OTListIt LogfileOTListIt logfile created on: 1/29/2009 6:51:35 PM - Run
OTListIt2 by OldTimer - Version 1.0.4.1 Folder = C:\Documents and Settings\Kathleen\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
223.48 Mb Total Physical Memory | 106.47 Mb Available Physical Memory | 47.64% Memory free
546.13 Mb Paging File | 178.06 Mb Available in Paging File | 32.60% Paging File free
Paging file location(s): C:\pagefile.sys 336 672;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.63 Gb Total Space | 9.32 Gb Free Space | 50.03% Space Free | Partition Type: FAT32
Drive D: | 18.63 Gb Total Space | 4.93 Gb Free Space | 26.47% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PERSONAL-ECE16E
Current User Name: Kathleen
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe (Symantec Corporation)
D:\iTunesHelper.exe (Apple Inc.)
C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\Vista Drive Icon\DrvIcon.exe (artArmin)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\VisualTooltip\VisualToolTip.exe (Christian Salmon)
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe (Symantec Corporation)
C:\Program Files\DAP\DAP.EXE (Speedbit Ltd.)
C:\Program Files\ViOrb\ViOrb.exe (Lee-Soft.com)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
C:\Program Files\Vista Start Menu\VistaStartMenu.exe (OrdinarySoft)
C:\Program Files\ViStart\ViStart.exe (Lee Matthew Chantrey & Windows X)
C:\Program Files\VisualTooltip\VisualToolTip.exe (Christian Salmon)
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe (Speedbit Ltd.)
C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe (Speedbit Ltd.)
C:\Documents and Settings\Kathleen\Desktop\OTListIt2.exe (OldTimer Tools)
========== (O23) Win32 Services (SafeList) ========== (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
(aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(Autodesk Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
(Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
(BthServ [Auto | Running]) -- C:\WINDOWS\System32\bthserv.dll (Microsoft Corporation)
(CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(DefWatch [Auto | Running]) -- C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe (Symantec Corporation)
(getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
(helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
(iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(Microsoft Office Groove Audit Service [On_Demand | Stopped]) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
(NBService [On_Demand | Stopped]) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
(NMIndexingService [On_Demand | Running]) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
(Norton AntiVirus Server [Auto | Running]) -- C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe (Symantec Corporation)
(odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
(ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
(Pctspk [Auto | Running]) -- C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)
(usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(VideoAcceleratorService [Auto | Running]) -- C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe (Speedbit Ltd.)
(WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
(WudfSvc [On_Demand | Stopped]) -- C:\WINDOWS\System32\WUDFSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ========== (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
(BthEnum [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\BthEnum.sys (Microsoft Corporation)
(BTHMODEM [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\bthmodem.sys (Microsoft Corporation)
(BthPan [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\bthpan.sys (Microsoft Corporation)
(BTHPORT [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BTHport.sys (Microsoft Corporation)
(BTHUSB [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BTHUSB.sys (Microsoft Corporation)
(FETNDIS [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
(gameenum [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
(GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
(NAVAP [On_Demand | Running]) -- C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys (Symantec Corporation)
(NAVAPEL [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS (Symantec Corporation)
(NAVENG [On_Demand | Running]) -- C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090122.020\NAVENG.sys (Symantec Corporation)
(NAVEX15 [On_Demand | Running]) -- C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090122.020\NAVEX15.sys (Symantec Corporation)
(Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
(Ptserlp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptserlp.sys (PCTEL, INC.)
(RFCOMM [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\rfcomm.sys (Microsoft Corporation)
(S3SavageNB [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
(sbbotdi [Auto | Running]) -- C:\PROGRA~1\SPEEDB~1\sbbotdi.sys (SpeedBit Ltd.)
(Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys ()
(SymEvent [On_Demand | Running]) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
(usbvideo [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\usbvideo.sys (Microsoft Corporation)
(Vmodem [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vmodem.sys (PCTEL, INC.)
(Vpctcom [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vpctcom.sys (PCtel, Inc.)
(Vvoice [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vvoice.sys (PCtel, Inc.)
========== Standard Registry (All) ========== ========== Internet Explorer ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.comHKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo....Terms}&fr=yie7cHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/intl/en/URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (801 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - D:\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar: (no name) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe (artArmin)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "D:\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpeedBitVideoAccelerator] "C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe" (Speedbit Ltd.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VisualTooltip] C:\Program Files\VisualTooltip\VisualToolTip.exe (Christian Salmon)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (Nero AG)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP (Speedbit Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe (Lee-Soft.com)
O4 - HKCU..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe (Lee Matthew Chantrey & Windows X)
O4 - HKCU..\Run: [VistaStartMenu] "C:\Program Files\Vista Start Menu\VistaStartMenu.exe" (OrdinarySoft)
O4 - HKCU..\Run: [VisualTooltip] C:\Program Files\VisualTooltip\VisualToolTip.exe (Christian Salmon)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\Kathleen\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Kathleen\Start Menu\Programs\Startup\Multiply AutoUploader.lnk = D:\Multiply AutoUploader\Multiply AutoUploader.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download by Orbit - res://D:\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71}
http://codecs.micros...cs/i386/fhg.CAB (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - grooveLocalGWS - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-help - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - skype4com - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wlmailhtml - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
========== HKLM Winlogon Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\Explorer.exe (Microsoft Corporation)
"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
"UIHost" = vistaui.exe
>C:\WINDOWS\system32\vistaui.exe (Microsoft Corporation)
"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
========== Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll -- C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll -- C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll -- C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\system32\NavLogon.dll ()
ScCertProp: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll -- C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll -- C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
========== IFEO "Debugger" Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
========== Shell Execute Hooks ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) -- C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) -- C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL (Microsoft Corporation)
========== HKLM *SecurityProviders* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
========== LSA *Authentication Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
========== LSA *Security Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
========== Safeboot Options ========== "AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () -- [ FAT32 ]
========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6eee55d0-a941-11dd-95bc-003018072533}\Shell\AutoRun\command]
"" = rsbrj.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6eee55d0-a941-11dd-95bc-003018072533}\Shell\explore\Command]
"" = rsbrj.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6eee55d0-a941-11dd-95bc-003018072533}\Shell\open\Command]
"" = rsbrj.exe
========== Files/Folders - Created Within 30 Days ========== [3 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/01/29 18:49:12 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kathleen\Desktop\OTListIt2.exe
[2009/01/29 18:35:03 | 00,393,112 | ---- | C] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/01/29 18:30:50 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/01/29 18:26:11 | 00,348,160 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kathleen\Desktop\OTMoveIt3.exe
[2009/01/28 17:36:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\Help
[2009/01/28 17:35:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Local Settings\Application Data\Help
[2009/01/24 22:49:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\Malwarebytes
[2009/01/24 22:48:59 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/24 22:48:58 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/24 22:48:54 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/24 22:48:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/24 22:48:50 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/24 22:43:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/01/24 22:41:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/24 22:40:38 | 00,000,515 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\NTREGOPT.lnk
[2009/01/24 22:40:38 | 00,000,496 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\ERUNT.lnk
[2009/01/24 22:40:32 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/01/24 22:37:48 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Kathleen\Desktop\erunt_setup.exe
[2009/01/23 16:38:03 | 00,086,016 | ---- | C] (MindVision Software) -- C:\WINDOWS\unvise32.exe
[2009/01/23 16:37:52 | 00,000,373 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\Media Subtitler.lnk
[2009/01/23 16:16:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Desktop\plugins
[2009/01/23 15:17:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\My Documents\Nero Home
[2009/01/21 19:11:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2009/01/21 18:54:44 | 00,076,214 | ---- | C] () -- C:\WINDOWS\Icon_3.ico
[2009/01/21 18:42:07 | 00,000,000 | ---D | C] -- C:\Program Files\TrueTransparency
[2009/01/21 18:42:04 | 00,000,000 | ---D | C] -- C:\Program Files\WinFlip
[2009/01/21 18:42:03 | 00,000,000 | ---D | C] -- C:\Program Files\ViStart
[2009/01/21 18:42:03 | 00,000,000 | ---D | C] -- C:\Program Files\ViOrb
[2009/01/21 18:42:02 | 00,000,000 | ---D | C] -- C:\Program Files\VisualTooltip
[2009/01/21 18:41:56 | 00,000,000 | ---D | C] -- C:\Program Files\Styler
[2009/01/21 18:41:54 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\LClock.cpl
[2009/01/21 18:41:54 | 00,000,000 | ---D | C] -- C:\Program Files\Vista Rainbar
[2009/01/21 18:41:53 | 00,000,000 | ---D | C] -- C:\Program Files\LClock
[2009/01/21 18:41:52 | 06,181,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vistaui.exe
[2009/01/21 18:41:52 | 00,049,208 | ---- | C] () -- C:\WINDOWS\System32\vistartup.bmp
[2009/01/21 18:41:52 | 00,000,000 | ---D | C] -- C:\Program Files\Vista Drive Icon
[2009/01/21 18:36:13 | 00,076,214 | ---- | C] () -- C:\WINDOWS\Icon_2.ico
[2009/01/21 18:35:50 | 00,000,610 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\vtp.sif
[2009/01/21 18:29:56 | 00,020,480 | ---- | C] (WindowsX Corporation) -- C:\WINDOWS\System32\scrnrdr.exe
[2009/01/21 18:04:18 | 00,001,253 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\My Completed Downloads.lnk
[2009/01/21 18:04:18 | 00,000,514 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\Download Accelerator Plus (DAP).lnk
[2009/01/21 17:44:27 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2009/01/21 17:34:50 | 00,000,000 | -HSD | C] -- C:\FOUND.001
[2009/01/19 21:23:18 | 00,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/01/19 21:22:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\skypePM
[2009/01/19 21:13:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\Skype
[2009/01/19 21:09:37 | 00,002,257 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/01/19 21:08:02 | 00,000,000 | ---D | C] -- C:\Program Files\Skype
[2009/01/19 21:07:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009/01/19 21:03:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype
[2009/01/18 13:34:54 | 00,000,524 | ---- | C] () -- C:\Documents and Settings\Kathleen\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
[2009/01/18 13:34:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
[2009/01/17 20:16:31 | 00,000,050 | ---- | C] () -- C:\WINDOWS\MegaManager.INI
[2009/01/17 08:11:06 | 00,000,000 | -HSD | C] -- C:\FOUND.000
[2009/01/14 17:04:03 | 00,000,636 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\Free Mp3 Wma Converter.lnk
[2009/01/14 17:03:57 | 00,164,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\COMCT232.OCX
[2009/01/14 17:03:45 | 00,116,296 | ---- | C] () -- C:\WINDOWS\System32\NCTWMAProfiles.prx
[2009/01/14 17:03:44 | 00,479,232 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudioVisu.dll
[2009/01/14 17:03:44 | 00,458,752 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudPlayer.dll
[2009/01/14 17:03:44 | 00,454,656 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudioRecord.dll
[2009/01/14 17:03:43 | 01,986,560 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudFile.dll
[2009/01/14 17:03:43 | 01,212,416 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudioInfos.dll
[2009/01/14 17:03:43 | 00,417,792 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudDisplay.dll
[2009/01/14 17:03:42 | 02,084,864 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\AudDesign.dll
[2009/01/14 17:03:42 | 00,119,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\VB6FR.DLL
[2009/01/14 17:03:42 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\VB6STKIT.DLL
[2009/01/14 17:03:42 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetfr.DLL
[2009/01/14 17:03:41 | 00,224,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TABCTL32.OCX
[2009/01/14 17:03:41 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TABCTFR.DLL
[2009/01/14 17:03:40 | 00,662,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSCOMCT2.OCX
[2009/01/14 17:03:40 | 00,141,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSCMCFR.DLL
[2009/01/14 17:03:39 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Mscc2fr.dll
[2009/01/14 17:03:39 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CMDLGFR.DLL
[2009/01/14 17:03:38 | 00,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009/01/14 17:03:37 | 00,307,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr70.dll
[2009/01/13 23:45:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\Megaupload
[2009/01/13 23:44:49 | 00,000,420 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mega Manager.lnk
[2009/01/13 23:43:31 | 00,000,000 | ---D | C] -- C:\downloads
[2009/01/13 23:43:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\EmailNotifier
[2009/01/13 23:43:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Megaupload
[2009/01/13 23:43:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2009/01/13 23:43:10 | 00,000,000 | ---D | C] -- C:\Program Files\MegauploadToolbar
[2009/01/13 23:43:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\MegauploadToolbar
[2009/01/13 23:41:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\InstallShield
[2009/01/04 17:27:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\My Documents\Any Video Converter
[2009/01/04 17:26:48 | 00,000,497 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\Any Video Converter.lnk
[2009/01/04 17:26:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\Any Video Converter
[2009/01/04 15:05:45 | 00,038,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthmodem.sys
[2009/01/04 15:05:45 | 00,038,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthmodem.sys
[2009/01/04 14:58:44 | 00,000,012 | ---- | C] () -- C:\WINDOWS\bthservsdp.dat
[2009/01/04 14:57:10 | 00,100,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthpan.sys
[2009/01/04 14:57:10 | 00,100,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthpan.sys
[2009/01/04 14:56:53 | 00,059,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rfcomm.sys
[2009/01/04 14:56:53 | 00,059,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rfcomm.sys
[2009/01/04 14:56:53 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BthEnum.sys
[2009/01/04 14:56:53 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthenum.sys
[2009/01/04 14:56:52 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll
[2009/01/04 14:56:52 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll
[2009/01/04 14:56:51 | 00,152,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irftp.exe
[2009/01/04 14:56:51 | 00,152,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irftp.exe
[2009/01/04 14:56:51 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshirda.dll
[2009/01/04 14:56:51 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshirda.dll
[2009/01/04 14:56:30 | 00,274,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthport.sys
[2009/01/04 14:56:30 | 00,274,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2009/01/04 14:56:29 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BTHUSB.SYS
[2009/01/04 14:56:29 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthusb.sys
[2009/01/03 02:47:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\My Documents\Icons and Cursors
[2009/01/03 02:47:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Local Settings\Application Data\Microangelo Toolset 6
[2009/01/01 06:08:31 | 00,359,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tcpip.sys.original.orbit
[2009/01/01 06:08:31 | 00,359,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip.sys.original.orbit
[2009/01/01 06:02:07 | 00,000,502 | ---- | C] () -- C:\Documents and Settings\Kathleen\Desktop\Orbit.lnk
[2009/01/01 05:53:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/01/01 05:43:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Desktop\Cablenut
[2009/01/01 05:09:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kathleen\Application Data\Vista Start Menu
[2009/01/01 05:09:25 | 00,000,000 | ---D | C] -- C:\Program Files\Vista Start Menu
[2008/12/31 14:45:18 | 02,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntkrnlpa.exe.zottel
[2008/12/31 14:45:17 | 02,192,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntoskrnl.exe.zottel
[2008/12/31 14:19:57 | 00,000,000 | ---D | C] -- C:\Program Files\ViSplore
[2008/12/31 13:36:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2008/12/31 13:36:16 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek AC97
[2008/12/31 13:34:14 | 00,000,000 | ---D | C] -- C:\alcvista
[2008/12/31 11:30:29 | 00,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2008/12/31 10:42:55 | 00,053,732 | ---- | C] () -- C:\WaxCrash.dmp
[2008/12/31 10:29:53 | 00,000,000 | ---D | C] -- C:\Program Files\DebugMode
========== Files - Modified Within 30 Days ========== [3 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/01/29 18:49:44 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kathleen\Desktop\OTListIt2.exe
[2009/01/29 18:38:56 | 00,393,112 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/01/29 18:35:56 | 00,008,224 | ---- | M] () -- C:\Documents and Settings\Kathleen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/29 18:33:14 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/29 18:33:10 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/29 18:33:08 | 23,440,9984 | -HS- | M] () -- C:\hiberfil.sys
[2009/01/29 18:32:20 | 00,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2009/01/29 18:27:22 | 00,348,160 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kathleen\Desktop\OTMoveIt3.exe
[2009/01/28 18:03:24 | 00,002,515 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Microsoft Office Word 2007.lnk
[2009/01/28 18:00:08 | 00,000,414 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Kathleen.job
[2009/01/28 17:03:14 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/26 09:55:50 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Microsoft Office Excel 2007.lnk
[2009/01/25 03:01:40 | 00,359,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tcpip.sys
[2009/01/25 03:01:38 | 00,359,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip.sys
[2009/01/24 22:49:00 | 00,000,600 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/24 22:40:40 | 00,000,515 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\NTREGOPT.lnk
[2009/01/24 22:40:40 | 00,000,496 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\ERUNT.lnk
[2009/01/24 22:38:46 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Kathleen\Desktop\erunt_setup.exe
[2009/01/24 20:58:44 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/01/24 18:15:12 | 00,094,720 | ---- | M] () -- C:\Documents and Settings\Kathleen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/23 16:37:54 | 00,000,373 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Media Subtitler.lnk
[2009/01/23 00:42:22 | 00,000,050 | ---- | M] () -- C:\WINDOWS\MegaManager.INI
[2009/01/21 21:40:56 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/01/21 18:54:46 | 00,076,214 | ---- | M] () -- C:\WINDOWS\Icon_3.ico
[2009/01/21 18:42:12 | 00,001,324 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vista Transformation Pack - Welcome Center.lnk
[2009/01/21 18:36:14 | 00,076,214 | ---- | M] () -- C:\WINDOWS\Icon_2.ico
[2009/01/21 18:35:52 | 00,000,610 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\vtp.sif
[2009/01/21 18:04:20 | 00,001,253 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\My Completed Downloads.lnk
[2009/01/21 18:04:20 | 00,000,514 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Download Accelerator Plus (DAP).lnk
[2009/01/21 17:52:12 | 00,000,464 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VDownloader.lnk
[2009/01/21 17:46:14 | 00,000,524 | ---- | M] () -- C:\Documents and Settings\Kathleen\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
[2009/01/19 21:23:20 | 00,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/01/14 17:04:04 | 00,000,636 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Free Mp3 Wma Converter.lnk
[2009/01/14 16:11:32 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/13 23:44:50 | 00,000,420 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mega Manager.lnk
[2009/01/10 13:36:36 | 00,001,506 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/10 13:01:44 | 00,395,200 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/01/10 13:01:44 | 00,059,440 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/01/10 13:01:42 | 00,462,344 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/04 17:26:50 | 00,000,497 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Any Video Converter.lnk
[2009/01/01 06:02:08 | 00,000,502 | ---- | M] () -- C:\Documents and Settings\Kathleen\Desktop\Orbit.lnk
[2008/12/31 14:49:56 | 01,161,400 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/31 14:46:10 | 00,218,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uxtheme.dll
[2008/12/31 11:29:10 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2008/12/31 11:29:10 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2008/12/31 10:43:12 | 00,053,732 | ---- | M] () -- C:\WaxCrash.dmp
========== LOP Check ========== [2008/10/28 21:38:34 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/11/09 18:01:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/30 20:45:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/10/28 22:23:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2008/11/09 17:58:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2008/11/09 17:59:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/28 23:13:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/01/13 23:43:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2008/12/15 02:50:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/01/24 22:48:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/13 23:43:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Megaupload
[2008/10/28 21:38:12 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/10/28 22:40:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/10/28 22:21:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nero
[2008/10/30 20:01:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS
[2008/11/16 01:14:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\scar5
[2009/01/19 21:03:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2008/10/30 21:28:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2008/10/28 22:36:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2008/10/30 21:28:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/10/28 23:42:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/11/08 18:26:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2008/11/05 20:44:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/11/22 22:46:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/12/15 02:55:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2008/11/17 09:03:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2008/10/28 21:38:34 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Kathleen\Application Data
[2008/10/30 19:38:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kathleen\Application Data\Adobe
[2008/10/28 22:23:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kathleen\Application Data\Ahead
[2009/01/04 17:26:22 | 00,000,000 | ---D | M] -- C:\Documents and