HI Jeff:
OTL.TXT output file:
OTL logfile created on: 11/4/2011 9:27:36 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.74 Gb Available Physical Memory | 62.43% Memory free
12.09 Gb Paging File | 9.68 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.87 Gb Total Space | 38.59 Gb Free Space | 5.60% Space Free | Partition Type: NTFS
Drive I: | 245.73 Mb Total Space | 238.26 Mb Free Space | 96.96% Space Free | Partition Type: FAT
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Windows\SysWOW64\cfgmig32.exe ()
PRC - C:\Windows\SysWOW64\svcprs32.exe ()
PRC - C:\Windows\SysWOW64\mdmcls32.exe ()
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\CNYHKey.exe (Creative)
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Windows\ModLEDKey.exe (Chicony)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\SysWOW64\winsflt.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Windows\mHotkey.exe ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe (CA)
SRV:
64bit: - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV:
64bit: - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV:
64bit: - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV:
64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (UmxEngine) – C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe (CA)
SRV:
64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:
64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:
64bit: - (ETService) – C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe ()
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (WinSvchostManagerSrv) – C:\Windows\SysWOW64\cfgmig32.exe ()
SRV - (WinSvchostManager) – C:\Windows\SysWOW64\svcprs32.exe ()
SRV - (WinExtManager) – C:\Windows\SysWOW64\mdmcls32.exe ()
SRV - (SpeedDiskService) – C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Symantec RemoteAssist) – C:\Program Files (x86)\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (Symantec Core LC) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (KmxCF) – C:\Windows\SysNative\DRIVERS\KmxCF.sys (CA)
DRV:
64bit: - (KmxCfg) – C:\Windows\SysNative\DRIVERS\kmxcfg.sys (CA)
DRV:
64bit: - (KmxAMRT) – C:\Windows\SysNative\DRIVERS\KmxAMRT.sys (CA)
DRV:
64bit: - (KmxAgent) – C:\Windows\SysNative\DRIVERS\kmxagent.sys (CA)
DRV:
64bit: - (KmxFile) – C:\Windows\SysNative\DRIVERS\KmxFile.sys (CA)
DRV:
64bit: - (KmxSbx) – C:\Windows\SysNative\DRIVERS\KmxSbx.sys (CA)
DRV:
64bit: - (KmxFw) – C:\Windows\SysNative\DRIVERS\kmxfw.sys (CA)
DRV:
64bit: - (KmxFilter) – C:\Windows\SysNative\DRIVERS\KmxFilter.sys (CA)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:
64bit: - (SymDSMon) – C:\Windows\SysNative\drivers\SymDSMon.sys (Symantec Corporation)
DRV:
64bit: - (SYMSpeedDisk) – C:\Windows\SysNative\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV:
64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (LSI Corporation)
DRV:
64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (HPEWSFXBULK) – C:\Windows\SysNative\drivers\hpfx64bulk.sys (Hewlett Packard)
DRV:
64bit: - (RTL8187Se) – C:\Windows\SysNative\DRIVERS\RTL8187Se.sys (Realtek Semiconductor Corporation )
DRV:
64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:
64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\DRIVERS\e1y60x64.sys (Intel Corporation)
DRV:
64bit: - (gwfilt64) – C:\Windows\SysNative\drivers\gwfilt64.sys (Creative Technology Ltd.)
DRV:
64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (SYMSpeedDisk) – C:\Windows\SysWOW64\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 1C F7 7A 0E 74 0D 1D 44 A6 FD E9 39 B6 6D 90 5D [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\Firefox [2011/09/16 12:12:51 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5576EE23-03F7-4284-AA8B-760A71D594D2}: C:\Users\Admin\AppData\Local\{5576EE23-03F7-4284-AA8B-760A71D594D2} [2011/05/08 10:01:02 | 000,000,000 | —D | M]
[2011/06/30 14:30:14 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
O1 HOSTS File: ([2011/11/02 19:53:05 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\Program Files (x86)\WinZip Courier\wzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4:
64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [LchDrvKey] C:\Windows\LchDrvKey.exe ()
O4 - HKLM..\Run: [LedKey] C:\Windows\CNYHKey.exe (Creative)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000023 - wwinsflt.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000024 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: DhcpNameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\UmxSbxExA64.dll) - C:\Windows\SysNative\UmxSbxExA64.dll (CA)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20:
64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\PFW: DllName - (UmxWnp.Dll) - C:\Windows\SysWow64\UmxWNP.dll (CA)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/04 08:59:19 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – \$RECYCLE.BIN
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\temp
[2011/11/02 22:16:48 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/01 19:41:57 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/01 19:41:57 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/01 19:40:20 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – \Qoobox
[2011/10/31 23:11:24 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 23:11:24 | 000,607,260 | R— | C] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/30 00:20:55 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Malwarebytes
[2011/10/30 00:20:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/30 00:20:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/30 00:20:34 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/10/30 00:20:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – \Config.Msi
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/29 13:37:20 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/29 13:37:17 | 009,852,544 | —- | C] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/27 18:16:00 | 004,266,378 | —- | C] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 18:15:05 | 004,280,796 | R— | C] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/10/13 03:01:08 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/13 03:01:08 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/13 03:01:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/13 03:01:07 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/13 03:01:06 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/13 03:01:06 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/13 03:01:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/13 03:01:05 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/13 03:01:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 20:09:31 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 20:09:31 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 20:08:59 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 20:08:59 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 20:08:59 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 20:08:59 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 20:08:59 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 20:08:59 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 20:03:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/11 20:03:05 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
========== Files - Modified Within 30 Days ==========
[2011/11/04 09:29:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/04 09:17:19 | 000,000,126 | —- | M] () – C:\pclog_3440.dat
[2011/11/04 08:55:26 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/04 08:55:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
[2011/11/04 08:54:17 | 000,000,000 | —- | M] () – C:\Windows\SysNative\LogConfigTemp.xml
[2011/11/04 08:54:04 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 08:54:04 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 08:54:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/04 01:39:23 | 003,657,573 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k0
[2011/11/04 01:39:23 | 000,371,180 | —- | M] () – C:\Windows\SysNative\drivers\KmxAgent.asc
[2011/11/04 01:39:23 | 000,000,337 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k0
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k7
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k6
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k5
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k4
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k3
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k2
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k1
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k7
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k6
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k5
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k4
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k3
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k2
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k1
[2011/11/04 01:37:39 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
[2011/11/03 23:58:22 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/03 21:22:45 | 000,725,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/03 21:22:45 | 000,620,130 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/03 21:22:45 | 000,109,204 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/02 19:53:05 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/02 18:50:28 | 004,280,796 | R— | M] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/11/01 03:51:40 | 000,000,378 | —- | M] () – C:\pclog_3636.dat
[2011/10/31 23:08:05 | 000,000,680 | —- | M] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/31 22:51:08 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 22:48:58 | 000,607,260 | R— | M] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/31 13:55:02 | 000,002,519 | —- | M] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/31 08:44:05 | 000,000,126 | —- | M] () – C:\pclog_3460.dat
[2011/10/31 01:50:58 | 000,000,126 | —- | M] () – C:\pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 13:01:15 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/29 12:58:04 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/28 08:57:04 | 000,000,245 | —- | M] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/27 18:16:00 | 004,266,378 | —- | M] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 16:17:03 | 000,000,930 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/10/26 08:19:04 | 000,000,063 | —- | M] () – C:\pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | M] () – C:\pclog_4268.dat
[2011/10/16 05:41:04 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/15 20:19:42 | 000,134,382 | —- | M] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 03:50:48 | 000,389,272 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/13 00:57:04 | 000,000,063 | —- | M] () – C:\pclog_3620.dat
[2011/10/12 22:02:32 | 928,890,990 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/10/12 19:44:36 | 000,000,063 | —- | M] () – C:\pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/10 01:17:12 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/10/08 15:14:18 | 000,000,063 | —- | M] () – C:\pclog_3716.dat
========== Files Created - No Company Name ==========
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – C:\pclog_3440.dat
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – \pclog_3440.dat
[2011/11/01 19:41:57 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/01 19:41:57 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/01 19:41:57 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/01 19:41:57 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/01 19:41:57 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – C:\Submission_Contract.pdf
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – \Submission_Contract.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – C:\ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – \ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – C:\GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – \GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – C:\winningargument.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – \winningargument.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – C:\sf_rcd_execsum.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – \sf_rcd_execsum.pdf
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – C:\2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – \2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – C:\National Estimator.lnk
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – \National Estimator.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – C:\1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – \1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – C:\Winamp.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – \Winamp.lnk
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – \Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – C:\Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – \Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – C:\Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – \Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – C:\Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – \Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – C:\FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – \FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – C:\PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – \PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – C:\Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – \Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – C:\D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – \D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – C:\Tutorial for National Estimator.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – \Tutorial for National Estimator.url
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – C:\pclog_3460.dat
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – \pclog_3460.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – C:\pclog_3496.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – \pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 14:34:32 | 000,002,519 | —- | C] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/28 09:39:54 | 000,000,680 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – C:\pclog_3636.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – \pclog_3636.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – C:\pclog_3652.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – \pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – C:\pclog_4268.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – \pclog_4268.dat
[2011/10/15 20:19:42 | 000,134,382 | —- | C] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – C:\pclog_3620.dat
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – \pclog_3620.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – C:\pclog_3648.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – \pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – C:\pclog_3716.dat
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – \pclog_3716.dat
[2011/10/04 20:10:07 | 000,000,189 | —- | C] () – \pclog_3500.dat
[2011/09/29 00:25:54 | 000,000,063 | —- | C] () – \pclog_3656.dat
[2011/09/14 11:47:40 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/08/24 20:19:10 | 000,056,320 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/06/29 13:47:56 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/06/13 08:47:01 | 1073,741,824 | —- | C] () – \pgbleach.27
[2011/05/08 10:01:03 | 000,000,120 | —- | C] () – C:\Users\Admin\AppData\Local\Snapadutodi.dat
[2011/05/08 10:01:03 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Local\Ivekalega.bin
[2011/04/26 15:58:54 | 000,000,066 | —- | C] () – C:\Windows\bi_group.ini
[2011/03/22 23:41:29 | 1073,741,824 | —- | C] () – \pgbleach.45
[2011/03/17 13:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/03/15 01:48:25 | 000,000,000 | —- | C] () – C:\Windows\HPMProp.INI
[2011/01/08 01:37:39 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\bibstats
[2010/12/25 20:53:38 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll
[2010/12/25 20:43:17 | 001,422,672 | —- | C] () – C:\Windows\SysWow64\cfgmig32.dll
[2010/12/25 20:43:17 | 000,263,504 | —- | C] () – C:\Windows\SysWow64\cfgmig32.exe
[2010/12/25 20:43:01 | 004,108,304 | —- | C] () – C:\Windows\SysWow64\win32cpr.dll
[2010/12/25 20:43:01 | 002,760,720 | —- | C] () – C:\Windows\SysWow64\svcprs32.exe
[2010/12/25 20:43:01 | 001,744,912 | —- | C] () – C:\Windows\SysWow64\winsflt.dll
[2010/12/25 20:43:01 | 000,098,320 | —- | C] () – C:\Windows\SysWow64\winsfinst.exe
[2010/12/25 20:43:00 | 003,207,184 | —- | C] () – C:\Windows\SysWow64\mdmcls32.exe
[2010/06/04 21:07:04 | 000,036,864 | —- | C] () – \nphssb.dll
[2010/06/04 21:07:04 | 000,000,247 | —- | C] () – \nphssb.xpt
[2010/06/04 21:04:21 | 000,098,136 | —- | C] () – C:\Windows\gzip.exe
[2010/05/31 16:27:08 | 000,000,000 | —- | C] () – C:\Windows\DVEdit.INI
[2010/05/11 22:30:25 | 000,000,062 | —- | C] () – C:\Windows\wininit.ini
[2010/04/07 11:25:11 | 000,037,027 | —- | C] () – C:\Windows\atmoUn.exe
[2010/02/16 00:17:13 | 000,004,096 | —- | C] () – C:\Users\Admin\AppData\Local\keyfile3.drm
[2010/02/01 22:38:22 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\FileOps.exe
[2010/01/31 18:43:33 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/25 18:44:18 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\downloads.m3u
[2009/12/08 22:52:35 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2009/12/08 22:52:35 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2009/12/08 22:52:35 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2009/12/08 22:52:35 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2009/12/08 22:52:35 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2009/12/08 22:52:35 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2009/12/08 22:52:35 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2009/12/08 22:52:35 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2009/12/08 22:52:35 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2009/12/08 22:52:35 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2009/12/08 22:52:35 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2009/12/08 22:52:35 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2009/12/08 22:50:16 | 000,000,044 | —- | C] () – C:\Windows\EPSNX400.ini
[2009/12/02 09:24:03 | 000,726,594 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/11/23 20:32:22 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2009/11/20 10:25:01 | 000,000,197 | —- | C] () – C:\Users\Admin\AppData\Roaming\default.rss
[2009/11/20 09:49:52 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/11/20 00:48:45 | 000,004,767 | —- | C] () – C:\Windows\Irremote.ini
[2009/11/19 00:19:06 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/11/19 00:18:37 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/11/19 00:18:09 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/19 00:17:54 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/11/17 17:42:22 | 000,019,313 | —- | C] () – C:\Users\Admin\AppData\Roaming\UserTile.png
[2009/11/17 16:49:45 | 000,001,460 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps64.dat
[2009/11/17 16:41:31 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2009/11/17 14:30:39 | 000,145,920 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/17 13:53:36 | 000,581,120 | —- | C] () – C:\Windows\mHotkey.exe
[2009/11/17 13:53:36 | 000,294,912 | —- | C] () – C:\Windows\PIC.dll
[2009/11/17 13:53:36 | 000,036,864 | —- | C] () – C:\Windows\LchDrvKey.exe
[2009/11/17 13:53:36 | 000,000,870 | —- | C] () – C:\Windows\mhotkey_reg.ini
[2009/09/10 17:31:13 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/09 20:29:25 | 000,001,324 | —- | C] () – C:\Windows\FF08_not_Spk_Hp.ini
[2008/01/09 20:29:25 | 000,001,269 | —- | C] () – C:\Windows\FF08_Render_Spk_Hp.ini
[2008/01/09 20:28:57 | 000,145,408 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2008/01/09 20:28:57 | 000,071,680 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2008/01/09 19:37:33 | 000,008,192 | R-S- | C] () – \BOOTSECT.BAK
[2008/01/09 19:37:32 | 000,333,257 | RHS- | C] () – \bootmgr
[2006/11/02 11:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/05/20 14:44:46 | 000,051,392 | —- | C] () – C:\Windows\SysWow64\drivers\atnt40k.sys
[2002/03/14 13:00:26 | 000,038,567 | —- | C] () – C:\Windows\SysWow64\pcpbios.exe
[1998/08/16 06:00:00 | 000,004,096 | —- | C] () – C:\Windows\SysWow64\sysres.dll
========== LOP Check ==========
[2010/09/27 19:11:30 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Amazon
[2011/10/01 04:00:48 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Azureus
[2010/11/21 14:05:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DelTel, Inc
[2009/12/09 22:54:06 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\EPSON
[2009/11/17 18:57:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Forte
[2009/12/02 09:19:57 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\GetRightToGo
[2009/12/08 23:02:23 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Leadertech
[2011/07/07 22:24:19 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\OpenCandy
[2011/01/20 15:16:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\SupportSoft
[2011/05/05 00:04:05 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Usuqz
[2010/03/19 12:08:06 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\webex
[2011/11/04 01:37:56 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
========== Alternate Data Streams ==========
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:D287FACF
< End of report >
The EXTRAS.TXT will be in next post.
~James