OTL logfile created on: 3/27/2011 4:00:39 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
223.00 Mb Total Physical Memory | 40.00 Mb Available Physical Memory | 18.00% Memory free
547.00 Mb Paging File | 333.00 Mb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.40 Gb Total Space | 22.71 Gb Free Space | 68.00% Space Free | Partition Type: NTFS
Drive D: | 3.89 Gb Total Space | 0.74 Gb Free Space | 18.99% Space Free | Partition Type: FAT32
Computer Name: MARKS | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe (Valve Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (WSWNA1100) – C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe ()
SRV - (jswpsapi) – C:\Program Files\NETGEAR\WNA1100\jswpsapi.exe (Atheros Communications, Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (navapsvc) – c:\Program Files\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
SRV - (ccPwdSvc) – c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (tmrkb) – C:\WINDOWS\system32\drivers\tmrkb.sys (trend_company_name)
DRV - (AR9271) – C:\WINDOWS\system32\drivers\athuw.sys (Atheros Communications, Inc.)
DRV - (WSIMD) – C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (JSWSCIMD) – C:\WINDOWS\system32\drivers\jswscimd.sys (Atheros Communications, Inc.)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (wltwo51b) – C:\WINDOWS\system32\drivers\wltwo51b.sys (2wire)
DRV - (SAVRTPEL) – C:\WINDOWS\system32\drivers\SAVRTPEL.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\WINDOWS\system32\drivers\SAVRT.SYS (Symantec Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20021202.005\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20021202.005\NAVENG.SYS (Symantec Corporation)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (nv_agp) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Search-Results"
FF - prefs.js..browser.search.defaultenginename: "Search-Results"
FF - prefs.js..browser.search.order.1: "Search-Results"
FF - prefs.js..browser.search.selectedEngine: "Search-Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.search-results.com?o=41647951&l=dis"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..keyword.URL: "
http://websearch.search-results.com/redirect?client=ff&src=kw&tb=BBY2-SRS&o=41647948&locale=en_US&apn_uid=1576782B-2AE3-4CDB-AB53-2250635C5BD0&apn_ptnrs=7S&apn_sauid=5F1E14BD-165A-4A6E-BA31-74EB4082FCBE&apn_dtid=YYYYYYYYUS&q="
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 19:30:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/02/23 04:30:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/03/27 15:06:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\y1sv4l9w.default\extensions
[2011/03/26 21:18:59 | 000,003,368 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\y1sv4l9w.default\searchplugins\search-results.xml
[2011/03/27 15:03:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Y1SV4L9W.DEFAULT\EXTENSIONS\[removed]
[2011/03/18 11:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 02:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2002/08/29 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Java Plug-in 1.4.0_01)
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Java Plug-in 1.4.0_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed] [removed]
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/01/24 08:07:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{e0a3a000-0a1d-11da-9871-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{e0a3a000-0a1d-11da-9871-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e0a3a000-0a1d-11da-9871-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe" -a "%1" %* (Valve Corporation)
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe" -a "%1" %* (Valve Corporation)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/27 15:35:11 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/03/27 15:35:11 | 000,056,400 | —- | C] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/03/27 15:35:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\log
[2011/03/27 15:21:41 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/03/27 15:21:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\HiJackThis
[2011/03/26 21:49:11 | 000,335,872 | -HS- | C] (Valve Corporation) – C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe
[2011/03/26 20:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2011/03/26 20:41:11 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/03/26 12:21:01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/03/26 12:20:26 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/03/26 11:49:18 | 000,000,000 | —D | C] – C:\Program Files\James River Software
[2011/03/25 19:07:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/03/25 19:06:34 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/25 19:06:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/25 19:06:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/03/25 19:06:29 | 000,019,288 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/25 19:06:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/25 17:41:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2011/03/15 16:51:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Identities
[2011/03/13 00:36:50 | 000,000,000 | –SD | C] – C:\Documents and Settings\Owner\UserData
[2011/03/11 16:32:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/03/10 20:02:26 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data\Atheros
[2011/03/10 20:01:02 | 000,058,208 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\drivers\wsimd.sys
[2011/03/10 20:00:53 | 001,269,854 | —- | C] (Devicescape) – C:\WINDOWS\System32\dsa.dll
[2011/03/10 20:00:53 | 000,426,074 | —- | C] (Atheros) – C:\WINDOWS\System32\wgapi.dll
[2011/03/10 20:00:53 | 000,405,504 | —- | C] (Atheros) – C:\WINDOWS\System32\wcapi.dll
[2011/03/10 20:00:53 | 000,356,443 | —- | C] (Atheros) – C:\WINDOWS\System32\wcapiU.dll
[2011/03/10 20:00:53 | 000,311,390 | —- | C] (Atheros) – C:\WINDOWS\System32\athcfg20U.dll
[2011/03/10 20:00:53 | 000,254,022 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\wsfwDS.dll
[2011/03/10 20:00:53 | 000,249,924 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\wsimd.dll
[2011/03/10 20:00:53 | 000,237,568 | —- | C] (Atheros) – C:\WINDOWS\System32\athcfg20.dll
[2011/03/10 20:00:53 | 000,127,079 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\athcfg20resU.dll
[2011/03/10 20:00:53 | 000,127,053 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\athcfg20res.dll
[2011/03/10 20:00:53 | 000,082,017 | —- | C] (Devicescape, Inc.) – C:\WINDOWS\System32\dsaNac.dll
[2011/03/10 20:00:52 | 001,723,840 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\drivers\athuw.sys
[2011/03/10 20:00:52 | 000,495,700 | —- | C] (Atheros) – C:\WINDOWS\System32\acs.exe
[2011/03/10 20:00:52 | 000,058,208 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\wsimd.sys
[2011/03/10 20:00:52 | 000,057,440 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\jswscimd.sys
[2011/03/10 20:00:52 | 000,057,440 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\drivers\jswscimd.sys
[2011/03/10 20:00:48 | 000,405,582 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\jswscsup.dll
[2011/03/10 20:00:48 | 000,073,800 | —- | C] (Atheros) – C:\WINDOWS\System32\athgina.dll
[2011/03/10 20:00:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NETGEAR WNA1100 Smart Wizard
[2011/03/10 20:00:44 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2011/03/10 19:45:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2011/02/28 13:46:05 | 000,000,000 | —D | C] – C:\$WIN_NT$.~BT
[2011/02/28 13:45:53 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2011/02/28 04:48:33 | 000,000,000 | —D | C] – C:\WINDOWS\setup.pss
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/27 15:47:46 | 000,013,950 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uu7a0286ok431ntm7blec27
[2011/03/27 15:47:46 | 000,013,950 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\uu7a0286ok431ntm7blec27
[2011/03/27 15:37:28 | 000,002,447 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2011/03/27 15:37:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/27 15:37:00 | 234,409,984 | -HS- | M] () – C:\hiberfil.sys
[2011/03/27 15:35:11 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/03/27 15:35:11 | 000,056,400 | —- | M] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/03/27 15:14:05 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/03/27 14:39:54 | 000,000,246 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/03/26 21:49:11 | 000,335,872 | -HS- | M] (Valve Corporation) – C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe
[2011/03/26 11:52:30 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/25 20:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
[2011/03/25 19:30:59 | 000,000,750 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/25 19:30:59 | 000,000,732 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/25 19:06:34 | 000,000,792 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/25 15:35:09 | 000,005,120 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/12 23:20:55 | 000,000,252 | RHS- | M] () – C:\boot.ini
[2011/03/11 18:48:04 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/03/10 20:03:24 | 000,394,078 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/10 20:03:24 | 000,059,326 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/10 20:00:47 | 000,000,583 | —- | M] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WNA1100 Smart Wizard.lnk
[2011/03/10 19:54:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/08 18:16:59 | 000,018,541 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Y1EMgpFs.htm.part
[2011/03/08 14:04:40 | 000,003,344 | —- | M] () – C:\Documents and Settings\Owner\Desktop\General Experience and Reputation.html
[2011/03/07 03:11:58 | 000,117,661 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Rugger10-22TigerMaple.jpg
[2011/03/06 17:14:54 | 000,000,152 | —- | M] () – C:\logfile
[2011/03/06 17:12:19 | 000,140,440 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/06 00:59:42 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2011/03/06 00:54:35 | 000,000,608 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/03/05 23:58:54 | 000,000,907 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Kodak Pictures.lnk
[2011/02/28 04:48:48 | 000,000,237 | RHS- | M] () – C:\BOOT.BAK
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/27 15:21:41 | 000,002,447 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2011/03/26 21:49:18 | 000,013,950 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uu7a0286ok431ntm7blec27
[2011/03/26 21:49:18 | 000,013,950 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\uu7a0286ok431ntm7blec27
[2011/03/25 19:30:59 | 000,000,732 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/25 19:30:58 | 000,000,738 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/03/25 19:06:34 | 000,000,792 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/11 18:48:04 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/03/11 18:48:04 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/03/11 16:22:55 | 000,024,672 | —- | C] () – C:\WINDOWS\System32\javaw.exe
[2011/03/11 16:22:54 | 000,024,670 | —- | C] () – C:\WINDOWS\System32\java.exe
[2011/03/10 20:00:52 | 000,039,471 | —- | C] () – C:\WINDOWS\System32\wsimdp.cat
[2011/03/10 20:00:52 | 000,039,469 | —- | C] () – C:\WINDOWS\System32\wsimd.cat
[2011/03/10 20:00:52 | 000,035,967 | —- | C] () – C:\WINDOWS\System32\jswscimdp.cat
[2011/03/10 20:00:52 | 000,035,538 | —- | C] () – C:\WINDOWS\System32\jswscimd.cat
[2011/03/10 20:00:52 | 000,005,529 | —- | C] () – C:\WINDOWS\System32\jswscimdp.inf
[2011/03/10 20:00:52 | 000,005,363 | —- | C] () – C:\WINDOWS\System32\wsimdp.inf
[2011/03/10 20:00:52 | 000,002,231 | —- | C] () – C:\WINDOWS\System32\jswscimd.inf
[2011/03/10 20:00:52 | 000,002,179 | —- | C] () – C:\WINDOWS\System32\wsimd.inf
[2011/03/10 20:00:48 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2011/03/10 20:00:47 | 000,000,583 | —- | C] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WNA1100 Smart Wizard.lnk
[2011/03/08 18:16:56 | 000,018,541 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Y1EMgpFs.htm.part
[2011/03/08 14:04:37 | 000,003,344 | —- | C] () – C:\Documents and Settings\Owner\Desktop\General Experience and Reputation.html
[2011/03/07 03:11:49 | 000,117,661 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Rugger10-22TigerMaple.jpg
[2011/03/06 17:14:43 | 000,000,152 | —- | C] () – C:\logfile
[2011/03/06 00:59:42 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/03/05 23:58:54 | 000,000,907 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Kodak Pictures.lnk
[2011/02/28 04:48:48 | 000,000,237 | RHS- | C] () – C:\BOOT.BAK
[2009/10/04 11:35:14 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2007/11/01 16:03:04 | 000,000,049 | —- | C] () – C:\WINDOWS\VistaEmail.ini
[2007/09/25 17:10:53 | 000,086,082 | —- | C] () – C:\WINDOWS\System32\ftdiunin.exe
[2007/09/25 17:10:53 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2007/03/08 15:10:39 | 000,000,312 | —- | C] () – C:\WINDOWS\EReg515.dat
[2005/08/24 13:11:59 | 000,561,152 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2005/07/25 17:03:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\eraseme_32050.exe
[2005/07/01 15:54:02 | 000,005,120 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/06/26 12:19:54 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\winsusrm.dll
[2005/05/14 15:43:49 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/05/05 20:58:12 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\shawn_1.dll
[2005/05/05 20:58:10 | 000,067,511 | —- | C] () – C:\WINDOWS\System32\a_i_037.exe
[2005/05/05 20:57:37 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\a_i_037.dll
[2005/04/30 18:33:33 | 000,000,400 | —- | C] () – C:\WINDOWS\System32\im64.dll
[2005/03/02 21:55:08 | 000,000,625 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/06 16:35:50 | 000,000,182 | —- | C] () – C:\WINDOWS\eomaha.ini
[2004/11/06 16:27:17 | 000,000,062 | —- | C] () – C:\WINDOWS\draw.ini
[2004/11/06 16:09:13 | 000,000,181 | —- | C] () – C:\WINDOWS\eholdem.ini
[2004/08/08 16:56:01 | 001,404,204 | —- | C] () – C:\WINDOWS\jawa32v.bin
[2004/08/08 16:56:01 | 000,188,416 | —- | C] () – C:\WINDOWS\jawa32.exe
[2004/08/08 16:56:01 | 000,106,324 | —- | C] () – C:\WINDOWS\jawa32u.bin
[2004/08/08 16:56:01 | 000,002,668 | —- | C] () – C:\WINDOWS\jawa32.dat
[2004/08/08 16:56:01 | 000,000,032 | —- | C] () – C:\WINDOWS\jawa32e.bin
[2004/08/08 16:56:00 | 000,034,068 | —- | C] () – C:\WINDOWS\jawa32.bin
[2004/07/14 14:40:34 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\msmc.exe
[2004/07/13 20:41:38 | 000,249,856 | —- | C] () – C:\WINDOWS\aqadcup.exe
[2004/07/13 20:41:17 | 000,024,576 | —- | C] () – C:\WINDOWS\wsem300.dll
[2004/06/25 10:20:43 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\istinstall_adlogix.exe
[2004/06/15 21:10:13 | 000,054,528 | —- | C] () – C:\WINDOWS\wsem218.dll
[2004/06/15 21:10:05 | 000,034,560 | —- | C] () – C:\WINDOWS\nem219.dll_
[2004/06/15 20:13:03 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\cdsm32.dll
[2004/06/11 17:10:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\automove.exe_
[2004/05/20 00:52:49 | 000,155,648 | —- | C] () – C:\WINDOWS\fash.exe
[2004/05/20 00:51:19 | 000,042,328 | —- | C] () – C:\WINDOWS\PreProcess.data
[2004/05/18 19:31:59 | 000,187,314 | —- | C] () – C:\WINDOWS\System32\silent.exe
[2004/05/15 18:44:14 | 000,167,936 | —- | C] () – C:\WINDOWS\mwsvm.exe
[2004/05/15 18:42:26 | 001,404,204 | —- | C] () – C:\WINDOWS\vurls.bin
[2004/05/15 18:42:26 | 000,160,400 | —- | C] () – C:\WINDOWS\mwsvm.bin
[2004/05/15 18:42:26 | 000,106,324 | —- | C] () – C:\WINDOWS\urls.bin
[2004/05/15 18:42:26 | 000,002,623 | —- | C] () – C:\WINDOWS\mwsvm.dat
[2004/05/12 18:09:04 | 000,073,728 | —- | C] () – C:\WINDOWS\ieasst.dll
[2004/05/12 18:07:53 | 000,202,527 | —- | C] () – C:\Documents and Settings\Owner\Application Data\tvmknwrd.dll
[2004/05/12 18:07:13 | 000,000,357 | —- | C] () – C:\WINDOWS\whInstaller.ini
[2004/05/12 18:00:04 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\IdleUI.dll
[2004/05/12 17:59:40 | 000,067,584 | —- | C] () – C:\WINDOWS\System32\2ndsrch.dll
[2004/05/12 17:59:27 | 000,229,793 | —- | C] () – C:\WINDOWS\twaintec.ini
[2004/05/12 17:58:26 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\stcloader.exe
[2004/05/12 17:57:18 | 000,000,060 | —- | C] () – C:\WINDOWS\wininit.ini_
[2004/05/12 17:57:03 | 000,032,768 | —- | C] () – C:\WINDOWS\preInsTT.exe_
[2004/05/12 17:54:48 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\bridge.dll_
[2004/05/12 17:54:48 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\jao.dll
[2004/05/12 17:54:20 | 000,251,829 | —- | C] () – C:\WINDOWS\System32\0021-bdl94126.EXE
[2004/05/12 17:54:05 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\infamous_downloader.exe
[2004/05/12 17:53:02 | 000,213,012 | —- | C] () – C:\WINDOWS\infamous.exe
[2003/08/23 15:16:24 | 000,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2003/08/23 15:16:24 | 000,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2003/07/30 22:42:07 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlsz.INI
[2003/07/28 21:09:34 | 000,000,037 | —- | C] () – C:\WINDOWS\Acroread.ini
[2003/06/07 18:50:19 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2003/02/07 06:49:22 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2003/02/07 06:49:22 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2003/02/07 06:47:42 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/02/07 06:47:38 | 000,001,740 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2003/02/07 06:24:42 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/02/07 06:24:31 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/02/07 06:24:31 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/02/07 06:24:29 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2003/02/07 06:24:25 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2003/02/07 06:24:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/01/25 04:43:47 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/01/25 04:43:16 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\iAlmcoin.dll
[2003/01/25 04:30:01 | 000,000,032 | -HS- | C] () – C:\WINDOWS\System32\{7A423CBA-2B8A-4A0B-AE91-B7E63A03AA63}.dat
[2003/01/25 04:30:01 | 000,000,032 | -HS- | C] () – C:\WINDOWS\{432DC6F6-968D-4F5B-A15F-5FECE3F263AD}.dat
[2003/01/25 04:29:51 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\SR2.dat
[2003/01/24 09:36:27 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\IntroReg.dll
[2003/01/24 09:36:25 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/01/24 09:36:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/01/24 09:27:03 | 000,008,822 | —- | C] () – C:\WINDOWS\mozver.dat
[2003/01/24 09:18:55 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/01/24 09:18:40 | 000,000,608 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/01/24 08:52:52 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/01/24 08:41:30 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2003/01/24 08:30:21 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/01/24 08:30:21 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/01/24 08:29:52 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/01/24 08:11:36 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/01/24 08:09:48 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2003/01/24 08:04:56 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2003/01/24 06:55:28 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/24 06:54:59 | 000,004,573 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/24 06:54:56 | 000,394,078 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/01/24 06:54:56 | 000,059,326 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/01/24 00:00:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/23 23:59:01 | 000,140,440 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2001/08/22 18:00:00 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\cfg.dat
[2001/08/19 05:30:44 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\elitesiy32.exe
[1999/01/22 12:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2005/06/30 12:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/08/23 18:53:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2003/01/24 09:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterTrust
[2004/05/20 01:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2003/01/24 09:24:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2009/01/24 16:37:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/14 15:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2003/01/24 09:09:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/17 15:00:49 | 000,000,450 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration RunOnce Task.job
[2003/09/10 20:17:22 | 000,000,342 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1055195529.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2003/01/24 08:07:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/28 04:48:48 | 000,000,237 | RHS- | M] () – C:\BOOT.BAK
[2011/03/12 23:20:55 | 000,000,252 | RHS- | M] () – C:\boot.ini
[2003/01/24 08:07:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/27 15:37:00 | 234,409,984 | -HS- | M] () – C:\hiberfil.sys
[2003/01/24 08:07:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/08/10 22:28:54 | 000,000,586 | -H– | M] () – C:\IPH.PH
[2011/03/06 17:14:54 | 000,000,152 | —- | M] () – C:\logfile
[2003/01/24 08:07:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 06:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/03/06 17:12:37 | 000,000,000 | —- | M] () – C:\nvlog.txt
[2011/03/27 15:36:59 | 352,321,536 | -HS- | M] () – C:\pagefile.sys
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2003/01/24 08:07:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007/06/07 12:53:02 | 000,031,744 | —- | M] () – C:\Program Files\Megan's Resume.doc
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2003/01/23 23:58:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2003/01/23 23:58:14 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2003/01/23 23:58:14 | 000,385,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2003/01/24 08:07:39 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2003/12/09 23:44:20 | 000,063,074 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\.plugin140_01.trace
[2002/02/21 04:05:54 | 000,000,173 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\oobecmt.ini
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2003/01/24 08:11:24 | 000,000,139 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/01/24 08:11:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/02/23 04:29:01 | 008,582,536 | —- | M] (Mozilla) – C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.6.13.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 3/27/2011 4:00:39 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
223.00 Mb Total Physical Memory | 40.00 Mb Available Physical Memory | 18.00% Memory free
547.00 Mb Paging File | 333.00 Mb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.40 Gb Total Space | 22.71 Gb Free Space | 68.00% Space Free | Partition Type: NTFS
Drive D: | 3.89 Gb Total Space | 0.74 Gb Free Space | 18.99% Space Free | Partition Type: FAT32
Computer Name: MARKS | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL %1,%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe (Valve Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL %1,%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{01F9D88C-3C86-4E82-840A-101A3221F67A}" = Microsoft Money 2003
"{02B42D23-10F2-4862-ADA4-3DF1EA0021B2}" = Microsoft Money 2003 System Pack
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{7CF31609-270B-11D6-9445-000102308676}" = Java 2 Runtime Environment, SE v1.4.0_01
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver Software
"{8D5D99B8-DFA2-4018-ADE9-A6B83E655C65}" =
"{A2AE9709-283B-4B48-AA34-729C070A62FB}" = NETGEAR WNA1100 wireless USB 2.0 adapter
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English) v1.0.3705
"{EDCD4CE3-DE92-49A9-87F9-FE09B2FBA16C}" = Norton AntiVirus 2003
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"America Online us" = America Online
"AolCoach" = AOL Coach Version 1.0(Build:20011028.1)
"FTDICOMM" = FTDI USB Serial Converter Drivers
"Inactive HP Printer Drivers (Remove only)" = Inactive HP Printer Drivers (Remove only)
"Java Web Start" = Java Web Start
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PS2" = PS2
"Q327979" = Windows XP Hotfix (SP2) Q327979
"q330638" = Windows XP Hotfix (SP2) [See q330638 for more information]
"Q331958" = Windows XP Hotfix (SP2) Q331958
"QuickTime" = QuickTime
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/27/2011 4:42:32 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca
Error - 3/27/2011 4:52:23 PM | Computer Name = MARKS | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.
Error - 3/27/2011 4:52:39 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff
Error - 3/27/2011 4:52:39 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca
Error - 3/27/2011 5:02:47 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff
Error - 3/27/2011 5:02:47 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca
Error - 3/27/2011 5:30:45 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff
Error - 3/27/2011 5:30:46 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca
Error - 3/27/2011 5:30:55 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff
Error - 3/27/2011 5:30:55 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca
[ System Events ]
Error - 3/27/2011 5:08:51 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:51 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:08:53 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 3/27/2011 5:37:17 PM | Computer Name = MARKS | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 80636000, parameter2 00000000, parameter3
ec73bf97, parameter4 00000000.
Error - 3/27/2011 5:38:40 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7003
Description = The tmrkb service depends on the following nonexistent service: tmcomm
< End of report >