O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:
64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:
64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:
64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:
64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\NLAapi.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\napinsp.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220
O18:
64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\msvidctl.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\msvidctl.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\SysNative\shell32.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\SysNative\sysdm.cpl (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\SysWow64\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\SysWow64\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\FastAccess: DllName - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysNative\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O22:
64bit: - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysNative\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Bob\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Bob\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29:
64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:
64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 23:01:00 | 000,000,053 | -HS- | M] () - E:\AUTORUN.INF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/05/16 20:38:28 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\Bob\Desktop\ATF-Cleaner.exe
[2010/05/14 13:55:29 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\HpUpdate
[2010/05/13 12:11:37 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Sports Interactive
[2010/05/10 11:58:36 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Printer Info Cache
[2010/05/10 11:58:35 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Image Zone Express
[2010/05/09 19:09:09 | 000,000,000 | ---D | C] -- C:\Users\Bob\Tracing
[2010/05/09 19:05:05 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\skypePM
[2010/05/09 19:03:29 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Skype
[2010/05/09 01:18:22 | 000,000,000 | -HSD | C] -- C:\found.000
[2010/05/08 22:33:53 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Research In Motion
[2010/05/08 21:56:11 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Adobe
[2010/05/08 20:50:49 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\Mozilla
[2010/05/08 20:50:37 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Apple Computer
[2010/05/08 19:03:59 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/05/08 19:02:42 | 000,518,656 | ---- | C] (OldTimer Tools) -- C:\Users\Bob\Desktop\OTM.exe
[2010/05/07 14:01:49 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Users\Bob\Desktop\OTL.exe
[2010/05/07 13:53:12 | 000,000,000 | ---D | C] -- C:\Users\Bob\Desktop\backups
[2010/05/06 17:30:14 | 001,050,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjet35.dll
[2010/05/06 17:30:14 | 000,024,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSJTER35.DLL
[2010/05/06 17:30:13 | 000,415,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrepl35.dll
[2010/05/06 17:30:13 | 000,397,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSRDO20.DLL
[2010/05/06 17:30:13 | 000,260,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSFLXGRD.ocx
[2010/05/06 17:30:13 | 000,252,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSRD2X35.DLL
[2010/05/06 17:30:13 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMAPI32.ocx
[2010/05/06 17:30:13 | 000,123,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSJINT35.DLL
[2010/05/06 17:30:13 | 000,089,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VB5DB.DLL
[2010/05/06 17:30:12 | 000,000,000 | ---D | C] -- C:\TeamsScorer
[2010/05/01 12:40:47 | 000,126,312 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\GEARAspi64.dll
[2010/05/01 12:40:47 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysWow64\GEARAspi.dll
[2010/05/01 12:40:47 | 000,034,152 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/05/01 12:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/01 12:39:55 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/01 12:39:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2010/05/01 12:39:55 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010/05/01 12:34:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010/05/01 12:29:41 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/05/01 12:29:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2010/04/27 10:01:43 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Bob\Desktop\HiJackThis.exe
[2010/04/27 09:20:05 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\Stardock_Corporation
[2010/04/27 09:17:51 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\Broadcom
[2010/04/27 09:17:51 | 000,000,000 | ---D | C] -- C:\Users\Bob\Documents\Bluetooth Exchange Folder
[2010/04/24 23:18:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2010/04/20 01:20:02 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Malwarebytes
[2010/04/18 22:48:25 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Documents\My Videos
[2010/04/18 22:48:25 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Documents\My Pictures
[2010/04/18 22:48:25 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Documents\My Music
[2010/04/18 22:35:21 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Dell
[2010/04/18 22:34:32 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\HP
[2010/04/18 22:33:17 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Mozilla
[2010/04/18 22:33:15 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\PowerDVD DX
[2010/04/18 22:33:14 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\SupportSoft
[2010/04/18 22:32:59 | 000,000,000 | R--D | C] -- C:\Users\Bob\Searches
[2010/04/18 22:32:45 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Identities
[2010/04/18 22:32:40 | 000,000,000 | R--D | C] -- C:\Users\Bob\Contacts
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\AppData\Local\Temporary Internet Files
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Templates
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Start Menu
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\SendTo
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Recent
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\PrintHood
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\NetHood
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\My Documents
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Local Settings
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\AppData\Local\History
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Cookies
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\Application Data
[2010/04/18 22:32:20 | 000,000,000 | -HSD | C] -- C:\Users\Bob\AppData\Local\Application Data
[2010/04/18 22:32:18 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\Temp
[2010/04/18 22:32:18 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Local\Microsoft
[2010/04/18 22:32:18 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Media Center Programs
[2010/04/18 22:32:18 | 000,000,000 | ---D | C] -- C:\Users\Bob\AppData\Roaming\Macromedia
[2010/04/18 22:32:17 | 000,000,000 | --SD | C] -- C:\Users\Bob\AppData\Roaming\Microsoft
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Videos
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Saved Games
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Pictures
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Music
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Links
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Favorites
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Downloads
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Documents
[2010/04/18 22:32:17 | 000,000,000 | R--D | C] -- C:\Users\Bob\Desktop
[2010/04/18 22:32:17 | 000,000,000 | -H-D | C] -- C:\Users\Bob\AppData
[2010/04/17 07:27:39 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Profiles
[2010/04/17 07:22:50 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
========== Files - Modified Within 30 Days ========== [2010/05/16 22:12:13 | 001,572,864 | -HS- | M] () -- C:\Users\Bob\NTUSER.DAT
[2010/05/16 22:09:22 | 000,001,737 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2010/05/16 22:07:19 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/16 22:07:16 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/16 22:07:16 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/16 22:07:13 | 000,524,288 | -HS- | M] () -- C:\Users\Bob\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/05/16 22:07:13 | 000,065,536 | -HS- | M] () -- C:\Users\Bob\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/05/16 22:07:07 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/05/16 22:07:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/05/16 22:06:59 | 4291,145,728 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/16 22:05:56 | 000,002,140 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/05/16 22:05:37 | 002,301,954 | -H-- | M] () -- C:\Users\Bob\AppData\Local\IconCache.db
[2010/05/16 22:04:38 | 000,152,064 | ---- | M] () -- C:\Users\Bob\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/16 22:03:49 | 000,789,862 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/16 22:03:49 | 000,668,418 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/05/16 22:03:49 | 000,133,614 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/05/16 21:48:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/16 20:38:28 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\Bob\Desktop\ATF-Cleaner.exe
[2010/05/16 17:20:54 | 000,036,864 | ---- | M] () -- C:\Users\Bob\Desktop\application formDOC.DOC
[2010/05/16 15:37:53 | 478,933,091 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/05/16 15:14:04 | 000,000,162 | -H-- | M] () -- C:\Users\Bob\Desktop\~$plication formDOC.DOC
[2010/05/16 15:13:53 | 000,000,162 | -H-- | M] () -- C:\Users\Bob\Desktop\~$B Instructions.doc
[2010/05/16 15:13:17 | 000,045,568 | ---- | M] () -- C:\Users\Bob\Desktop\CRB Instructions.doc
[2010/05/15 22:54:03 | 000,000,680 | ---- | M] () -- C:\Users\Bob\AppData\Local\d3d9caps.dat
[2010/05/15 22:03:57 | 000,002,337 | ---- | M] () -- C:\Users\Bob\Desktop\Steam.lnk
[2010/05/14 14:25:28 | 366,434,194 | ---- | M] () -- C:\Users\Bob\Desktop\CSI.S10E22.HDTV.XviD-LOL.avi
[2010/05/14 11:26:20 | 000,032,768 | ---- | M] () -- C:\Users\Bob\Desktop\DL.doc
[2010/05/13 12:09:51 | 000,001,050 | ---- | M] () -- C:\Users\Bob\Desktop\FMRTE.lnk
[2010/05/08 22:55:31 | 000,001,798 | ---- | M] () -- C:\Users\Bob\Desktop\Mozilla Firefox.lnk
[2010/05/08 20:31:12 | 000,001,499 | ---- | M] () -- C:\Users\Bob\Desktop\fix.reg
[2010/05/08 19:40:23 | 000,002,651 | ---- | M] () -- C:\Users\Bob\Desktop\Microsoft Office Word 2007.lnk
[2010/05/08 19:02:52 | 000,518,656 | ---- | M] (OldTimer Tools) -- C:\Users\Bob\Desktop\OTM.exe
[2010/05/08 17:22:28 | 000,154,469 | ---- | M] () -- C:\Users\Bob\Desktop\tdsskiller.zip
[2010/05/08 16:22:33 | 000,000,574 | ---- | M] () -- C:\cleanup.bat
[2010/05/08 16:22:32 | 000,135,168 | ---- | M] () -- C:\zip.exe
[2010/05/08 16:22:32 | 000,061,440 | ---- | M] () -- C:\Windows\SysWow64\drivers\qugipz.sys
[2010/05/08 15:28:14 | 000,724,952 | ---- | M] () -- C:\Users\Bob\Desktop\avenger.zip
[2010/05/07 14:02:11 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\Bob\Desktop\OTL.exe
[2010/05/06 18:59:01 | 000,393,089 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2010/05/06 10:50:21 | 000,344,288 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/04/27 17:16:24 | 000,528,616 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfehidk.sys
[2010/04/27 17:16:24 | 000,440,688 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfefirek.sys
[2010/04/27 17:16:24 | 000,279,752 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfewfpk.sys
[2010/04/27 17:16:24 | 000,189,880 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeavfk.sys
[2010/04/27 17:16:24 | 000,121,504 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeapfk.sys
[2010/04/27 17:16:24 | 000,093,840 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mferkdet.sys
[2010/04/27 17:16:24 | 000,075,288 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfenlfk.sys
[2010/04/27 17:16:24 | 000,062,416 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\cfwids.sys
[2010/04/27 17:16:24 | 000,009,984 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeclnk.sys
[2010/04/27 10:01:48 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Bob\Desktop\HiJackThis.exe
[2010/04/27 10:00:46 | 000,392,729 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20100506-185901.backup
[2010/04/27 09:13:47 | 000,000,950 | ---- | M] () -- C:\Users\Bob\Desktop\MBAM.lnk
[2010/04/24 18:13:52 | 000,020,480 | ---- | M] () -- C:\Users\Bob\Desktop\University Money.xls
[2010/04/19 11:03:10 | 366,446,592 | ---- | M] () -- C:\Users\Bob\Desktop\tpz-ncis420.avi
[2010/04/19 10:50:44 | 366,798,848 | ---- | M] () -- C:\Users\Bob\Desktop\tpz-ncis419.avi
[2010/04/19 10:39:11 | 367,060,992 | ---- | M] () -- C:\Users\Bob\Desktop\tpz-ncis418.avi
[2010/04/19 10:25:32 | 366,520,320 | ---- | M] () -- C:\Users\Bob\Desktop\tpz-ncis417.avi
[2010/04/18 22:48:20 | 000,524,288 | -HS- | M] () -- C:\Users\Bob\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000002.regtrans-ms
[2010/04/18 22:34:15 | 000,086,600 | ---- | M] () -- C:\Users\Bob\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/18 22:32:21 | 000,000,020 | -HS- | M] () -- C:\Users\Bob\ntuser.ini
[2010/04/16 22:30:00 | 367,077,376 | ---- | M] () -- C:\Users\Bob\Desktop\tpz-ncis416.avi
========== Files Created - No Company Name ========== [2010/05/16 22:02:15 | 366,446,592 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis420.avi
[2010/05/16 22:02:03 | 366,798,848 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis419.avi
[2010/05/16 22:01:52 | 367,060,992 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis418.avi
[2010/05/16 22:01:40 | 366,520,320 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis417.avi
[2010/05/16 22:01:27 | 367,077,376 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis416.avi
[2010/05/16 15:14:04 | 000,000,162 | -H-- | C] () -- C:\Users\Bob\Desktop\~$plication formDOC.DOC
[2010/05/16 15:13:53 | 000,000,162 | -H-- | C] () -- C:\Users\Bob\Desktop\~$B Instructions.doc
[2010/05/16 15:13:10 | 000,045,568 | ---- | C] () -- C:\Users\Bob\Desktop\CRB Instructions.doc
[2010/05/16 15:13:06 | 000,036,864 | ---- | C] () -- C:\Users\Bob\Desktop\application formDOC.DOC
[2010/05/14 13:32:06 | 366,434,194 | ---- | C] () -- C:\Users\Bob\Desktop\CSI.S10E22.HDTV.XviD-LOL.avi
[2010/05/14 00:03:11 | 367,071,232 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis415.avi
[2010/05/14 00:02:55 | 367,104,000 | ---- | C] () -- C:\Users\Bob\Desktop\tpz-ncis414.avi
[2010/05/13 12:09:51 | 000,001,050 | ---- | C] () -- C:\Users\Bob\Desktop\FMRTE.lnk
[2010/05/09 23:03:14 | 000,000,680 | ---- | C] () -- C:\Users\Bob\AppData\Local\d3d9caps.dat
[2010/05/08 22:55:31 | 000,001,798 | ---- | C] () -- C:\Users\Bob\Desktop\Mozilla Firefox.lnk
[2010/05/08 20:31:09 | 000,001,499 | ---- | C] () -- C:\Users\Bob\Desktop\fix.reg
[2010/05/08 17:22:25 | 000,154,469 | ---- | C] () -- C:\Users\Bob\Desktop\tdsskiller.zip
[2010/05/08 16:22:32 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\qugipz.sys
[2010/05/08 16:22:32 | 000,001,046 | ---- | C] () -- C:\Program Files (x86)\mnagotzg.txt
[2010/05/08 15:30:59 | 000,135,168 | ---- | C] () -- C:\zip.exe
[2010/05/08 15:30:59 | 000,000,574 | ---- | C] () -- C:\cleanup.bat
[2010/05/08 15:28:03 | 000,724,952 | ---- | C] () -- C:\Users\Bob\Desktop\avenger.zip
[2010/04/27 09:13:47 | 000,000,950 | ---- | C] () -- C:\Users\Bob\Desktop\MBAM.lnk
[2010/04/19 22:35:56 | 000,001,737 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2010/04/18 22:35:49 | 000,152,064 | ---- | C] () -- C:\Users\Bob\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/18 22:32:21 | 000,000,020 | -HS- | C] () -- C:\Users\Bob\ntuser.ini
[2010/04/18 22:32:20 | 000,524,288 | -HS- | C] () -- C:\Users\Bob\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000002.regtrans-ms
[2010/04/18 22:32:19 | 000,524,288 | -HS- | C] () -- C:\Users\Bob\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/04/18 22:32:19 | 000,262,144 | -H-- | C] () -- C:\Users\Bob\ntuser.dat.LOG1
[2010/04/18 22:32:19 | 000,065,536 | -HS- | C] () -- C:\Users\Bob\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/04/18 22:32:19 | 000,000,000 | -H-- | C] () -- C:\Users\Bob\ntuser.dat.LOG2
[2010/04/18 22:32:17 | 001,572,864 | -HS- | C] () -- C:\Users\Bob\NTUSER.DAT
[2010/01/22 03:40:17 | 000,735,582 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/12/21 23:23:46 | 000,000,074 | ---- | C] () -- C:\Windows\MPLAYER.INI
[2009/12/04 16:16:07 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/04 16:14:53 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/16 11:39:05 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.INI
[2009/10/23 18:15:04 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
[2009/09/16 11:53:26 | 000,164,352 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009/09/16 11:53:23 | 000,755,027 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009/09/16 11:53:23 | 000,159,839 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/09/16 11:53:22 | 003,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2009/09/16 11:53:21 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009/09/16 11:53:21 | 000,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/06/24 22:32:34 | 000,089,352 | ---- | C] () -- C:\Windows\SysWow64\FAIEExtension.dll
[2009/06/24 22:31:46 | 000,059,144 | ---- | C] () -- C:\Windows\SysWow64\FAib.dll
[2009/06/24 22:31:00 | 000,234,760 | ---- | C] () -- C:\Windows\SysWow64\FACrashRpt.dll
[2008/01/21 03:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
========== LOP Check ========== [2010/05/12 10:42:03 | 000,000,000 | ---D | M] -- C:\Users\Bob\AppData\Roaming\Image Zone Express
[2010/05/10 11:58:50 | 000,000,000 | ---D | M] -- C:\Users\Bob\AppData\Roaming\Printer Info Cache
[2010/05/08 22:33:53 | 000,000,000 | ---D | M] -- C:\Users\Bob\AppData\Roaming\Research In Motion
[2010/05/13 12:11:37 | 000,000,000 | ---D | M] -- C:\Users\Bob\AppData\Roaming\Sports Interactive
[2010/05/16 22:05:58 | 000,032,596 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 76 bytes -> C:\Users\Bob\Documents\the_unit_phone ring.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Bob\Documents\24-ring-tone-4.mp3:Roxio EMC Stream
< End of report >