bazzab
Topic Starter
OTL logfile created on: 06/11/2010 12:54:41 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Barrie & Jill\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 791.02 Gb Total Space | 619.84 Gb Free Space | 78.36% Space Free | Partition Type: NTFS
Drive D: | 140.49 Gb Total Space | 84.02 Gb Free Space | 59.80% Space Free | Partition Type: NTFS
Drive E: | 94.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: CATFORD | User Name: Barrie & Jill | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Barrie & Jill\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\RapidBIT\cidaemon.exe (BitMicro Software Corporation)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\PCSecurityShield\BitDefender 2009\seccenter.exe ()
PRC - C:\Program Files\PCSecurityShield\BitDefender 2009\vsserv.exe (PCSecurityShield)
PRC - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (PCSecurityShield)
PRC - C:\Program Files\PCSecurityShield\BitDefender 2009\bdagent.exe (PCSecurityShield)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2009 DVD\EDICT.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\USB CAMERA\DRIVER\emSwapAp2.exe (eMPIA Technology, Inc.)
PRC - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
PRC - C:\WINDOWS\etMon.exe (EMPIA Technology Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
PRC - C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe (Common Group)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Barrie & Jill\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (FlexService) – C:\Program Files\RapidBIT\cisvc.exe (BitMicro Software Corporation)
SRV - (VSSERV) – C:\Program Files\PCSecurityShield\BitDefender 2009\vsserv.exe (PCSecurityShield)
SRV - (LIVESRV) – C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (PCSecurityShield)
SRV - (scan) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (PCSecurityShield)
SRV - (Arrakis3) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe ()
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (upperdev) – C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (GMSIPCI) – D:\INSTALL\GMSIPCI.SYS File not found
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (bdftdif) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC)
DRV - (BDSelfPr) – C:\Program Files\PCSecurityShield\BitDefender 2009\bdselfpr.sys (BitDefender S.R.L.)
DRV - (bdfsfltr) – C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (bdfm) – C:\WINDOWS\system32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (DCamUSBET) – C:\WINDOWS\system32\drivers\etDevice.sys (eMPIA Technology, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (ScanUSBET) – C:\WINDOWS\system32\drivers\etScan.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBET) – C:\WINDOWS\system32\drivers\etFilter.sys (eMPIA Technology Inc.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (GT680x) – C:\WINDOWS\system32\drivers\TR12389.sys ( )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2014090
IE - HKCU\..\URLSearchHook: {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=971163"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [removed]:1.4.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {7c5c0f58-e061-457d-9033-77307f5ed00c}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..keyword.URL: ""
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PCSecurityShield\BitDefender 2009\FFToolbar\ [2009/10/23 13:13:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/07/10 09:00:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/31 15:02:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 10:38:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/10/28 15:34:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/09/03 11:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Extensions
[2010/09/03 11:20:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/11/05 17:24:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions
[2009/10/21 10:47:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/06 15:38:15 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/12/03 16:06:59 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/21 10:27:28 | 000,000,000 | —D | M] (TorrentMan Toolbar) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}
[2010/05/09 19:31:47 | 000,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/01/28 11:41:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/10/07 08:03:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\[removed]
[2009/12/15 20:32:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\[removed]
[2009/10/21 20:00:10 | 000,002,234 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\searchplugins\askcom.xml
[2010/11/05 17:24:54 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 07:45:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/26 13:45:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/03/05 17:08:04 | 000,049,664 | —- | M] () – C:\Program Files\Mozilla Firefox\components\FFComm.dll
[2010/07/17 04:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/10/21 15:32:36 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/10/21 15:32:36 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/10/21 15:32:36 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/10/21 15:32:36 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2004/08/04 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Bitlord Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (The Shield Deluxe 2009 Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\PCSecurityShield\BitDefender 2009\IEToolbar.dll (Bitdefender)
O3 - HKLM\..\Toolbar: (Bitlord Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Bitlord Toolbar) - {7C5C0F58-E061-457D-9033-77307F5ED00C} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BDAgent] C:\Program Files\PCSecurityShield\BitDefender 2009\bdagent.exe (PCSecurityShield)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\PCSecurityShield\BitDefender 2009\IEShow.exe (The Shield Deluxe 2009 )
O4 - HKLM..\Run: [etMonitor] C:\WINDOWS\etMon.exe (EMPIA Technology Corporation)
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [L09AXLRD_4705812] C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2009 DVD\EDICT.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\emSwapAP2.EXE.lnk = C:\Program Files\USB CAMERA\DRIVER\emSwapAp2.exe (eMPIA Technology, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Watch.lnk = C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe (Common Group)
O4 - Startup: C:\Documents and Settings\Barrie & Jill\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Barrie & Jill\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\Barrie & Jill\Start Menu\Programs\Startup\YPOPs.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1256032315671 (WUWebControl Class)
O16 - DPF: CabBuilder http://kiw.imgag.com/imgag/kiw/toolbar/dow…llerControl.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 10.30.0.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/20 08:32:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/05/21 12:45:00 | 000,000,046 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{2498f6b0-1d39-11df-933c-00218511fe88}\Shell - "" = AutoRun
O33 - MountPoints2\{2498f6b0-1d39-11df-933c-00218511fe88}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2498f6b0-1d39-11df-933c-00218511fe88}\Shell\AutoRun\command - "" = F:\DPFMate.exe – File not found
O33 - MountPoints2\{b89bd4ba-01c3-11df-9301-00218511fe88}\Shell\AutoRun\command - "" = H:\Default.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\J:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/11/01 20:53:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Barrie & Jill\My Documents\Forever web site articles
[2010/10/23 17:57:38 | 000,000,000 | —D | C] – C:\Sounds
[2010/10/23 11:15:09 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/10/22 16:07:40 | 000,024,832 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgusbmodem.sys
[2010/10/22 16:07:40 | 000,019,968 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgusbdiag.sys
[2010/10/22 16:07:40 | 000,013,056 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgusbbus.sys
[2010/10/22 16:07:39 | 000,000,000 | —D | C] – C:\Program Files\LG Electronics
[2010/10/22 16:05:32 | 001,164,728 | —- | C] (NuMedia Soft, Inc.) – C:\WINDOWS\System32\NMSDVDXU.dll
[2010/10/22 16:05:32 | 000,419,240 | —- | C] (VideoSoft) – C:\WINDOWS\System32\Vsflex7L.ocx
[2010/10/22 16:05:31 | 000,630,784 | —- | C] (ComponentOne) – C:\WINDOWS\System32\vsflex8u.ocx
[2010/10/22 16:05:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Barrie & Jill\Application Data\LG Electronics
[2010/10/22 16:05:15 | 000,000,000 | —D | C] – C:\Program Files\LG PC Suite II
[2010/10/22 15:49:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Barrie & Jill\My Documents\top 40 171010
[2010/10/12 19:04:54 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/12 19:04:54 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/12 19:00:47 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/09 07:56:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/10/09 07:56:35 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/02/18 11:44:25 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.sys
[2009/11/11 18:27:43 | 000,017,524 | —- | C] ( ) – C:\WINDOWS\System32\drivers\TR12389.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/06 11:00:03 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/06 08:48:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/05 20:50:19 | 000,081,984 | —- | M] () – C:\WINDOWS\System32\bdod.bin
[2010/11/05 19:19:00 | 000,000,567 | —- | M] () – C:\WINDOWS\System32\BDUpdateV1.xml
[2010/10/31 14:58:01 | 000,554,592 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/31 14:58:01 | 000,108,078 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/31 14:56:18 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/26 15:49:37 | 000,010,752 | —- | M] () – C:\Documents and Settings\Barrie & Jill\My Documents\cna work of nancy.doc
[2010/10/25 20:18:08 | 000,020,480 | —- | M] () – C:\Documents and Settings\Barrie & Jill\My Documents\musica work.doc
[2010/10/24 14:06:03 | 000,000,121 | —- | M] () – C:\WINDOWS\bdagent.INI
[2010/10/22 16:05:41 | 000,001,459 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LG PC Suite II.lnk
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/12 19:17:10 | 000,002,265 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Desktop\Skype (2).lnk
[2010/10/12 19:13:57 | 000,153,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/12 19:08:15 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/10/12 18:07:45 | 000,139,776 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/09 07:56:49 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/26 15:49:36 | 000,010,752 | —- | C] () – C:\Documents and Settings\Barrie & Jill\My Documents\cna work of nancy.doc
[2010/10/25 20:18:07 | 000,020,480 | —- | C] () – C:\Documents and Settings\Barrie & Jill\My Documents\musica work.doc
[2010/10/22 16:05:41 | 000,001,459 | —- | C] () – C:\Documents and Settings\All Users\Desktop\LG PC Suite II.lnk
[2010/10/09 07:56:49 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/11 10:17:57 | 000,001,041 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\vso_ts_preview.xml
[2010/03/12 09:54:08 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/12 09:54:08 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/02/18 17:12:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/02/18 17:12:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/02/18 17:12:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/02/18 17:12:06 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/02/18 11:44:25 | 000,087,608 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\inst.exe
[2010/02/18 11:44:25 | 000,007,887 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.cat
[2010/02/18 11:44:25 | 000,001,144 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.inf
[2010/02/18 11:44:25 | 000,000,034 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.log
[2010/01/05 17:11:45 | 000,000,736 | —- | C] () – C:\WINDOWS\SamsungMaster.INI
[2009/11/28 16:59:09 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/11/11 18:33:12 | 000,000,000 | —- | C] () – C:\WINDOWS\WATCH.INI
[2009/10/28 11:49:57 | 001,064,960 | —- | C] () – C:\WINDOWS\System32\H5KRNL32.DLL
[2009/10/28 11:49:57 | 000,188,928 | —- | C] () – C:\WINDOWS\System32\H5ICON32.DLL
[2009/10/28 11:49:57 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\H5MENU32.DLL
[2009/10/28 11:49:57 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\H5RTF32.DLL
[2009/10/28 11:49:57 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\H5TOOL32.DLL
[2009/10/28 11:44:39 | 000,569,344 | —- | C] () – C:\WINDOWS\System32\tx11.dll
[2009/10/28 11:44:38 | 000,000,478 | —- | C] () – C:\WINDOWS\System32\tx11_ic.ini
[2009/10/24 16:30:26 | 000,000,121 | —- | C] () – C:\WINDOWS\bdagent.INI
[2009/10/23 13:34:22 | 000,106,496 | R— | C] () – C:\WINDOWS\System32\vshp1018.dll
[2009/10/21 14:06:13 | 000,139,776 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/20 18:24:42 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/10/20 14:17:04 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/10/20 14:17:04 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/10/20 14:17:01 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/10/20 10:22:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/10/20 08:43:17 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2009/07/08 03:05:20 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/10/09 15:31:54 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\txmlutil.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/01/31 13:50:32 | 000,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
========== LOP Check ==========
[2010/06/05 15:57:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\agi
[2010/01/27 19:48:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/10/23 13:14:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BitDefender
[2010/07/10 08:57:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/12/03 16:27:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/02/16 13:53:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/11 11:28:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/11/24 17:46:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/02/17 17:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\AnvSoft
[2010/01/28 11:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Azureus
[2009/10/23 13:13:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\BitDefender
[2009/10/21 10:01:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Canneverbe_Limited
[2010/02/18 16:00:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\DVDFab
[2010/04/18 09:02:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Facebook
[2010/02/19 13:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\ImTOO Software Studio
[2010/10/23 17:57:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\LG Electronics
[2009/12/03 16:34:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Nokia
[2009/10/21 09:51:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\OpenOffice.org
[2009/12/03 16:27:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\PC Suite
[2010/09/03 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Thunderbird
[2010/10/01 19:51:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Vso
[2009/12/03 16:04:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Windows Desktop Search
[2009/10/22 12:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Windows Search
[2010/11/06 11:00:03 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/10/20 08:32:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/18 20:49:57 | 000,053,586 | —- | M] () – C:\avi_log.txt
[2009/10/20 08:28:17 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/10/20 08:32:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/05/20 18:02:53 | 000,018,918 | —- | M] () – C:\drwtsn32.log
[2010/03/10 20:57:45 | 000,000,132 | —- | M] () – C:\httpdwl.dat
[2009/10/20 08:32:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/20 08:32:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/10/20 10:39:02 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/06 08:48:37 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/02/19 13:23:00 | 000,000,216 | —- | M] () – C:\temp.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/10/20 08:32:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/30 17:00:00 | 000,049,152 | R— | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 11:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/10/20 10:20:59 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/20 10:20:59 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/20 10:20:59 | 000,880,640 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/20 10:43:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/21 09:50:47 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Barrie & Jill\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/21 09:50:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-06 08:06:48
========== Alternate Data Streams ==========
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD4DD9B9
< End of report >
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Barrie & Jill\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 791.02 Gb Total Space | 619.84 Gb Free Space | 78.36% Space Free | Partition Type: NTFS
Drive D: | 140.49 Gb Total Space | 84.02 Gb Free Space | 59.80% Space Free | Partition Type: NTFS
Drive E: | 94.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: CATFORD | User Name: Barrie & Jill | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Barrie & Jill\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\RapidBIT\cidaemon.exe (BitMicro Software Corporation)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\PCSecurityShield\BitDefender 2009\seccenter.exe ()
PRC - C:\Program Files\PCSecurityShield\BitDefender 2009\vsserv.exe (PCSecurityShield)
PRC - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (PCSecurityShield)
PRC - C:\Program Files\PCSecurityShield\BitDefender 2009\bdagent.exe (PCSecurityShield)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2009 DVD\EDICT.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\USB CAMERA\DRIVER\emSwapAp2.exe (eMPIA Technology, Inc.)
PRC - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
PRC - C:\WINDOWS\etMon.exe (EMPIA Technology Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
PRC - C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe (Common Group)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Barrie & Jill\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (FlexService) – C:\Program Files\RapidBIT\cisvc.exe (BitMicro Software Corporation)
SRV - (VSSERV) – C:\Program Files\PCSecurityShield\BitDefender 2009\vsserv.exe (PCSecurityShield)
SRV - (LIVESRV) – C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (PCSecurityShield)
SRV - (scan) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (PCSecurityShield)
SRV - (Arrakis3) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe ()
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (upperdev) – C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (GMSIPCI) – D:\INSTALL\GMSIPCI.SYS File not found
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (bdftdif) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC)
DRV - (BDSelfPr) – C:\Program Files\PCSecurityShield\BitDefender 2009\bdselfpr.sys (BitDefender S.R.L.)
DRV - (bdfsfltr) – C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (bdfm) – C:\WINDOWS\system32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (DCamUSBET) – C:\WINDOWS\system32\drivers\etDevice.sys (eMPIA Technology, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (ScanUSBET) – C:\WINDOWS\system32\drivers\etScan.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBET) – C:\WINDOWS\system32\drivers\etFilter.sys (eMPIA Technology Inc.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (GT680x) – C:\WINDOWS\system32\drivers\TR12389.sys ( )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2014090
IE - HKCU\..\URLSearchHook: {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=971163"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [removed]:1.4.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {7c5c0f58-e061-457d-9033-77307f5ed00c}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..keyword.URL: ""
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PCSecurityShield\BitDefender 2009\FFToolbar\ [2009/10/23 13:13:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/07/10 09:00:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/31 15:02:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 10:38:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/10/28 15:34:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/09/03 11:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Extensions
[2010/09/03 11:20:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/11/05 17:24:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions
[2009/10/21 10:47:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/06 15:38:15 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/12/03 16:06:59 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/21 10:27:28 | 000,000,000 | —D | M] (TorrentMan Toolbar) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}
[2010/05/09 19:31:47 | 000,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/01/28 11:41:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/10/07 08:03:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\[removed]
[2009/12/15 20:32:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\extensions\[removed]
[2009/10/21 20:00:10 | 000,002,234 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Application Data\Mozilla\Firefox\Profiles\gftmrqaq.default\searchplugins\askcom.xml
[2010/11/05 17:24:54 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 07:45:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/26 13:45:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/03/05 17:08:04 | 000,049,664 | —- | M] () – C:\Program Files\Mozilla Firefox\components\FFComm.dll
[2010/07/17 04:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/10/21 15:32:36 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/10/21 15:32:36 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/10/21 15:32:36 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/10/21 15:32:36 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2004/08/04 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Bitlord Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (The Shield Deluxe 2009 Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\PCSecurityShield\BitDefender 2009\IEToolbar.dll (Bitdefender)
O3 - HKLM\..\Toolbar: (Bitlord Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Bitlord Toolbar) - {7C5C0F58-E061-457D-9033-77307F5ED00C} - C:\Program Files\TorrentMan\tbTor1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BDAgent] C:\Program Files\PCSecurityShield\BitDefender 2009\bdagent.exe (PCSecurityShield)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\PCSecurityShield\BitDefender 2009\IEShow.exe (The Shield Deluxe 2009 )
O4 - HKLM..\Run: [etMonitor] C:\WINDOWS\etMon.exe (EMPIA Technology Corporation)
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [L09AXLRD_4705812] C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2009 DVD\EDICT.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\emSwapAP2.EXE.lnk = C:\Program Files\USB CAMERA\DRIVER\emSwapAp2.exe (eMPIA Technology, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Watch.lnk = C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe (Common Group)
O4 - Startup: C:\Documents and Settings\Barrie & Jill\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Barrie & Jill\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\Barrie & Jill\Start Menu\Programs\Startup\YPOPs.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1256032315671 (WUWebControl Class)
O16 - DPF: CabBuilder http://kiw.imgag.com/imgag/kiw/toolbar/dow…llerControl.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 10.30.0.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/20 08:32:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/05/21 12:45:00 | 000,000,046 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{2498f6b0-1d39-11df-933c-00218511fe88}\Shell - "" = AutoRun
O33 - MountPoints2\{2498f6b0-1d39-11df-933c-00218511fe88}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2498f6b0-1d39-11df-933c-00218511fe88}\Shell\AutoRun\command - "" = F:\DPFMate.exe – File not found
O33 - MountPoints2\{b89bd4ba-01c3-11df-9301-00218511fe88}\Shell\AutoRun\command - "" = H:\Default.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\J:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/11/01 20:53:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Barrie & Jill\My Documents\Forever web site articles
[2010/10/23 17:57:38 | 000,000,000 | —D | C] – C:\Sounds
[2010/10/23 11:15:09 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/10/22 16:07:40 | 000,024,832 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgusbmodem.sys
[2010/10/22 16:07:40 | 000,019,968 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgusbdiag.sys
[2010/10/22 16:07:40 | 000,013,056 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgusbbus.sys
[2010/10/22 16:07:39 | 000,000,000 | —D | C] – C:\Program Files\LG Electronics
[2010/10/22 16:05:32 | 001,164,728 | —- | C] (NuMedia Soft, Inc.) – C:\WINDOWS\System32\NMSDVDXU.dll
[2010/10/22 16:05:32 | 000,419,240 | —- | C] (VideoSoft) – C:\WINDOWS\System32\Vsflex7L.ocx
[2010/10/22 16:05:31 | 000,630,784 | —- | C] (ComponentOne) – C:\WINDOWS\System32\vsflex8u.ocx
[2010/10/22 16:05:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Barrie & Jill\Application Data\LG Electronics
[2010/10/22 16:05:15 | 000,000,000 | —D | C] – C:\Program Files\LG PC Suite II
[2010/10/22 15:49:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Barrie & Jill\My Documents\top 40 171010
[2010/10/12 19:04:54 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/12 19:04:54 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/12 19:00:47 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/09 07:56:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/10/09 07:56:35 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/02/18 11:44:25 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.sys
[2009/11/11 18:27:43 | 000,017,524 | —- | C] ( ) – C:\WINDOWS\System32\drivers\TR12389.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/06 11:00:03 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/06 08:48:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/05 20:50:19 | 000,081,984 | —- | M] () – C:\WINDOWS\System32\bdod.bin
[2010/11/05 19:19:00 | 000,000,567 | —- | M] () – C:\WINDOWS\System32\BDUpdateV1.xml
[2010/10/31 14:58:01 | 000,554,592 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/31 14:58:01 | 000,108,078 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/31 14:56:18 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/26 15:49:37 | 000,010,752 | —- | M] () – C:\Documents and Settings\Barrie & Jill\My Documents\cna work of nancy.doc
[2010/10/25 20:18:08 | 000,020,480 | —- | M] () – C:\Documents and Settings\Barrie & Jill\My Documents\musica work.doc
[2010/10/24 14:06:03 | 000,000,121 | —- | M] () – C:\WINDOWS\bdagent.INI
[2010/10/22 16:05:41 | 000,001,459 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LG PC Suite II.lnk
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/12 19:17:10 | 000,002,265 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Desktop\Skype (2).lnk
[2010/10/12 19:13:57 | 000,153,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/12 19:08:15 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/10/12 18:07:45 | 000,139,776 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/09 07:56:49 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/26 15:49:36 | 000,010,752 | —- | C] () – C:\Documents and Settings\Barrie & Jill\My Documents\cna work of nancy.doc
[2010/10/25 20:18:07 | 000,020,480 | —- | C] () – C:\Documents and Settings\Barrie & Jill\My Documents\musica work.doc
[2010/10/22 16:05:41 | 000,001,459 | —- | C] () – C:\Documents and Settings\All Users\Desktop\LG PC Suite II.lnk
[2010/10/09 07:56:49 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/11 10:17:57 | 000,001,041 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\vso_ts_preview.xml
[2010/03/12 09:54:08 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/12 09:54:08 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/02/18 17:12:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/02/18 17:12:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/02/18 17:12:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/02/18 17:12:06 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/02/18 11:44:25 | 000,087,608 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\inst.exe
[2010/02/18 11:44:25 | 000,007,887 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.cat
[2010/02/18 11:44:25 | 000,001,144 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.inf
[2010/02/18 11:44:25 | 000,000,034 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Application Data\pcouffin.log
[2010/01/05 17:11:45 | 000,000,736 | —- | C] () – C:\WINDOWS\SamsungMaster.INI
[2009/11/28 16:59:09 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/11/11 18:33:12 | 000,000,000 | —- | C] () – C:\WINDOWS\WATCH.INI
[2009/10/28 11:49:57 | 001,064,960 | —- | C] () – C:\WINDOWS\System32\H5KRNL32.DLL
[2009/10/28 11:49:57 | 000,188,928 | —- | C] () – C:\WINDOWS\System32\H5ICON32.DLL
[2009/10/28 11:49:57 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\H5MENU32.DLL
[2009/10/28 11:49:57 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\H5RTF32.DLL
[2009/10/28 11:49:57 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\H5TOOL32.DLL
[2009/10/28 11:44:39 | 000,569,344 | —- | C] () – C:\WINDOWS\System32\tx11.dll
[2009/10/28 11:44:38 | 000,000,478 | —- | C] () – C:\WINDOWS\System32\tx11_ic.ini
[2009/10/24 16:30:26 | 000,000,121 | —- | C] () – C:\WINDOWS\bdagent.INI
[2009/10/23 13:34:22 | 000,106,496 | R— | C] () – C:\WINDOWS\System32\vshp1018.dll
[2009/10/21 14:06:13 | 000,139,776 | —- | C] () – C:\Documents and Settings\Barrie & Jill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/20 18:24:42 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/10/20 14:17:04 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/10/20 14:17:04 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/10/20 14:17:01 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/10/20 10:22:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/10/20 08:43:17 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2009/07/08 03:05:20 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/10/09 15:31:54 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\txmlutil.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/01/31 13:50:32 | 000,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
========== LOP Check ==========
[2010/06/05 15:57:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\agi
[2010/01/27 19:48:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/10/23 13:14:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BitDefender
[2010/07/10 08:57:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/12/03 16:27:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/02/16 13:53:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/11 11:28:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/11/24 17:46:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/02/17 17:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\AnvSoft
[2010/01/28 11:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Azureus
[2009/10/23 13:13:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\BitDefender
[2009/10/21 10:01:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Canneverbe_Limited
[2010/02/18 16:00:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\DVDFab
[2010/04/18 09:02:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Facebook
[2010/02/19 13:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\ImTOO Software Studio
[2010/10/23 17:57:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\LG Electronics
[2009/12/03 16:34:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Nokia
[2009/10/21 09:51:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\OpenOffice.org
[2009/12/03 16:27:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\PC Suite
[2010/09/03 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Thunderbird
[2010/10/01 19:51:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Vso
[2009/12/03 16:04:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Windows Desktop Search
[2009/10/22 12:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Barrie & Jill\Application Data\Windows Search
[2010/11/06 11:00:03 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/10/20 08:32:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/18 20:49:57 | 000,053,586 | —- | M] () – C:\avi_log.txt
[2009/10/20 08:28:17 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/10/20 08:32:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/05/20 18:02:53 | 000,018,918 | —- | M] () – C:\drwtsn32.log
[2010/03/10 20:57:45 | 000,000,132 | —- | M] () – C:\httpdwl.dat
[2009/10/20 08:32:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/20 08:32:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/10/20 10:39:02 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/06 08:48:37 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/02/19 13:23:00 | 000,000,216 | —- | M] () – C:\temp.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/10/20 08:32:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/30 17:00:00 | 000,049,152 | R— | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 11:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/10/20 10:20:59 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/20 10:20:59 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/20 10:20:59 | 000,880,640 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/20 10:43:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/21 09:50:47 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Barrie & Jill\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/21 09:50:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\Barrie & Jill\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-06 08:06:48
========== Alternate Data Streams ==========
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD4DD9B9
< End of report >