > < %PROGRAMFILES%\*.* >[2009/10/09 12:07:43 | 33,961,728 | ---- | M] () -- C:\Program Files\avira_antivir_personal_en.exe
[2009/10/09 11:01:40 | 40,519,952 | ---- | M] (COMODO) -- C:\Program Files\CIS_Setup_3.12.111745.560_XP_Vista_x32.exe
[2009/09/20 22:33:01 | 00,513,320 | ---- | M] () -- C:\Program Files\erunt.zip
[2009/09/21 23:13:09 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\HJTInstall.exe
[2003/12/19 20:36:56 | 00,040,960 | ---- | M] () -- C:\Program Files\Uninstall_CDS.exe
< %PROGRAMFILES%\*.exe >[2009/10/09 12:07:43 | 33,961,728 | ---- | M] () -- C:\Program Files\avira_antivir_personal_en.exe
[2009/10/09 11:01:40 | 40,519,952 | ---- | M] (COMODO) -- C:\Program Files\CIS_Setup_3.12.111745.560_XP_Vista_x32.exe
[2009/09/21 23:13:09 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\HJTInstall.exe
[2003/12/19 20:36:56 | 00,040,960 | ---- | M] () -- C:\Program Files\Uninstall_CDS.exe
Invalid Environment Variable: DESKTOP
< %USERNAME%\*.exe > < %USERPROFILE%\*.exe > < %ALLUSERSPROFILE%\*.exe > < %SYSTEMDRIVE%\*.exe > < %SYSTEMROOT%\*.exe >[2003/11/21 10:56:36 | 00,139,264 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\alcrmv.exe
[2003/11/21 10:58:34 | 00,208,896 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\alcupd.exe
[2004/08/04 09:56:49 | 01,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2000/08/31 08:00:00 | 00,080,412 | ---- | M] () -- C:\WINDOWS\grep.exe
[2005/05/27 01:22:01 | 00,010,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\hh.exe
[1998/10/29 17:45:06 | 00,306,688 | ---- | M] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2006/01/28 19:01:15 | 00,737,280 | ---- | M] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002.exe
[2009/04/20 12:56:28 | 00,031,232 | ---- | M] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2004/08/04 09:56:54 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[1999/04/02 16:37:00 | 00,033,792 | R--- | M] (Electronic Arts) -- C:\WINDOWS\NPSExec.exe
[2009/09/14 02:12:36 | 00,229,888 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2004/08/04 09:56:55 | 00,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\regedit.exe
[2000/08/31 08:00:00 | 00,098,816 | ---- | M] () -- C:\WINDOWS\sed.exe
[2003/02/28 18:26:30 | 00,046,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\setdebug.exe
[2004/08/04 09:56:56 | 00,032,866 | ---- | M] (Smart Link) -- C:\WINDOWS\slrundll.exe
[2003/12/19 11:53:18 | 00,065,024 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
[2000/08/31 08:00:00 | 00,161,792 | ---- | M] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2000/08/31 08:00:00 | 00,136,704 | ---- | M] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2000/08/31 08:00:00 | 00,212,480 | ---- | M] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2003/03/31 14:00:00 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2003/03/31 14:00:00 | 00,049,680 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_16.exe
[2003/03/31 14:00:00 | 00,025,600 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_32.exe
[1997/05/12 17:53:00 | 00,314,368 | ---- | M] (InstallShield Software Corporation) -- C:\WINDOWS\uninst.exe
[2005/04/20 13:32:57 | 02,916,352 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroVision.exe
[2005/02/08 14:12:22 | 02,670,592 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNMP.exe
[1999/11/10 11:05:00 | 00,086,016 | ---- | M] (MindVision) -- C:\WINDOWS\unvise32qt.exe
[2003/03/31 14:00:00 | 00,256,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhelp.exe
[2004/08/04 09:56:57 | 00,283,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhlp32.exe
[2000/08/31 08:00:00 | 00,068,096 | ---- | M] () -- C:\WINDOWS\zip.exe
[1 C:\WINDOWS\*.tmp files]
< %systemroot%\system32\drivers\*.exe > < %systemroot%\system\*.exe > < %systemroot%\AppPatch\*.exe > < %systemroot%\Cache\*.exe > < %systemroot%\Downloaded Program Files\*.exe > < %systemroot%\Fonts\*.exe > < %systemroot%\Help\*.exe > < %APPDATA%\*.exe >[2009/09/07 22:03:09 | 04,958,032 | ---- | M] (Perfect Software LLC) -- C:\Documents and Settings\Annalie\Application Data\pdinstall.exe
< %APPDATA%\Google\*.exe > < %systemroot%\system32\inf\*.exe > < %APPDATA%\Opera\Opera\profile\widgets\*.exe > < %PROGRAMFILES%\Opera\program\plugins\*.exe > < %APPDATA%\Opera\Opera\profile\toolbar\*.exe > < %systemroot%\Web\*.exe > < %systemroot%\Wbem\*.exe > < %systemroot%\twain_32\*.exe > < %systemroot%\WinSxS\*.exe > < %systemroot%\Sun\*.exe > < %systemroot%\srchasst\*.exe > < %systemroot%\Shellnew\*.exe > < %systemroot%\Security\*.exe > < %systemroot%\Resources\*.exe > < %systemroot%\Repair\*.exe > < %systemroot%\Registration\*.exe > < %systemroot%\RegisteredPackages\*.exe > < %systemroot%\pss\*.exe > < %systemroot%\Provisioning\*.exe > < %systemroot%\PIF\*.exe > < %systemroot%\PeerNet\*.exe > < %systemroot%\PcTel\*.exe > < %systemroot%\Offline Web Pages\*.exe > < %systemroot%\network diagnostic\*.exe > < %systemroot%\mui\*.exe > < %systemroot%\msapps\*.exe > < %systemroot%\msagent\*.exe >[2004/08/04 09:56:47 | 00,256,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\msagent\agentsvr.exe
< %systemroot%\minidump\*.exe > < %systemroot%\media\*.exe > < %systemroot%\Help\*.exe > < %systemroot%\ie7\*.exe > < %systemroot%\ie7updates\*.exe > < %systemroot%\ime\*.exe > < %systemroot%\installer\*.exe > < %systemroot%\internet logs\*.exe > < %systemroot%\Cursors\*.exe > < %systemroot%\Config\*.exe > < %systemroot%\internet logs\*.exe > < %systemroot%\Assembly\*.exe > < %systemroot%\internet logs\*.exe > < %systemroot%\AppPatch\*.exe > < %systemroot%\l2schemas\*.exe > < %systemroot%\Debug\*.exe > < %systemroot%\ehome\*.exe > < %systemroot%\Connection Wizard\*.exe > < %systemroot%\system32\1025\*.exe > < %systemroot%\system32\1028\*.exe > < %systemroot%\system32\1031\*.exe > < %systemroot%\system32\1033\*.exe > < %systemroot%\system32\1037\*.exe > < %systemroot%\system32\1041\*.exe > < %systemroot%\system32\1042\*.exe > < %systemroot%\system32\1054\*.exe > < %systemroot%\system32\2052\*.exe > < %systemroot%\system32\3076\*.exe > < %systemroot%\system32\appmgmt\*.exe > < %systemroot%\system32\bits\*.exe > < %systemroot%\system32\catroot\*.exe > < %systemroot%\system32\catroot2\*.exe > < %systemroot%\system32\com\*.exe >[2004/08/04 09:56:48 | 00,009,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\com\comrepl.exe
[2003/03/31 14:00:00 | 00,005,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\com\comrereg.exe
< %systemroot%\system32\config\*.exe > < %systemroot%\system32\dhcp\*.exe > < %systemroot%\system32\DirectX\*.exe > < %systemroot%\system32\drvstore\*.exe > < %systemroot%\system32\en\*.exe > < %systemroot%\system32\en-us\*.exe > < %systemroot%\system32\export\*.exe > < %systemroot%\system32\GroupPolicy\*.exe > < %systemroot%\system32\ias\*.exe > < %systemroot%\system32\icsxml\*.exe > < %systemroot%\system32\ime\*.exe > < %systemroot%\system32\inetsrv\*.exe > < %systemroot%\system32\LogFiles\*.exe > < %systemroot%\system32\Macromed\*.exe > < %systemroot%\system32\Microsoft\*.exe > < %systemroot%\system32\Msdtc\*.exe > < %systemroot%\system32\Mui\*.exe > < %systemroot%\system32\npp\*.exe >[2004/08/04 09:56:54 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\npp\nppagent.exe
< %systemroot%\system32\NtMsData\*.exe > < %systemroot%\system32\oobe\*.exe >[2003/03/31 14:00:00 | 00,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oobe\msoobe.exe
[2004/08/04 09:56:54 | 00,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oobe\oobebaln.exe
< %systemroot%\system32\PreInstall\*.exe > < %systemroot%\system32\ras\*.exe > < %systemroot%\system32\ReInstallBackups\*.exe > < %systemroot%\system32\Restore\*.exe >[2004/08/04 09:56:55 | 00,380,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Restore\rstrui.exe
[2003/03/31 14:00:00 | 00,047,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Restore\srdiag.exe
< %systemroot%\system32\Scripting\*.exe > < %systemroot%\system32\Setup\*.exe > < %systemroot%\system32\ShellExt\*.exe > < %systemroot%\system32\SoftwareDistribution\*.exe > < %systemroot%\system32\URTTEmp\*.exe >[2003/02/21 05:16:08 | 00,049,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\URTTEmp\regtlib.exe
< %systemroot%\system32\USMT\*.exe >[2004/08/04 09:56:50 | 00,103,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migload.exe
[2004/08/04 09:56:51 | 00,240,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migwiz.exe
[2004/08/04 09:56:51 | 00,236,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migwiz_a.exe
< %systemroot%\system32\Wbem\*.exe >[2004/08/04 09:56:51 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\mofcomp.exe
[2004/08/04 09:56:55 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\scrcons.exe
[2003/03/31 14:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\unsecapp.exe
[2004/08/04 09:56:57 | 00,116,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wbemtest.exe
[2003/03/31 14:00:00 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\winmgmt.exe
[2004/08/04 09:56:57 | 00,196,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wmiadap.exe
[2004/08/04 09:56:57 | 00,126,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wmiapsrv.exe
[2004/08/04 09:56:57 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wmiprvse.exe
< %systemroot%\system32\Wins\*.exe > < %systemroot%\system32\Xircom\*.exe > < %systemroot%\system32\XPSViewer\*.exe > < %COMMONPROGRAMFILES%\*.exe > < %APPDATA%\*.* >[2008/09/25 11:56:05 | 00,038,434 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\Comma Separated Values (Windows).ADR
[2004/08/30 20:51:32 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Annalie\Application Data\desktop.ini
[2009/09/07 22:03:09 | 04,958,032 | ---- | M] (Perfect Software LLC) -- C:\Documents and Settings\Annalie\Application Data\pdinstall.exe
[2008/09/25 11:47:09 | 00,038,432 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\Tab Separated Values (Windows).ADR
[2009/09/28 00:38:07 | 00,002,119 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5at.gif
[2009/09/28 00:38:07 | 00,000,598 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5by.gif
[2009/09/28 00:38:07 | 00,000,607 | ---- | M] () -- C:\Documents and Settings\Annalie\Application Data\YQzcnqK5zn.gif
< %TEMP%\*.* >[2009/10/10 11:28:27 | 00,008,989 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\au-descriptor-1.6.0_15-b71.xml
[2009/10/08 13:53:47 | 00,012,818 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\control.xml
[2009/10/09 15:57:18 | 00,803,158 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\dd_ATL80SP1_KB973923MSI70B6.txt
[2009/10/09 15:57:18 | 00,011,756 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\dd_ATL80SP1_KB973923UI70B6.txt
[2009/10/10 22:22:03 | 00,480,004 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\dd_vcredistMSI654F.txt
[2009/10/10 22:22:03 | 00,011,498 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\dd_vcredistUI654F.txt
[2009/10/09 16:41:44 | 00,000,291 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\java_install_reg.log
[2009/10/10 11:29:35 | 00,000,949 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\jinstall.cfg
[2009/09/23 22:15:37 | 00,714,528 | ---- | M] (Sun Microsystems, Inc.) -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\jre-6u15-windows-i586-iftw.exe
[2009/10/10 11:29:35 | 00,031,796 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\jusched.log
[2009/10/08 09:18:39 | 00,006,340 | ---- | M] () -- C:\DOCUME~1\Annalie\LOCALS~1\Temp\mccleanup.log
[15 C:\DOCUME~1\Annalie\LOCALS~1\Temp\*.tmp files]
< set /c >ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Annalie\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HOME-STUDY
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Annalie
LOGONSERVER=\\HOME-STUDY
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\ATI Technologies\ATI Control Panel
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Annalie\LOCALS~1\Temp
TMP=C:\DOCUME~1\Annalie\LOCALS~1\Temp
USERDOMAIN=HOME-STUDY
USERNAME=Annalie
USERPROFILE=C:\Documents and Settings\Annalie
windir=C:\WINDOWS
========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Annalie\Desktop\aaw2007.exe:SummaryInformation
< End of report >
###############################
There was only the log created in the previous run (Sept) in the Extras.Txt file - it seems this run created nothing new. Hope this is OK!
Thanks again!
Annalie