drishi8
Topic Starter
Sorry, I wasn't able to get back to you because my battery power cord broke and I had to order a new one. I got a new cord. I had downloaded OTL.exe and ran it.
Below are the results of the scan.
OTL logfile created on: 5/19/2010 10:55:12 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Audra Drish\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 123.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.18 Gb Free Space | 5.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: AUDRA
Current User Name: Audra Drish
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Audra Drish\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Audra Drish\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\asOEHook.dll (Symantec Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\Microsoft.VC90.CRT\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\Microsoft.VC90.CRT\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (N360) – C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe (Symantec Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
SRV - (CFSvcs) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AOL TopSpeedMonitor) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100522.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100522.003\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100429.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0401000.020\Ironx86.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0401000.020\ccHPx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMDS.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100513.002\IDSXpx86.sys (Symantec Corporation)
DRV - (SAMFILT) – C:\WINDOWS\system32\drivers\samfilt.sys (Dolphin, Inc.)
DRV - (tbiosdrv) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TVALZ) – C:\WINDOWS\system32\DRIVERS\TVALZ.SYS (TOSHIBA Corporation)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.iastate.edu/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: [removed]:1.03.01
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/04/26 20:49:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/04/21 00:51:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/31 21:16:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/31 15:46:21 | 000,000,000 | —D | M]
[2008/11/11 17:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Extensions
[2010/05/18 08:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions
[2009/08/10 16:51:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/28 15:50:55 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/07 23:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\[removed]
[2009/08/15 21:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\[removed]
[2010/04/20 19:38:39 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.1.0.32\IPSBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [000StTHK] C:\WINDOWS\System32\000StTHK.exe ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe File not found
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CFSServ.exe] File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe File not found
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TFNF5] C:\WINDOWS\System32\TFNF5.exe (TOSHIBA Corp.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPSODDCtl] C:\WINDOWS\System32\TPSODDCtl.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Norton Download Manager{N360S_prod_1.19_4.1.0.32}] C:\Documents and Settings\All Users\Documents\Norton\{N360S_prod_1.19_4.1.0.32}\N360Downloader.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe (SanDisk)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\Audra Drish\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\NPJPI150_04.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab (TTestGenXInstallObject)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} http://www.slide.com/uploader/SlideImageUploader.cab (Slide Image Uploader Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} http://www.parallelgraphics.com/l2/bin/cortvrml.cab (ParallelGraphics Cortona Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (Reg Error: Key error.)
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} http://aolsvc.aol.com/onlinegames/sonydavi…aderControl.cab (DVCDownloaderControl Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.com/books/_Players/MathPlayer.cab (Pearson MathXL Player)
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/AUDRAD~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Audra Drish\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Audra Drish\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/14 18:12:54 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Audra Drish\Local Settings\Application Data\av.exe" /START "%1" %* File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/11/14 18:12:17 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/05/19 10:52:11 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Audra Drish\Desktop\OTL.exe
[2010/04/23 20:23:23 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Audra Drish\Desktop\HJTInstall(2)(2).exe
[2010/04/22 23:09:49 | 002,260,992 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCompress.dll
[2010/04/22 23:09:49 | 000,282,624 | —- | C] (Online Media Technologies Company Ltd.) – C:\WINDOWS\System32\NCTQuickTimeFile.dll
[2010/04/22 23:09:49 | 000,261,632 | —- | C] (MainConcept) – C:\WINDOWS\System32\mcdvd_32.dll
[2010/04/22 23:09:49 | 000,139,264 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoFile.dll
[2010/04/22 23:09:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\RMBin
[2010/04/22 23:09:48 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioFile2.dll
[2010/04/22 23:09:48 | 001,245,184 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTRMFile.dll
[2010/04/22 23:09:48 | 000,991,232 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCoreM.dll
[2010/04/22 23:09:48 | 000,294,912 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAVIFile.dll
[2010/04/22 23:09:48 | 000,196,608 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTWMVFile.dll
[2010/04/22 23:09:48 | 000,106,496 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCoreU.dll
[2010/04/22 23:09:47 | 002,564,096 | —- | C] (Online Media Technologies Ltd.) – C:\WINDOWS\System32\NCTAudioCompress3.dll
[2010/04/22 23:09:47 | 001,810,432 | —- | C] (Online Media Technologies Ltd.) – C:\WINDOWS\System32\NCTAudioCompress2.dll
[2010/04/22 23:09:44 | 000,000,000 | —D | C] – C:\Program Files\4U Computing
[2010/04/22 23:06:40 | 011,610,677 | —- | C] (4U Computing, Inc. ) – C:\Documents and Settings\Audra Drish\Desktop\4UAVIMPEGConverter.exe
[2010/04/20 21:47:17 | 097,525,032 | —- | C] (Apple Inc.) – C:\Documents and Settings\Audra Drish\Desktop\iTunesSetup.exe
[2010/04/20 19:43:34 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/20 19:43:34 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/20 19:42:34 | 000,362,032 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\symtdi.sys
[2010/04/20 19:42:34 | 000,340,016 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\symtdiv.sys
[2010/04/20 19:42:34 | 000,328,752 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.sys
[2010/04/20 19:42:34 | 000,325,680 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.sys
[2010/04/20 19:42:34 | 000,172,592 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.sys
[2010/04/20 19:42:34 | 000,116,784 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\Ironx86.sys
[2010/04/20 19:42:34 | 000,043,696 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.sys
[2010/04/20 19:42:30 | 000,501,888 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.sys
[2010/04/20 19:40:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2010/04/20 19:40:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0401000.020
[2010/04/20 19:40:48 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/04/20 19:40:47 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/04/20 19:17:58 | 110,083,680 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360-ESD-17-6-0-32-EN.exe
[2010/04/20 19:13:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2010/04/20 19:06:18 | 000,408,024 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader(2).exe
[2010/04/20 19:05:04 | 000,408,024 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader.exe
[2 C:\Documents and Settings\Audra Drish\My Documents\*.tmp files -> C:\Documents and Settings\Audra Drish\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/19 10:52:15 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Audra Drish\Desktop\OTL.exe
[2010/05/18 12:07:31 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/17 17:08:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/05/17 16:42:23 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/17 16:41:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/17 16:41:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/17 16:41:01 | 000,361,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/17 16:41:00 | 527,749,120 | -HS- | M] () – C:\hiberfil.sys
[2010/05/17 16:39:02 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Audra Drish\NTUSER.DAT
[2010/05/17 16:39:02 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Audra Drish\ntuser.ini
[2010/05/17 08:41:08 | 000,005,746 | —- | M] () – C:\Documents and Settings\Audra Drish\Application Data\wklnhst.dat
[2010/05/17 04:47:58 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Audra Drish\Desktop\~$ta Analysis Form.docx
[2010/05/17 04:40:54 | 000,011,019 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Data%20Analysis%20Form.docx
[2010/04/26 20:00:17 | 000,000,692 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Audra Drish.job
[2010/04/23 23:24:00 | 000,002,137 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\iTunes.lnk
[2010/04/23 22:44:33 | 000,032,256 | —- | M] () – C:\Documents and Settings\Audra Drish\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/23 20:27:26 | 000,002,459 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.lnk
[2010/04/23 20:23:24 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Audra Drish\Desktop\HJTInstall(2)(2).exe
[2010/04/23 20:16:43 | 001,402,880 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.msi
[2010/04/22 23:10:08 | 000,000,839 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\4U AVI MPEG Converter.lnk
[2010/04/22 23:08:15 | 011,610,677 | —- | M] (4U Computing, Inc. ) – C:\Documents and Settings\Audra Drish\Desktop\4UAVIMPEGConverter.exe
[2010/04/22 13:13:39 | 000,000,349 | —- | M] () – C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2010/04/21 21:02:35 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/04/21 00:55:11 | 000,677,310 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/20 21:58:27 | 097,525,032 | —- | M] (Apple Inc.) – C:\Documents and Settings\Audra Drish\Desktop\iTunesSetup.exe
[2010/04/20 20:48:06 | 000,002,421 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\VideoSpin.lnk
[2010/04/20 19:43:33 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/20 19:43:33 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/20 19:43:33 | 000,007,443 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/20 19:43:33 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/20 19:42:53 | 000,001,908 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/20 19:39:58 | 000,000,897 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Download Manager.lnk
[2010/04/20 19:39:58 | 000,000,768 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Installation Files.lnk
[2010/04/20 19:25:11 | 110,083,680 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360-ESD-17-6-0-32-EN.exe
[2010/04/20 19:06:18 | 000,408,024 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader(2).exe
[2010/04/20 19:05:11 | 000,408,024 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader.exe
[2 C:\Documents and Settings\Audra Drish\My Documents\*.tmp files -> C:\Documents and Settings\Audra Drish\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/17 04:47:58 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Audra Drish\Desktop\~$ta Analysis Form.docx
[2010/05/17 04:40:42 | 000,011,019 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Data%20Analysis%20Form.docx
[2010/04/23 20:18:00 | 000,002,459 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.lnk
[2010/04/23 20:16:32 | 001,402,880 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.msi
[2010/04/22 23:10:07 | 000,000,839 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\4U AVI MPEG Converter.lnk
[2010/04/22 23:09:47 | 000,126,464 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/04/21 21:02:34 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/04/21 21:02:34 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/04/21 00:59:36 | 527,749,120 | -HS- | C] () – C:\hiberfil.sys
[2010/04/20 21:06:36 | 000,002,137 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\iTunes.lnk
[2010/04/20 19:46:09 | 000,677,310 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/20 19:43:34 | 000,007,443 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/20 19:43:34 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/20 19:42:52 | 000,001,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/20 19:41:44 | 000,003,374 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.inf
[2010/04/20 19:41:44 | 000,002,793 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.inf
[2010/04/20 19:41:44 | 000,001,473 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNetV.inf
[2010/04/20 19:41:44 | 000,001,445 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNet.inf
[2010/04/20 19:41:44 | 000,001,388 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.inf
[2010/04/20 19:41:44 | 000,001,382 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.inf
[2010/04/20 19:41:44 | 000,000,741 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Iron.inf
[2010/04/20 19:41:43 | 000,001,754 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\ccHPx86.inf
[2010/04/20 19:40:54 | 000,007,787 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\symnetv.cat
[2010/04/20 19:40:54 | 000,007,444 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.cat
[2010/04/20 19:40:54 | 000,007,442 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.cat
[2010/04/20 19:40:54 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.cat
[2010/04/20 19:40:54 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\iron.cat
[2010/04/20 19:40:54 | 000,007,425 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.cat
[2010/04/20 19:40:54 | 000,007,396 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.cat
[2010/04/20 19:40:54 | 000,007,368 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNet.cat
[2010/04/20 19:40:53 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\isolate.ini
[2010/04/20 19:13:03 | 000,000,897 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Download Manager.lnk
[2010/04/20 19:13:03 | 000,000,768 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Installation Files.lnk
[2010/03/12 23:01:43 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/02/04 21:36:45 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/02/04 21:36:44 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/05/02 12:28:54 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/01/26 03:04:12 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2007/01/26 03:04:12 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/04/27 00:25:15 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/03/22 19:39:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS38.DLL
[2006/03/20 17:12:27 | 000,000,012 | —- | C] () – C:\WINDOWS\dirsaver.ini
[2006/03/19 23:50:04 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2005/11/15 13:11:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/14 19:51:26 | 000,000,228 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/14 19:44:44 | 000,000,166 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/11/14 19:35:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/14 19:35:03 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/14 19:35:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/14 19:35:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/14 19:35:03 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/14 19:35:03 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/11/14 19:32:21 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2005/11/14 19:07:08 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2005/11/14 19:07:08 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2005/11/14 19:07:08 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2005/11/14 19:07:08 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/11/14 18:57:24 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\stac97co.dll
[2005/11/14 18:17:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/14 18:09:30 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/14 16:46:58 | 000,000,341 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/24 18:20:28 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/10 22:02:04 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/06/21 17:22:08 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/21 14:04:23 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\atsdrve.dll
========== LOP Check ==========
[2009/05/03 13:36:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/04/05 20:37:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010/01/19 21:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2007/12/16 20:51:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/11/11 18:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/06/04 10:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2008/02/04 21:36:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2008/11/12 00:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/11/13 20:45:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
[2006/12/14 15:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SonyPicturesGames
[2008/02/04 21:31:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/11/11 23:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/13 20:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VideoSpin
[2008/02/22 16:39:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/08/03 14:10:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2010/02/21 19:27:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Canon
[2006/08/26 12:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\FUJIFILM
[2008/12/04 19:34:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\GetRightToGo
[2005/11/14 20:51:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\InterVideo
[2007/10/24 15:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Leadertech
[2008/11/11 18:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\muvee Technologies
[2007/03/08 13:37:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Snapfish
[2008/02/04 21:36:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\TaxCut
[2006/03/19 18:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Template
[2009/04/28 22:21:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\toshiba
[2007/01/15 16:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Viewpoint
[2010/05/17 17:08:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/11/14 10:04:20 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/11/14 10:04:20 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/11/14 10:04:20 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/20 19:43:33 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS
========== Alternate Data Streams ==========
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7F4E393D
< End of report >
Below are the results of the scan.
OTL logfile created on: 5/19/2010 10:55:12 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Audra Drish\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 123.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.18 Gb Free Space | 5.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: AUDRA
Current User Name: Audra Drish
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Audra Drish\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Audra Drish\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\asOEHook.dll (Symantec Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\Microsoft.VC90.CRT\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\Microsoft.VC90.CRT\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (N360) – C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe (Symantec Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
SRV - (CFSvcs) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AOL TopSpeedMonitor) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100522.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100522.003\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100429.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0401000.020\Ironx86.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0401000.020\ccHPx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMDS.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100513.002\IDSXpx86.sys (Symantec Corporation)
DRV - (SAMFILT) – C:\WINDOWS\system32\drivers\samfilt.sys (Dolphin, Inc.)
DRV - (tbiosdrv) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TVALZ) – C:\WINDOWS\system32\DRIVERS\TVALZ.SYS (TOSHIBA Corporation)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.iastate.edu/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: [removed]:1.03.01
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/04/26 20:49:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/04/21 00:51:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/31 21:16:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/31 15:46:21 | 000,000,000 | —D | M]
[2008/11/11 17:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Extensions
[2010/05/18 08:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions
[2009/08/10 16:51:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/28 15:50:55 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/07 23:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\[removed]
[2009/08/15 21:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\[removed]
[2010/04/20 19:38:39 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.1.0.32\IPSBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [000StTHK] C:\WINDOWS\System32\000StTHK.exe ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe File not found
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CFSServ.exe] File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe File not found
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TFNF5] C:\WINDOWS\System32\TFNF5.exe (TOSHIBA Corp.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPSODDCtl] C:\WINDOWS\System32\TPSODDCtl.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Norton Download Manager{N360S_prod_1.19_4.1.0.32}] C:\Documents and Settings\All Users\Documents\Norton\{N360S_prod_1.19_4.1.0.32}\N360Downloader.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe (SanDisk)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\Audra Drish\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\NPJPI150_04.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab (TTestGenXInstallObject)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} http://www.slide.com/uploader/SlideImageUploader.cab (Slide Image Uploader Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} http://www.parallelgraphics.com/l2/bin/cortvrml.cab (ParallelGraphics Cortona Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (Reg Error: Key error.)
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} http://aolsvc.aol.com/onlinegames/sonydavi…aderControl.cab (DVCDownloaderControl Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.com/books/_Players/MathPlayer.cab (Pearson MathXL Player)
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/AUDRAD~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Audra Drish\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Audra Drish\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/14 18:12:54 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Audra Drish\Local Settings\Application Data\av.exe" /START "%1" %* File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/11/14 18:12:17 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/05/19 10:52:11 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Audra Drish\Desktop\OTL.exe
[2010/04/23 20:23:23 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Audra Drish\Desktop\HJTInstall(2)(2).exe
[2010/04/22 23:09:49 | 002,260,992 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCompress.dll
[2010/04/22 23:09:49 | 000,282,624 | —- | C] (Online Media Technologies Company Ltd.) – C:\WINDOWS\System32\NCTQuickTimeFile.dll
[2010/04/22 23:09:49 | 000,261,632 | —- | C] (MainConcept) – C:\WINDOWS\System32\mcdvd_32.dll
[2010/04/22 23:09:49 | 000,139,264 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoFile.dll
[2010/04/22 23:09:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\RMBin
[2010/04/22 23:09:48 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioFile2.dll
[2010/04/22 23:09:48 | 001,245,184 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTRMFile.dll
[2010/04/22 23:09:48 | 000,991,232 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCoreM.dll
[2010/04/22 23:09:48 | 000,294,912 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAVIFile.dll
[2010/04/22 23:09:48 | 000,196,608 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTWMVFile.dll
[2010/04/22 23:09:48 | 000,106,496 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCoreU.dll
[2010/04/22 23:09:47 | 002,564,096 | —- | C] (Online Media Technologies Ltd.) – C:\WINDOWS\System32\NCTAudioCompress3.dll
[2010/04/22 23:09:47 | 001,810,432 | —- | C] (Online Media Technologies Ltd.) – C:\WINDOWS\System32\NCTAudioCompress2.dll
[2010/04/22 23:09:44 | 000,000,000 | —D | C] – C:\Program Files\4U Computing
[2010/04/22 23:06:40 | 011,610,677 | —- | C] (4U Computing, Inc. ) – C:\Documents and Settings\Audra Drish\Desktop\4UAVIMPEGConverter.exe
[2010/04/20 21:47:17 | 097,525,032 | —- | C] (Apple Inc.) – C:\Documents and Settings\Audra Drish\Desktop\iTunesSetup.exe
[2010/04/20 19:43:34 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/20 19:43:34 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/20 19:42:34 | 000,362,032 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\symtdi.sys
[2010/04/20 19:42:34 | 000,340,016 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\symtdiv.sys
[2010/04/20 19:42:34 | 000,328,752 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.sys
[2010/04/20 19:42:34 | 000,325,680 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.sys
[2010/04/20 19:42:34 | 000,172,592 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.sys
[2010/04/20 19:42:34 | 000,116,784 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\Ironx86.sys
[2010/04/20 19:42:34 | 000,043,696 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.sys
[2010/04/20 19:42:30 | 000,501,888 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.sys
[2010/04/20 19:40:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2010/04/20 19:40:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0401000.020
[2010/04/20 19:40:48 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/04/20 19:40:47 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/04/20 19:17:58 | 110,083,680 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360-ESD-17-6-0-32-EN.exe
[2010/04/20 19:13:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2010/04/20 19:06:18 | 000,408,024 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader(2).exe
[2010/04/20 19:05:04 | 000,408,024 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader.exe
[2 C:\Documents and Settings\Audra Drish\My Documents\*.tmp files -> C:\Documents and Settings\Audra Drish\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/19 10:52:15 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Audra Drish\Desktop\OTL.exe
[2010/05/18 12:07:31 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/17 17:08:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/05/17 16:42:23 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/17 16:41:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/17 16:41:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/17 16:41:01 | 000,361,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/17 16:41:00 | 527,749,120 | -HS- | M] () – C:\hiberfil.sys
[2010/05/17 16:39:02 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Audra Drish\NTUSER.DAT
[2010/05/17 16:39:02 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Audra Drish\ntuser.ini
[2010/05/17 08:41:08 | 000,005,746 | —- | M] () – C:\Documents and Settings\Audra Drish\Application Data\wklnhst.dat
[2010/05/17 04:47:58 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Audra Drish\Desktop\~$ta Analysis Form.docx
[2010/05/17 04:40:54 | 000,011,019 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Data%20Analysis%20Form.docx
[2010/04/26 20:00:17 | 000,000,692 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Audra Drish.job
[2010/04/23 23:24:00 | 000,002,137 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\iTunes.lnk
[2010/04/23 22:44:33 | 000,032,256 | —- | M] () – C:\Documents and Settings\Audra Drish\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/23 20:27:26 | 000,002,459 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.lnk
[2010/04/23 20:23:24 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Audra Drish\Desktop\HJTInstall(2)(2).exe
[2010/04/23 20:16:43 | 001,402,880 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.msi
[2010/04/22 23:10:08 | 000,000,839 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\4U AVI MPEG Converter.lnk
[2010/04/22 23:08:15 | 011,610,677 | —- | M] (4U Computing, Inc. ) – C:\Documents and Settings\Audra Drish\Desktop\4UAVIMPEGConverter.exe
[2010/04/22 13:13:39 | 000,000,349 | —- | M] () – C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2010/04/21 21:02:35 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/04/21 00:55:11 | 000,677,310 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/20 21:58:27 | 097,525,032 | —- | M] (Apple Inc.) – C:\Documents and Settings\Audra Drish\Desktop\iTunesSetup.exe
[2010/04/20 20:48:06 | 000,002,421 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\VideoSpin.lnk
[2010/04/20 19:43:33 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/20 19:43:33 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/20 19:43:33 | 000,007,443 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/20 19:43:33 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/20 19:42:53 | 000,001,908 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/20 19:39:58 | 000,000,897 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Download Manager.lnk
[2010/04/20 19:39:58 | 000,000,768 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Installation Files.lnk
[2010/04/20 19:25:11 | 110,083,680 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360-ESD-17-6-0-32-EN.exe
[2010/04/20 19:06:18 | 000,408,024 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader(2).exe
[2010/04/20 19:05:11 | 000,408,024 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader.exe
[2 C:\Documents and Settings\Audra Drish\My Documents\*.tmp files -> C:\Documents and Settings\Audra Drish\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/17 04:47:58 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Audra Drish\Desktop\~$ta Analysis Form.docx
[2010/05/17 04:40:42 | 000,011,019 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Data%20Analysis%20Form.docx
[2010/04/23 20:18:00 | 000,002,459 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.lnk
[2010/04/23 20:16:32 | 001,402,880 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.msi
[2010/04/22 23:10:07 | 000,000,839 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\4U AVI MPEG Converter.lnk
[2010/04/22 23:09:47 | 000,126,464 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/04/21 21:02:34 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/04/21 21:02:34 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/04/21 00:59:36 | 527,749,120 | -HS- | C] () – C:\hiberfil.sys
[2010/04/20 21:06:36 | 000,002,137 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\iTunes.lnk
[2010/04/20 19:46:09 | 000,677,310 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/20 19:43:34 | 000,007,443 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/20 19:43:34 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/20 19:42:52 | 000,001,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/20 19:41:44 | 000,003,374 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.inf
[2010/04/20 19:41:44 | 000,002,793 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.inf
[2010/04/20 19:41:44 | 000,001,473 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNetV.inf
[2010/04/20 19:41:44 | 000,001,445 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNet.inf
[2010/04/20 19:41:44 | 000,001,388 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.inf
[2010/04/20 19:41:44 | 000,001,382 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.inf
[2010/04/20 19:41:44 | 000,000,741 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Iron.inf
[2010/04/20 19:41:43 | 000,001,754 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\ccHPx86.inf
[2010/04/20 19:40:54 | 000,007,787 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\symnetv.cat
[2010/04/20 19:40:54 | 000,007,444 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.cat
[2010/04/20 19:40:54 | 000,007,442 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.cat
[2010/04/20 19:40:54 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.cat
[2010/04/20 19:40:54 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\iron.cat
[2010/04/20 19:40:54 | 000,007,425 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.cat
[2010/04/20 19:40:54 | 000,007,396 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.cat
[2010/04/20 19:40:54 | 000,007,368 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNet.cat
[2010/04/20 19:40:53 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\isolate.ini
[2010/04/20 19:13:03 | 000,000,897 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Download Manager.lnk
[2010/04/20 19:13:03 | 000,000,768 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Installation Files.lnk
[2010/03/12 23:01:43 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/02/04 21:36:45 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/02/04 21:36:44 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/05/02 12:28:54 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/01/26 03:04:12 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2007/01/26 03:04:12 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/04/27 00:25:15 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/03/22 19:39:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS38.DLL
[2006/03/20 17:12:27 | 000,000,012 | —- | C] () – C:\WINDOWS\dirsaver.ini
[2006/03/19 23:50:04 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2005/11/15 13:11:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/14 19:51:26 | 000,000,228 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/14 19:44:44 | 000,000,166 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/11/14 19:35:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/14 19:35:03 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/14 19:35:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/14 19:35:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/14 19:35:03 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/14 19:35:03 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/11/14 19:32:21 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2005/11/14 19:07:08 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2005/11/14 19:07:08 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2005/11/14 19:07:08 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2005/11/14 19:07:08 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/11/14 18:57:24 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\stac97co.dll
[2005/11/14 18:17:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/14 18:09:30 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/14 16:46:58 | 000,000,341 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/24 18:20:28 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/10 22:02:04 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/06/21 17:22:08 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/21 14:04:23 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\atsdrve.dll
========== LOP Check ==========
[2009/05/03 13:36:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/04/05 20:37:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010/01/19 21:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2007/12/16 20:51:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/11/11 18:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/06/04 10:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2008/02/04 21:36:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2008/11/12 00:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/11/13 20:45:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
[2006/12/14 15:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SonyPicturesGames
[2008/02/04 21:31:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/11/11 23:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/13 20:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VideoSpin
[2008/02/22 16:39:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/08/03 14:10:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2010/02/21 19:27:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Canon
[2006/08/26 12:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\FUJIFILM
[2008/12/04 19:34:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\GetRightToGo
[2005/11/14 20:51:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\InterVideo
[2007/10/24 15:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Leadertech
[2008/11/11 18:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\muvee Technologies
[2007/03/08 13:37:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Snapfish
[2008/02/04 21:36:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\TaxCut
[2006/03/19 18:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Template
[2009/04/28 22:21:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\toshiba
[2007/01/15 16:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Viewpoint
[2010/05/17 17:08:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/11/14 10:04:20 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/11/14 10:04:20 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/11/14 10:04:20 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/20 19:43:33 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS
========== Alternate Data Streams ==========
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7F4E393D
< End of report >