MAIN OTL LOG…THANK YOU!!!!
OTL logfile created on: 5/14/2010 12:57:58 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 74.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.79 Gb Total Space | 12.45 Gb Free Space | 5.44% Space Free | Partition Type: NTFS
Drive D: | 4.09 Gb Total Space | 2.38 Gb Free Space | 58.28% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KATIE
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe (Belkin Corporation)
PRC - C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Pml Driver) – C:\WINDOWS\system32\hphipm09.exe (HP)
SRV - (Adobe Version Cue CS2) – C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Adobe Systems Incorporated)
========== Driver Services (SafeList) ==========
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (gqejw) – C:\WINDOWS\system32\drivers\syfwco.sys ()
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (NdisWDM) – C:\WINDOWS\system32\drivers\NdisWDM.sys (Broadcom Corporation)
DRV - (Dot4Storage HPH09) Storage Class Driver for IEEE-1284.4 (HPH09) – C:\WINDOWS\system32\drivers\hphs2k09.sys (Hewlett-Packard)
DRV - (Dot4Usb HPH09) – C:\WINDOWS\system32\drivers\hphius09.sys (HP)
DRV - (Dot4Print HPH09) – C:\WINDOWS\system32\drivers\hphipr09.sys (HP)
DRV - (Dot4 HPH09) – C:\WINDOWS\system32\drivers\hphid409.sys (HP)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)
DRV - (BLKWGU(Belkin)) Belkin Wireless G USB Network Adapter(Belkin) – C:\WINDOWS\system32\drivers\BLKWGU.sys (Belkin Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\system32\drivers\cdralw2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\system32\drivers\cdr4_xp.sys (Roxio)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://biblegateway.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2009/06/08 19:56:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2009/06/08 19:56:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/24 16:29:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/24 16:29:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.1.0.0\Extensions\\Components: C:\Program Files\\Netscape\\Netscape Browser\Components [2008/12/07 13:42:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.1.0.0\Extensions\\Plugins: C:\Program Files\\Netscape\\Netscape Browser\Plugins [2009/11/06 18:36:09 | 000,000,000 | —D | M]
[2010/02/04 16:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/01/28 16:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/05/12 15:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions
[2010/05/03 13:27:13 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/11/27 16:14:57 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2008/10/02 21:17:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions\[removed]
[2010/05/12 15:40:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/05/24 13:36:57 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/01/02 01:10:23 | 000,159,744 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2004/08/10 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {6F45AEA2-9C81-4832-8390-7134102B8DE5} - C:\Program Files\WeatherStudio Desktop\bin\WeatherStudio Desktop.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\system32\bae.dll (Gateway Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe (Belkin Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: camperconnection.net ([]* in Trusted sites)
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE}
http://www.ritzpix.com/net/Uploader/LPUploader45.cab (Image Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab (YInstStarter Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5}
https://actsvr.comcastonline.com/techtools/…%20Controls.cab (SupportSoft External Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab (GameHouse Games Player)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8}
http://knoxville.yourhub.com/YourHub/ImageUploader3.cab (Aurigma Image Uploader 3.5 Control)
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197}
http://www.berkeley.edu/webcams/camera.cab (Cameractl Class)
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F}
http://www.ritzpix.com/net/Uploader/LPUploader57.cab (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://technologyondemand.webex.com/client…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.16.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/09 21:13:09 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\AutoRun\command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\Shell00\Command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\Shell01\Command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\Shell02\Command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{7855b9a1-9814-11da-9eba-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7855b9a1-9814-11da-9eba-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{871e1fdf-fdc0-11dc-a53a-0015581f7a49}\Shell\AutoRun\command - "" = K:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{a3862743-c727-11dd-a574-0015581f7a49}\Shell\AutoRun\command - "" = K:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{b3053969-9822-11da-b84e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b3053969-9822-11da-b84e-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c89802f5-d71c-11da-a480-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{c89802f5-d71c-11da-a480-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e16a983d-c7a4-11dd-a578-0015581f7a49}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e16a983d-c7a4-11dd-a578-0015581f7a49}\Shell\AutoRun\command - "" = L:\autorun.exe – File not found
O33 - MountPoints2\{e16a983d-c7a4-11dd-a578-0015581f7a49}\Shell\phone\command - "" = L:\autorun.exe – File not found
O33 - MountPoints2\{f23e23e2-0bc2-11db-a499-0015581f7a49}\Shell\AutoRun\command - "" = K:\setupSNK.exe – File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/01/09 21:12:02 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.
========== Files/Folders - Created Within 30 Days ==========
[2010/05/14 12:43:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\desktopjunk
[2010/05/14 12:18:01 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/12 14:32:03 | 000,640,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTS.exe
[2010/05/11 20:12:53 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/04/29 11:06:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\eskbackup
[2010/04/28 16:37:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\U3
[2010/04/22 12:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Google
[2010/04/22 12:05:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\aayqfpbnl
[2010/04/22 12:05:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\umqrfnmkr
[2010/04/20 17:14:37 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/04/20 16:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/04/20 16:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/04/20 16:04:11 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/04/20 16:04:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2010/04/20 16:03:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2010/04/18 12:46:01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Malwarebytes
[2010/04/17 17:45:45 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/17 17:45:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/17 16:09:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2010/04/17 16:09:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/17 16:09:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/17 14:33:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/17 14:33:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/04/17 13:01:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/14 12:59:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/14 12:42:01 | 000,000,650 | —- | M] () – C:\WINDOWS\win.ini
[2010/05/14 12:42:01 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/05/14 12:42:01 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2010/05/14 12:41:53 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/05/14 12:41:52 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/14 12:40:48 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/14 12:40:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/14 12:40:46 | 2011,746,304 | -HS- | M] () – C:\hiberfil.sys
[2010/05/14 12:21:01 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006UA.job
[2010/05/14 12:18:02 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/13 16:37:00 | 000,448,869 | —- | M] () – C:\Documents and Settings\Owner\Desktop\amanda.jpg
[2010/05/13 16:35:59 | 000,029,363 | —- | M] () – C:\Documents and Settings\Owner\Desktop\4565864025_e3cabd78e3_o.jpg
[2010/05/13 15:21:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006Core.job
[2010/05/12 14:52:12 | 016,252,928 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/05/12 14:32:04 | 000,640,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTS.exe
[2010/05/12 13:43:50 | 000,002,447 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/05/11 22:12:21 | 000,004,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpcdd.sys
[2010/05/11 18:17:18 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/05/11 17:55:40 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\syfwco.sys
[2010/05/11 16:48:42 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/11 16:19:13 | 000,012,552 | —- | M] () – C:\Documents and Settings\Owner\My Documents\sjcmeeting_51110.pdf
[2010/05/11 16:18:15 | 000,040,960 | —- | M] () – C:\Documents and Settings\Owner\My Documents\sjc_562010.doc
[2010/05/11 15:43:00 | 000,051,058 | —- | M] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.pdf
[2010/05/11 15:26:00 | 000,165,121 | —- | M] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.xls
[2010/05/11 13:31:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/08 16:13:06 | 000,037,888 | —- | M] () – C:\Documents and Settings\Owner\My Documents\journal4302010.doc
[2010/05/06 15:21:52 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$Bee.doc
[2010/05/06 15:21:39 | 000,136,192 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Bee.doc
[2010/04/30 14:34:45 | 000,028,160 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray_critical incident.doc
[2010/04/30 14:32:43 | 000,029,184 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray learning autobio.doc
[2010/04/30 14:32:00 | 000,376,320 | —- | M] () – C:\Documents and Settings\Owner\My Documents\reading record.xls
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/29 05:21:25 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2010/04/28 13:30:02 | 000,031,232 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Journal.doc
[2010/04/26 20:57:03 | 002,544,759 | —- | M] () – C:\Documents and Settings\Owner\My Documents\record-march-2010.pdf
[2010/04/26 14:27:39 | 000,034,304 | —- | M] () – C:\Documents and Settings\Owner\My Documents\There is no safety in man.doc
[2010/04/22 12:03:59 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/20 18:27:33 | 000,014,858 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\2fOFu
[2010/04/20 18:27:32 | 000,014,858 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2fOFu
[2010/04/20 16:58:15 | 000,015,350 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\p63586CeJQo2
[2010/04/20 16:58:15 | 000,015,350 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\p63586CeJQo2
[2010/04/20 16:04:16 | 000,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Professional.lnk
[2010/04/20 16:03:12 | 007,899,168 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SUPERAntiSpywarePro.exe
[2010/04/17 20:40:30 | 000,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Proposal for SJC.doc
[2010/04/17 17:45:48 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/17 17:06:01 | 000,017,274 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\JH40y5L
[2010/04/17 17:06:01 | 000,017,274 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\664514575
[2010/04/17 17:05:57 | 000,016,074 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\JH40y5L
[2010/04/17 16:58:16 | 000,019,022 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\664514575
[2010/04/17 16:58:16 | 000,019,022 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\2604077421
[2010/04/17 16:58:10 | 000,019,160 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2604077421
[2010/04/17 15:50:18 | 000,000,319 | —- | M] () – C:\Documents and Settings\Owner\Desktop\trojan_fakerean_exe_fix.reg
[2010/04/17 15:23:08 | 000,012,772 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\7UGM6
[2010/04/17 15:23:08 | 000,012,772 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\7UGM6
[2010/04/17 15:22:27 | 000,001,130 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\uk267W7
[2010/04/17 15:22:26 | 000,001,130 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uk267W7
[2010/04/17 14:49:29 | 000,012,590 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1917792730
[2010/04/17 14:49:28 | 000,012,590 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\1917792730
[2010/04/17 14:47:16 | 000,012,606 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2254186452
[2010/04/17 14:47:16 | 000,012,606 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\2254186452
[2010/04/17 14:18:27 | 000,028,160 | —- | M] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.doc
[2010/04/17 14:10:55 | 000,000,100 | –S- | M] () – C:\WINDOWS\System32\1324528605.dat
[2010/04/16 13:38:03 | 000,052,808 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_norrell_41610.pdf
[2010/04/16 13:36:50 | 000,057,856 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover3.doc
[2010/04/15 18:06:12 | 000,007,408 | —- | M] () – C:\Documents and Settings\Owner\My Documents\norrell_references.pdf
[2010/04/15 17:55:55 | 000,046,505 | —- | M] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_utathletics.pdf
[2010/04/15 17:55:22 | 000,058,368 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover2.doc
[2010/04/15 17:14:33 | 000,052,696 | —- | M] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_41510.pdf
[2010/04/15 17:13:24 | 000,007,857 | —- | M] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.pdf
[2010/04/15 11:24:01 | 000,048,128 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover.doc
[2010/04/15 10:53:46 | 000,050,176 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.doc
[2010/04/15 00:04:42 | 000,043,986 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.pdf
[2010/04/14 14:58:15 | 000,036,264 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Resume_KNorrell_talentsphere.pdf
[2010/04/14 14:57:11 | 000,079,945 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_knorrell.pdf
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/14 12:29:47 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2010/05/13 16:36:59 | 000,448,869 | —- | C] () – C:\Documents and Settings\Owner\Desktop\amanda.jpg
[2010/05/13 16:35:59 | 000,029,363 | —- | C] () – C:\Documents and Settings\Owner\Desktop\4565864025_e3cabd78e3_o.jpg
[2010/05/11 20:12:54 | 000,002,447 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/05/11 18:13:30 | 2011,746,304 | -HS- | C] () – C:\hiberfil.sys
[2010/05/11 17:55:40 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\syfwco.sys
[2010/05/11 16:19:13 | 000,012,552 | —- | C] () – C:\Documents and Settings\Owner\My Documents\sjcmeeting_51110.pdf
[2010/05/11 15:43:00 | 000,051,058 | —- | C] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.pdf
[2010/05/11 15:28:12 | 000,165,121 | —- | C] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.xls
[2010/05/06 15:21:52 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$Bee.doc
[2010/05/06 15:21:38 | 000,136,192 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Bee.doc
[2010/05/06 13:38:35 | 000,040,960 | —- | C] () – C:\Documents and Settings\Owner\My Documents\sjc_562010.doc
[2010/04/30 14:34:45 | 000,028,160 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray_critical incident.doc
[2010/04/30 14:32:43 | 000,029,184 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray learning autobio.doc
[2010/04/30 14:32:00 | 000,376,320 | —- | C] () – C:\Documents and Settings\Owner\My Documents\reading record.xls
[2010/04/30 11:57:52 | 000,037,888 | —- | C] () – C:\Documents and Settings\Owner\My Documents\journal4302010.doc
[2010/04/28 12:19:29 | 000,031,232 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Journal.doc
[2010/04/26 20:57:02 | 002,544,759 | —- | C] () – C:\Documents and Settings\Owner\My Documents\record-march-2010.pdf
[2010/04/25 22:02:46 | 000,034,304 | —- | C] () – C:\Documents and Settings\Owner\My Documents\There is no safety in man.doc
[2010/04/20 18:08:50 | 000,014,858 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2fOFu
[2010/04/20 18:08:50 | 000,014,858 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2fOFu
[2010/04/20 17:34:25 | 000,002,600 | —- | C] () – C:\Documents and Settings\Owner\Desktop\xp_exe_fix.reg
[2010/04/20 16:04:16 | 000,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Professional.lnk
[2010/04/20 16:02:58 | 007,899,168 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SUPERAntiSpywarePro.exe
[2010/04/20 15:18:01 | 000,002,284 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2010/04/20 15:16:43 | 000,000,978 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006UA.job
[2010/04/20 15:16:42 | 000,000,926 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006Core.job
[2010/04/20 14:44:05 | 000,000,335 | —- | C] () – C:\Documents and Settings\Owner\Desktop\FixExe.reg
[2010/04/20 14:11:24 | 000,000,319 | —- | C] () – C:\Documents and Settings\Owner\Desktop\trojan_fakerean_exe_fix.reg
[2010/04/20 14:04:57 | 000,015,350 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\p63586CeJQo2
[2010/04/20 14:02:17 | 000,015,350 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\p63586CeJQo2
[2010/04/20 14:02:17 | 000,010,376 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\p63586CeJQo2
[2010/04/17 20:40:30 | 000,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Proposal for SJC.doc
[2010/04/17 17:45:48 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/17 16:55:58 | 000,019,160 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2604077421
[2010/04/17 16:55:58 | 000,019,022 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\664514575
[2010/04/17 16:55:58 | 000,019,022 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2604077421
[2010/04/17 16:55:54 | 000,017,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\JH40y5L
[2010/04/17 16:55:54 | 000,017,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\664514575
[2010/04/17 16:55:53 | 000,016,074 | -HS- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\JH40y5L
[2010/04/17 16:53:17 | 000,016,074 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\JH40y5L
[2010/04/17 16:53:17 | 000,007,748 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\JH40y5L
[2010/04/17 15:22:21 | 000,001,130 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uk267W7
[2010/04/17 15:22:21 | 000,001,130 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\uk267W7
[2010/04/17 14:44:58 | 000,012,590 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\1917792730
[2010/04/17 14:43:53 | 000,012,606 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2254186452
[2010/04/17 14:43:53 | 000,012,590 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1917792730
[2010/04/17 14:43:34 | 000,012,772 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\7UGM6
[2010/04/17 14:43:34 | 000,012,606 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2254186452
[2010/04/17 14:34:04 | 000,012,772 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\7UGM6
[2010/04/17 14:34:04 | 000,012,598 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\7UGM6
[2010/04/17 14:33:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/16 13:37:39 | 000,052,808 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_norrell_41610.pdf
[2010/04/16 13:36:30 | 000,057,856 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover3.doc
[2010/04/15 18:06:12 | 000,007,408 | —- | C] () – C:\Documents and Settings\Owner\My Documents\norrell_references.pdf
[2010/04/15 17:55:55 | 000,046,505 | —- | C] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_utathletics.pdf
[2010/04/15 17:28:52 | 000,058,368 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover2.doc
[2010/04/15 17:13:24 | 000,007,857 | —- | C] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.pdf
[2010/04/15 16:48:56 | 000,028,160 | —- | C] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.doc
[2010/04/15 11:24:18 | 000,052,696 | —- | C] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_41510.pdf
[2010/04/15 10:50:19 | 000,048,128 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover.doc
[2010/04/15 00:04:42 | 000,043,986 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.pdf
[2010/04/14 15:00:11 | 000,050,176 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.doc
[2010/04/14 14:58:15 | 000,036,264 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Resume_KNorrell_talentsphere.pdf
[2010/04/14 14:57:10 | 000,079,945 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_knorrell.pdf
[2008/12/10 23:20:03 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/12/10 21:59:17 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/12/10 21:59:16 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/12/07 14:43:38 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2008/12/07 14:43:24 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/12/07 13:58:11 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2008/06/10 15:03:04 | 000,166,912 | —- | C] () – C:\WINDOWS\System32\Lame_enc.dll
[2008/04/24 21:05:21 | 000,036,291 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2006/12/24 21:26:49 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/08/15 21:14:28 | 000,000,126 | R— | C] () – C:\WINDOWS\hpw9600k.ini
[2006/08/15 21:06:55 | 000,014,973 | —- | C] () – C:\WINDOWS\hpdj9600.ini
[2006/05/23 13:00:57 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2006/02/07 16:11:31 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/07 15:51:54 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/02/07 15:51:54 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/02/07 15:51:53 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/02/07 15:51:51 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/02/07 15:51:51 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/02/07 15:51:51 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/02/07 15:51:49 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/08/06 01:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2005/06/11 11:47:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\fpprintmon.dll
[2005/01/12 13:38:00 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/09 19:49:16 | 000,001,220 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/01/09 19:49:16 | 000,000,491 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/12/20 11:08:28 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 11:03:26 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/01/07 19:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2008/07/04 10:43:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2009/02/02 22:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/02/16 00:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2006/12/24 21:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/12/01 20:22:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Smilebox
[2008/12/01 20:19:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/06/10 15:25:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/06/12 21:53:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/02/05 23:24:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeatherStudio Desktop
[2008/02/04 14:36:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeatherStudio348
[2008/12/07 13:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/05/12 23:01:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Alien Skin
[2009/04/01 18:32:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Artisteer
[2008/10/31 20:36:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2009/05/31 16:30:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.ExMan
[2009/06/08 19:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eMusic
[2010/05/14 12:20:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FileZilla
[2009/01/28 16:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flickr
[2006/06/02 21:31:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2009/12/31 15:07:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/08/10 17:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2008/10/16 23:28:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LimeWire
[2008/12/13 12:51:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mjusbsp
[2006/04/28 21:23:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2006/05/24 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Netscape
[2006/05/08 12:37:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2006/12/24 21:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\RhinoSoft.com
[2006/02/07 16:32:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2006/10/05 20:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Smilebox
[2006/12/15 22:13:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2006/05/07 00:19:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/02/10 12:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2008/05/25 00:19:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso
[2008/02/05 23:24:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherStudio Desktop
[2009/05/19 14:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\webex
[2009/12/31 15:09:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Xilisoft Corporation
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2004/08/04 10:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\drivers\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004/08/04 09:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004/08/10 15:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2004/08/10 15:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/10 15:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2005/07/26 00:39:44 | 001,267,200 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/01/09 12:58:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/01/09 12:58:49 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/01/09 12:58:49 | 000,868,352 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F
< End of report >