Code:
8.00 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 82.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 433.07 Gb Free Space | 93.00% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: XXXX09
Current User Name: XXXX
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\XXXX\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\XXXX\AppData\Local\Temp\Temp1_HostsXpert.zip\HostsXpert\HostsXpert.exe (funkytoad.com)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Everything\Everything.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\XXXX\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (TabletServiceWacom) -- C:\Windows\SysNative\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (WwanSvc) -- C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) -- C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (Power) -- C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) -- C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) -- C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) -- C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (StorSvc) -- C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) -- C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) -- C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) -- C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) -- C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) -- C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) -- C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) -- C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) -- C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) -- C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) -- C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) -- C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) -- C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
SRV - (VSS) -- C:\Windows\Vss [2009/07/14 03:20:14 | 00,000,000 | ---D | M]
SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2009/07/14 03:20:14 | 00,000,000 | ---D | M]
SRV - (HomeGroupProvider) -- C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab)
DRV:64bit: - (KLBG) -- C:\Windows\SysNative\drivers\klbg.sys (Kaspersky Lab)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (kl1) -- C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab)
DRV:64bit: - (wacmoumonitor) -- C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (KSecPkg) -- C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) -- C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) -- C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) -- C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) -- C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) -- C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) -- C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) -- C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) -- C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (fvevol) -- C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) -- C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) -- C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) -- C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) -- C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) -- C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) -- C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) -- C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) -- C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\SysNative\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) -- C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) -- C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) -- C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) -- C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) -- C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) -- C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) -- C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (discache) -- C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) -- C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) -- C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) -- C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (e1kexpress) Intel(R) -- C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (wacomvhid) -- C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (RimVSerPort) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (adfs) -- C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (wacommousefilter) -- C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (CSC) -- C:\Windows\CSC [2010/01/05 10:11:39 | 00,000,000 | ---D | M]
DRV - (SBRE) -- C:\Windows\SysWOW64\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NetBIOS) -- C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (adfs) -- C:\Windows\SysWOW64\drivers\adfs.sys (Adobe Systems, Inc.)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Bing
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Bing
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.XXXXgolf.co.uk/t1/t1/launch.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 E3 FD C7 E8 8F CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "http://www.XXXXgolf.co.uk/t1/t1/launch.html"
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.736
FF - prefs.js..extensions.enabledItems: LogMeInClient@logmein.com:1.0.0.464
FF - prefs.js..extensions.enabledItems: {b4e481a8-9ef7-47ff-8512-dc865ba752bd}:1.1.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
FF - prefs.js..keyword.URL: "http://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p="
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/01/11 19:38:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/01/11 19:37:41 | 00,000,000 | ---D | M]
[2010/01/07 22:28:34 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Mozilla\Extensions
[2010/01/07 22:28:34 | 00,000,000 | ---D | M] (No name found) -- C:\Users\XXXX\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/01/11 13:49:25 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\rkmp1sbs.default\extensions
[2010/01/07 23:37:46 | 00,000,000 | ---D | M] (Zen Usage Viewer) -- C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\rkmp1sbs.default\extensions\{b4e481a8-9ef7-47ff-8512-dc865ba752bd}
[2010/01/09 12:16:30 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\rkmp1sbs.default\extensions\LogMeInClient@logmein.com
[2010/01/10 21:24:51 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/01/07 22:19:19 | 00,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/01/10 21:24:52 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2009/12/22 17:41:43 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll
[2009/12/22 17:41:44 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll
[2009/12/22 17:41:45 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
[2009/12/22 02:32:20 | 00,001,394 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazondotcom.xml
[2009/12/22 02:32:20 | 00,002,193 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\answers.xml
[2010/01/08 21:05:27 | 00,001,353 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg_igeared.xml
[2009/12/22 02:32:20 | 00,001,534 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\creativecommons.xml
[2009/12/22 02:32:20 | 00,002,344 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay.xml
[2009/12/22 02:32:20 | 00,002,371 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\google.xml
[2009/12/22 02:32:20 | 00,001,178 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia.xml
[2009/12/22 02:32:20 | 00,000,792 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: (698 bytes) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll File not found
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [Everything] C:\Program Files (x86)\Everything\Everything.exe ()
O4 - Startup: C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\306313.lnk = C:\Users\XXXX\AppData\Local\Temp\nvscv.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9:64bit: - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/ge...sh/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\mzvkbd3.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll (Kaspersky Lab)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4604f6de-f9e9-11de-b431-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{4604f6de-f9e9-11de-b431-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.bat -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
64bit: O35 - comfile [open] -- "%1" %* File not found
64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/01/11 23:37:32 | 00,544,256 | ---- | C] (OldTimer Tools) -- C:\Users\XXXX\Desktop\OTL.exe
[2010/01/11 23:33:23 | 00,000,000 | ---D | C] -- C:\Users\XXXX\Desktop\HostsXpert
[2010/01/11 23:03:06 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Everything
[2010/01/11 22:50:28 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Yahoo!
[2010/01/11 22:50:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
[2010/01/11 19:35:37 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2010/01/11 18:52:36 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2010/01/11 18:26:11 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\process explorer
[2010/01/11 15:47:48 | 00,093,872 | ---- | C] (Sunbelt Software) -- C:\Windows\SysWow64\drivers\SBREDrv.sys
[2010/01/11 15:47:48 | 00,027,944 | ---- | C] (Sunbelt Software) -- C:\Windows\SysWow64\sbbd.exe
[2010/01/11 15:47:39 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\VIPRERESCUE
[2010/01/11 14:51:57 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Process Monitor
[2010/01/10 21:23:57 | 00,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010/01/10 21:23:57 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Kaspersky Lab
[2010/01/10 21:23:48 | 00,353,296 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2010/01/10 18:06:13 | 00,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2010/01/10 12:32:59 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Antimalware
[2010/01/10 12:32:56 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/01/10 12:20:00 | 00,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/01/10 12:20:00 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2010/01/10 11:05:37 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\a-squared Free
[2010/01/10 10:41:17 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Malwarebytes
[2010/01/10 10:41:12 | 00,022,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010/01/10 10:41:12 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/01/10 10:38:50 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/01/10 10:38:44 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\SUPERAntiSpyware.com
[2010/01/10 10:38:44 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\SUPERAntiSpyware
[2010/01/10 10:14:07 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2010/01/09 23:39:14 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\{C0B133B8-33F7-401B-A331-5780D8F885A9}
[2010/01/09 23:34:28 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2010/01/09 19:24:49 | 00,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2010/01/09 19:12:42 | 00,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/01/09 19:09:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2010/01/09 19:09:10 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Adobe
[2010/01/09 19:08:58 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2010/01/09 19:08:40 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2010/01/09 16:43:16 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Foxit
[2010/01/09 13:57:47 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2010/01/09 13:57:31 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Macromedia
[2010/01/09 13:56:07 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Adobe
[2010/01/09 13:56:07 | 00,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010/01/09 13:56:01 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2010/01/09 13:55:53 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/01/09 13:54:22 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2010/01/09 12:55:15 | 00,000,000 | ---D | C] -- C:\Users\XXXX\Documents\My Maps
[2010/01/09 12:54:52 | 00,000,000 | ---D | C] -- C:\ProgramData\Mindjet
[2010/01/09 12:44:30 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\{7C480F86-91B2-4DE0-9E83-A05DD0140F5C}
[2010/01/09 12:41:24 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Mindjet
[2010/01/09 12:40:51 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Mindjet
[2010/01/09 12:36:30 | 00,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2010/01/09 12:22:14 | 00,031,744 | ---- | C] (Research in Motion Ltd) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys
[2010/01/09 11:25:42 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Van Dyke Technologies
[2010/01/09 11:24:55 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AbsoluteFTP
[2010/01/09 11:10:22 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Xara
[2010/01/09 11:09:49 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2010/01/09 09:59:41 | 00,000,000 | ---D | C] -- C:\Users\XXXX\Documents\Xara_Xara Xtreme Pro 5
[2010/01/09 09:59:41 | 00,000,000 | ---D | C] -- C:\ProgramData\Magix
[2010/01/09 09:34:12 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Xara
[2010/01/09 09:34:12 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\MAGIX
[2010/01/09 09:34:02 | 00,000,000 | ---D | C] -- C:\ProgramData\Xara
[2010/01/08 22:47:36 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\.oit
[2010/01/08 22:45:04 | 00,000,000 | ---D | C] -- C:\ProgramData\X1 Updater
[2010/01/08 22:45:04 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\X1
[2010/01/08 22:05:15 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\avg
[2010/01/08 21:30:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ActiveSync
[2010/01/08 21:30:15 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010/01/08 21:30:10 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2010/01/08 21:30:10 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2010/01/08 21:27:27 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2010/01/08 18:00:38 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Diagnostics
[2010/01/08 08:35:23 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Helios
[2010/01/08 08:24:15 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\PolyEdit Lite
[2010/01/08 00:21:10 | 00,000,000 | ---D | C] -- C:\Docs
[2010/01/08 00:20:16 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\TeamViewer
[2010/01/08 00:20:09 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2010/01/08 00:19:45 | 00,000,000 | ---D | C] -- C:\Users\XXXX\temp
[2010/01/08 00:13:36 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\skypePM
[2010/01/08 00:10:11 | 00,000,000 | ---D | C] -- C:\ProgramData\Skype
[2010/01/07 23:58:47 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\WTablet
[2010/01/07 23:58:43 | 09,104,680 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\WacomTablet.cpl
[2010/01/07 23:58:43 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\TabletPlugins
[2010/01/07 23:58:40 | 00,012,848 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacommousefilter.sys
[2010/01/07 23:58:33 | 00,015,656 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacomvhid.sys
[2010/01/07 23:58:29 | 00,018,216 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacmoumonitor.sys
[2010/01/07 23:58:29 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\WTablet
[2010/01/07 23:58:26 | 05,521,192 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wacom_Tablet.exe
[2010/01/07 23:58:26 | 00,486,184 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wacom_Tablet.dll
[2010/01/07 23:58:26 | 00,412,456 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wacom_Tablet.dll
[2010/01/07 23:58:26 | 00,350,208 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wintab32.dll
[2010/01/07 23:58:26 | 00,285,184 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wintab32.dll
[2010/01/07 23:58:24 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Tablet
[2010/01/07 23:23:02 | 00,000,000 | ---D | C] -- C:\PSTs
[2010/01/07 23:16:03 | 00,000,000 | ---D | C] -- C:\Users\XXXX\Desktop\Seldom Used
[2010/01/07 22:56:41 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Deployment
[2010/01/07 22:56:41 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Apps
[2010/01/07 22:53:38 | 00,000,000 | ---D | C] -- C:\Users\XXXX\Documents\Downloads
[2010/01/07 22:48:00 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Google
[2010/01/07 22:47:54 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Google
[2010/01/07 22:47:49 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2010/01/07 22:28:29 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Mozilla
[2010/01/07 22:28:29 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Mozilla
[2010/01/07 22:25:59 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Searches
[2010/01/07 22:25:57 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Identities
[2010/01/07 22:25:55 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Contacts
[2010/01/07 22:25:55 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\VirtualStore
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\AppData\Local\Temporary Internet Files
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Templates
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Start Menu
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\SendTo
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Recent
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\PrintHood
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\NetHood
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Documents\My Videos
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Documents\My Pictures
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Documents\My Music
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\My Documents
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Local Settings
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\AppData\Local\History
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Cookies
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Application Data
[2010/01/07 22:25:53 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\AppData\Local\Application Data
[2010/01/07 22:25:52 | 00,000,000 | --SD | C] -- C:\Users\XXXX\AppData\Roaming\Microsoft
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Videos
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Saved Games
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Pictures
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Music
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Links
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Favorites
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Downloads
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Documents
[2010/01/07 22:25:52 | 00,000,000 | R--D | C] -- C:\Users\XXXX\Desktop
[2010/01/07 22:25:52 | 00,000,000 | -H-D | C] -- C:\Users\XXXX\AppData
[2010/01/07 22:25:52 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Temp
[2010/01/07 22:25:52 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Microsoft
[2010/01/07 22:25:52 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Media Center Programs
[2010/01/07 22:19:18 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2010/01/07 21:24:52 | 00,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2010/01/07 21:16:00 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft IntelliType Pro
[2010/01/05 18:10:37 | 00,000,000 | ---D | C] -- C:\Windows\Panther
[2010/01/05 13:23:57 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010/01/05 13:23:18 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/01/05 12:20:37 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2010/01/05 11:19:05 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010/01/05 11:18:45 | 00,541,800 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvuninst.exe
[2010/01/05 11:15:35 | 14,629,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2010/01/05 11:15:35 | 11,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2010/01/05 11:15:34 | 12,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2010/01/05 11:15:34 | 12,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2010/01/05 11:15:34 | 02,868,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2010/01/05 11:15:34 | 02,613,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2010/01/05 11:15:34 | 01,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll
[2010/01/05 11:15:34 | 01,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll
[2010/01/05 11:15:34 | 00,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2010/01/05 11:15:34 | 00,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2010/01/05 11:15:34 | 00,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010/01/05 11:15:34 | 00,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010/01/05 11:15:34 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2010/01/05 11:15:34 | 00,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2010/01/05 11:15:22 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll
[2010/01/05 11:15:21 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedsbs.dll
[2010/01/05 11:15:21 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
[2010/01/05 11:06:04 | 00,000,000 | ---D | C] -- C:\Program Files\Intel
[2010/01/05 11:05:53 | 00,342,656 | R--- | C] (Intel Corporation) -- C:\Windows\SysNative\PROUnstl.exe
[2010/01/05 11:05:27 | 00,273,072 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\e1k62x64.sys
[2010/01/05 11:05:27 | 00,072,288 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\e1kmsg.dll
[2010/01/05 11:05:27 | 00,036,472 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\NicCo36.dll
[2010/01/05 11:05:25 | 00,078,016 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\NicInstK.dll
[2010/01/05 11:03:02 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2010/01/05 11:03:02 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek
[2010/01/05 11:02:54 | 00,513,536 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2010/01/05 11:02:54 | 00,211,376 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2010/01/05 11:02:54 | 00,150,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2010/01/05 11:02:53 | 01,552,416 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
[2010/01/05 11:02:53 | 01,272,352 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
[2010/01/05 11:02:53 | 00,417,824 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
[2010/01/05 11:02:53 | 00,332,320 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
[2010/01/05 11:02:53 | 00,193,536 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2010/01/05 11:02:53 | 00,149,536 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
[2010/01/05 11:02:52 | 01,163,296 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
[2010/01/05 11:02:52 | 00,611,360 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
[2010/01/05 11:02:52 | 00,304,640 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2010/01/05 11:02:52 | 00,304,640 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2010/01/05 11:02:52 | 00,066,080 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInst64.dll
[2010/01/05 11:02:51 | 00,311,296 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010/01/05 11:02:50 | 00,176,640 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\FMAPO64.dll
[2010/01/05 11:02:50 | 00,166,400 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAC64.dll
[2010/01/05 11:02:50 | 00,108,032 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAR64.dll
[2010/01/05 11:02:50 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2010/01/05 11:02:49 | 00,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2010/01/05 11:02:49 | 00,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2010/01/05 11:02:48 | 00,540,672 | R--- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2010/01/05 11:02:43 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2010/01/05 11:01:01 | 00,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2010/01/05 11:01:01 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2010/01/05 11:00:59 | 00,000,000 | ---D | C] -- C:\Intel
[2010/01/05 11:00:18 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2010/01/05 11:00:16 | 00,000,000 | -HSD | C] -- C:\Windows\Installer
[2010/01/05 11:00:13 | 00,000,000 | ---D | C] -- C:\TempEI4
[2010/01/05 10:54:50 | 00,000,000 | -HSD | C] -- C:\Recovery
[2010/01/05 10:54:47 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010/01/05 10:11:43 | 00,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010/01/05 10:11:11 | 00,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2010/01/11 23:47:00 | 02,359,296 | -HS- | M] () -- C:\Users\XXXX\NTUSER.DAT
[2010/01/11 23:37:36 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Users\XXXX\Desktop\OTL.exe
[2010/01/11 23:36:43 | 00,000,698 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2010/01/11 23:33:09 | 00,353,485 | ---- | M] () -- C:\Users\XXXX\Desktop\HostsXpert.zip
[2010/01/11 23:22:00 | 00,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1000UA.job
[2010/01/11 23:21:17 | 00,014,816 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/01/11 23:21:17 | 00,014,816 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/01/11 23:18:28 | 00,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/01/11 23:18:28 | 00,619,206 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/01/11 23:18:28 | 00,107,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/01/11 23:14:24 | 00,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/01/11 23:14:07 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/01/11 23:14:02 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/01/11 23:13:53 | 21,399,42911 | -HS- | M] () -- C:\hiberfil.sys
[2010/01/11 23:09:38 | 02,876,814 | -H-- | M] () -- C:\Users\XXXX\AppData\Local\IconCache.db
[2010/01/11 23:03:07 | 00,001,079 | ---- | M] () -- C:\Users\XXXX\Desktop\Search Everything.lnk
[2010/01/11 23:02:54 | 00,341,811 | ---- | M] () -- C:\Users\XXXX\Desktop\Everything-1.2.1.371.exe
[2010/01/11 22:58:00 | 00,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1003UA.job
[2010/01/11 22:57:00 | 00,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1003Core.job
[2010/01/11 22:52:00 | 00,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/01/11 22:50:21 | 00,001,933 | ---- | M] () -- C:\Users\XXXX\Desktop\CCleaner.lnk
[2010/01/11 19:18:58 | 52,428,8000 | ---- | M] () -- C:\.fuse_hidden0000000200000001
[2010/01/11 18:44:27 | 00,001,555 | ---- | M] () -- C:\Users\XXXX\Desktop\procexp.exe - Shortcut.lnk
[2010/01/11 18:25:04 | 01,615,732 | ---- | M] () -- C:\Users\XXXX\Desktop\ProcessExplorer.zip
[2010/01/11 16:01:04 | 00,001,035 | ---- | M] () -- C:\Users\XXXX\Desktop\TextPad.lnk
[2010/01/10 22:22:00 | 00,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1000Core.job
[2010/01/10 21:24:41 | 00,143,387 | ---- | M] () -- C:\Windows\SysNative\drivers\klin.dat
[2010/01/10 21:24:41 | 00,104,987 | ---- | M] () -- C:\Windows\SysNative\drivers\klick.dat
[2010/01/10 21:23:48 | 00,353,296 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2010/01/10 21:22:02 | 02,972,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/01/10 18:01:57 | 03,168,344 | ---- | M] () -- C:\Users\XXXX\Desktop\Satellite_image_of_snow-covered_Great_Britain_on_7_January_2010.jpg
[2010/01/10 12:32:56 | 00,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/01/10 12:05:01 | 00,072,541 | ---- | M] () -- C:\Users\XXXX\Desktop\AVG_virus_vault_2010-01-10.gif
[2010/01/10 11:22:13 | 00,001,027 | ---- | M] () -- C:\Users\XXXX\Desktop\a-squared Free.lnk
[2010/01/10 11:22:02 | 00,001,075 | ---- | M] () -- C:\Users\XXXX\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 09:46:40 | 00,001,286 | ---- | M] () -- C:\Users\XXXX\Desktop\Control_Alt_A__batch_file.bat - Shortcut.lnk
[2010/01/10 09:46:30 | 00,001,286 | ---- | M] () -- C:\Users\XXXX\Desktop\Control_Alt_W__batch_file.bat - Shortcut.lnk
[2010/01/10 00:25:10 | 00,001,458 | ---- | M] () -- C:\Users\XXXX\Desktop\Internet Explorer (64-bit).lnk
[2010/01/10 00:01:25 | 00,000,948 | ---- | M] () -- C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\306313.lnk
[2010/01/10 00:00:21 | 00,089,752 | ---- | M] () -- C:\Users\XXXX\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/01/09 23:51:44 | 00,001,037 | ---- | M] () -- C:\Users\Public\Desktop\Xara Xtreme Pro 5.lnk
[2010/01/09 23:40:32 | 00,002,886 | ---- | M] () -- C:\Users\Public\Desktop\Mindjet MindManager 8.lnk
[2010/01/09 23:37:31 | 00,001,024 | ---- | M] () -- C:\Users\XXXX\Desktop\7-Zip File Manager.lnk
[2010/01/09 22:54:31 | 00,001,205 | ---- | M] () -- C:\Users\XXXX\Desktop\Adobe Dreamweaver CS4.lnk
[2010/01/09 16:43:49 | 03,451,056 | ---- | M] () -- C:\Users\XXXX\Desktop\U.S. Preventive Medicine Comprehensive Business Plan June 2008.PDF
[2010/01/09 14:02:22 | 00,001,181 | ---- | M] () -- C:\Users\XXXX\Desktop\Adobe Photoshop CS4.lnk
[2010/01/09 14:02:16 | 00,001,202 | ---- | M] () -- C:\Users\XXXX\Desktop\Adobe Photoshop CS4 (64 Bit).lnk
[2010/01/09 12:39:01 | 00,000,256 | ---- | M] () -- C:\Windows\SysWow64\pool.bin
[2010/01/09 12:27:30 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/01/09 12:09:27 | 00,000,224 | -H-- | M] () -- C:\ProgramData\{268EB95C-7C1C-4826-B79E-0E50B1A64C5A}.dss
[2010/01/09 00:32:58 | 00,002,558 | ---- | M] () -- C:\Users\XXXX\Documents\AMSS_Certificate_Export.pfx
[2010/01/08 22:40:13 | 00,001,920 | ---- | M] () -- C:\Users\XXXX\Desktop\SCANPST - Shortcut.lnk
[2010/01/08 22:17:29 | 00,002,675 | ---- | M] () -- C:\Users\XXXX\Desktop\Microsoft Office Word 2003.lnk
[2010/01/08 22:17:25 | 00,002,563 | ---- | M] () -- C:\Users\XXXX\Desktop\Microsoft Office Visio 2003.lnk
[2010/01/08 22:17:21 | 00,002,651 | ---- | M] () -- C:\Users\XXXX\Desktop\Microsoft Office Project 2003.lnk
[2010/01/08 22:17:16 | 00,002,645 | ---- | M] () -- C:\Users\XXXX\Desktop\Microsoft Office PowerPoint 2003.lnk
[2010/01/08 22:17:09 | 00,002,693 | ---- | M] () -- C:\Users\XXXX\Desktop\Microsoft Office Outlook 2003.lnk
[2010/01/08 22:17:05 | 00,002,677 | ---- | M] () -- C:\Users\XXXX\Desktop\Microsoft Office Excel 2003.lnk
[2010/01/08 22:11:19 | 00,000,039 | ---- | M] () -- C:\Windows\vbaddin.ini
[2010/01/08 22:10:38 | 00,000,499 | ---- | M] () -- C:\Windows\win.ini
[2010/01/08 21:52:34 | 00,000,376 | ---- | M] () -- C:\Windows\ODBC.INI
[2010/01/08 00:13:36 | 00,000,048 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2010/01/07 22:57:41 | 00,001,024 | ---- | M] () -- C:\.rnd
[2010/01/07 22:53:23 | 00,002,248 | ---- | M] () -- C:\Users\XXXX\Desktop\Google Chrome.lnk
[2010/01/07 22:25:53 | 00,524,288 | -HS- | M] () -- C:\Users\XXXX\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/01/07 22:25:53 | 00,524,288 | -HS- | M] () -- C:\Users\XXXX\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/01/07 22:25:53 | 00,065,536 | -HS- | M] () -- C:\Users\XXXX\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/01/07 22:25:53 | 00,000,020 | -HS- | M] () -- C:\Users\XXXX\ntuser.ini
[2010/01/07 22:19:19 | 00,001,988 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/01/07 21:16:20 | 00,002,677 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Keyboard.lnk
[2010/01/07 16:07:06 | 00,022,104 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010/01/05 10:13:42 | 00,040,833 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2010/01/05 10:13:42 | 00,040,833 | ---- | M] () -- C:\Windows\SysNative\license.rtf
========== Files Created - No Company Name ==========
[2010/01/11 23:33:08 | 00,353,485 | ---- | C] () -- C:\Users\XXXX\Desktop\HostsXpert.zip
[2010/01/11 23:03:07 | 00,001,079 | ---- | C] () -- C:\Users\XXXX\Desktop\Search Everything.lnk
[2010/01/11 23:02:47 | 00,341,811 | ---- | C] () -- C:\Users\XXXX\Desktop\Everything-1.2.1.371.exe
[2010/01/11 22:50:21 | 00,001,933 | ---- | C] () -- C:\Users\XXXX\Desktop\CCleaner.lnk
[2010/01/11 19:18:36 | 52,428,8000 | ---- | C] () -- C:\.fuse_hidden0000000200000001
[2010/01/11 18:44:27 | 00,001,555 | ---- | C] () -- C:\Users\XXXX\Desktop\procexp.exe - Shortcut.lnk
[2010/01/11 18:25:01 | 01,615,732 | ---- | C] () -- C:\Users\XXXX\Desktop\ProcessExplorer.zip
[2010/01/11 16:01:04 | 00,001,035 | ---- | C] () -- C:\Users\XXXX\Desktop\TextPad.lnk
[2010/01/10 21:24:41 | 00,143,387 | ---- | C] () -- C:\Windows\SysNative\drivers\klin.dat
[2010/01/10 21:24:41 | 00,104,987 | ---- | C] () -- C:\Windows\SysNative\drivers\klick.dat
[2010/01/10 18:01:57 | 03,168,344 | ---- | C] () -- C:\Users\XXXX\Desktop\Satellite_image_of_snow-covered_Great_Britain_on_7_January_2010.jpg
[2010/01/10 12:32:56 | 00,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/01/10 12:14:54 | 00,000,948 | ---- | C] () -- C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\306313.lnk
[2010/01/10 12:05:01 | 00,072,541 | ---- | C] () -- C:\Users\XXXX\Desktop\AVG_virus_vault_2010-01-10.gif
[2010/01/10 11:22:13 | 00,001,027 | ---- | C] () -- C:\Users\XXXX\Desktop\a-squared Free.lnk
[2010/01/10 11:22:02 | 00,001,075 | ---- | C] () -- C:\Users\XXXX\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 09:45:56 | 00,001,286 | ---- | C] () -- C:\Users\XXXX\Desktop\Control_Alt_A__batch_file.bat - Shortcut.lnk
[2010/01/10 09:45:51 | 00,001,286 | ---- | C] () -- C:\Users\XXXX\Desktop\Control_Alt_W__batch_file.bat - Shortcut.lnk
[2010/01/10 00:25:10 | 00,001,458 | ---- | C] () -- C:\Users\XXXX\Desktop\Internet Explorer (64-bit).lnk
[2010/01/09 23:40:32 | 00,002,886 | ---- | C] () -- C:\Users\Public\Desktop\Mindjet MindManager 8.lnk
[2010/01/09 23:37:31 | 00,001,024 | ---- | C] () -- C:\Users\XXXX\Desktop\7-Zip File Manager.lnk
[2010/01/09 22:54:31 | 00,001,205 | ---- | C] () -- C:\Users\XXXX\Desktop\Adobe Dreamweaver CS4.lnk
[2010/01/09 16:41:00 | 03,451,056 | ---- | C] () -- C:\Users\XXXX\Desktop\U.S. Preventive Medicine Comprehensive Business Plan June 2008.PDF
[2010/01/09 14:02:22 | 00,001,181 | ---- | C] () -- C:\Users\XXXX\Desktop\Adobe Photoshop CS4.lnk
[2010/01/09 14:02:16 | 00,001,202 | ---- | C] () -- C:\Users\XXXX\Desktop\Adobe Photoshop CS4 (64 Bit).lnk
[2010/01/09 12:27:30 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/01/09 12:24:04 | 00,000,256 | ---- | C] () -- C:\Windows\SysWow64\pool.bin
[2010/01/09 12:09:27 | 00,000,224 | -H-- | C] () -- C:\ProgramData\{268EB95C-7C1C-4826-B79E-0E50B1A64C5A}.dss
[2010/01/09 11:10:34 | 00,001,037 | ---- | C] () -- C:\Users\Public\Desktop\Xara Xtreme Pro 5.lnk
[2010/01/09 00:32:55 | 00,002,558 | ---- | C] () -- C:\Users\XXXX\Documents\AMSS_Certificate_Export.pfx
[2010/01/08 22:40:13 | 00,001,920 | ---- | C] () -- C:\Users\XXXX\Desktop\SCANPST - Shortcut.lnk
[2010/01/08 22:17:29 | 00,002,675 | ---- | C] () -- C:\Users\XXXX\Desktop\Microsoft Office Word 2003.lnk
[2010/01/08 22:17:25 | 00,002,563 | ---- | C] () -- C:\Users\XXXX\Desktop\Microsoft Office Visio 2003.lnk
[2010/01/08 22:17:21 | 00,002,651 | ---- | C] () -- C:\Users\XXXX\Desktop\Microsoft Office Project 2003.lnk
[2010/01/08 22:17:16 | 00,002,645 | ---- | C] () -- C:\Users\XXXX\Desktop\Microsoft Office PowerPoint 2003.lnk
[2010/01/08 22:17:09 | 00,002,693 | ---- | C] () -- C:\Users\XXXX\Desktop\Microsoft Office Outlook 2003.lnk
[2010/01/08 22:17:05 | 00,002,677 | ---- | C] () -- C:\Users\XXXX\Desktop\Microsoft Office Excel 2003.lnk
[2010/01/08 00:13:36 | 00,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/01/07 23:58:43 | 01,653,980 | ---- | C] () -- C:\Windows\SysNative\WacomTablet.znc
[2010/01/07 22:57:40 | 00,001,024 | ---- | C] () -- C:\.rnd
[2010/01/07 22:53:23 | 00,002,248 | ---- | C] () -- C:\Users\XXXX\Desktop\Google Chrome.lnk
[2010/01/07 22:53:00 | 00,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1003UA.job
[2010/01/07 22:52:59 | 00,000,852 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1003Core.job
[2010/01/07 22:47:57 | 00,000,892 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/01/07 22:47:56 | 00,000,888 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/01/07 22:45:20 | 00,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/01/07 22:25:53 | 00,524,288 | -HS- | C] () -- C:\Users\XXXX\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/01/07 22:25:53 | 00,524,288 | -HS- | C] () -- C:\Users\XXXX\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/01/07 22:25:53 | 00,065,536 | -HS- | C] () -- C:\Users\XXXX\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/01/07 22:25:53 | 00,000,020 | -HS- | C] () -- C:\Users\XXXX\ntuser.ini
[2010/01/07 22:25:52 | 02,359,296 | -HS- | C] () -- C:\Users\XXXX\NTUSER.DAT
[2010/01/07 22:19:19 | 00,001,988 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/01/07 22:17:08 | 00,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1000UA.job
[2010/01/07 22:17:07 | 00,000,856 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1371372046-1498751470-1065098117-1000Core.job
[2010/01/07 21:16:20 | 00,002,677 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Keyboard.lnk
[2010/01/05 11:05:53 | 00,001,904 | ---- | C] () -- C:\Windows\SysNative\SetupBD.din
[2010/01/05 11:05:27 | 00,003,127 | ---- | C] () -- C:\Windows\SysNative\e1k62x64.din
[2010/01/05 10:11:11 | 21,399,42911 | -HS- | C] () -- C:\hiberfil.sys
[2009/07/13 23:42:10 | 00,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 00,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/14 14:29:30 | 00,008,520 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2007/04/27 11:43:58 | 00,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\Windows\SysWow64\OUTLPERF.INI
========== LOP Check ==========
[2010/01/10 02:00:17 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\.oit
[2010/01/09 16:43:16 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Foxit
[2010/01/08 08:35:23 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Helios
[2010/01/09 09:34:12 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\MAGIX
[2010/01/08 08:24:15 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\PolyEdit Lite
[2010/01/09 17:27:55 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\TeamViewer
[2010/01/09 11:25:42 | 00,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Van Dyke Technologies
[2009/07/14 05:08:49 | 00,007,310 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >