Ok, I was able to get rkill to make the desktop cycle on and off. When I tried aswMBR again, I noticed the hourglass was showing a bit longer (maybe 5 seconds) but the program still will not open.
I did run the OTL scan and the OTL.txt log is below. I'll paste the Extras log in another post. Thanks again!
OTL logfile created on: 12/18/2011 4:11:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Chris\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 0.66 Gb Available Physical Memory | 44.15% Memory free
3.45 Gb Paging File | 2.69 Gb Available in Paging File | 77.89% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 213.20 Gb Total Space | 64.21 Gb Free Space | 30.12% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 89.92 Gb Free Space | 19.31% Space Free | Partition Type: NTFS
Drive G: | 19.63 Gb Total Space | 16.31 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: CHRIS-C3D63D9D4 | User Name: Chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Chris\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Iomega eGo Encrypt\eNOVAService.exe ()
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\TmPfw.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
========== Modules (No Company Name) ==========
MOD - c:\Program Files\Common Files\Akamai\netsession_win_b427739.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
MOD - C:\Program Files\Iomega eGo Encrypt\eNOVAService.exe ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security 14\PcSSE.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security 14\tmdbg.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEHook.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NMIndexingService) – File not found
SRV - (digiSPTIService) – File not found
SRV - (AppMgmt) – File not found
SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_b427739.dll ()
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (eNOVA Service) – C:\Program Files\Iomega eGo Encrypt\eNOVAService.exe ()
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (SandraAgentSrv) – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP2\RpcAgentSrv.exe (SiSoftware)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PcCtlCom) – C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (IDT, Inc.)
SRV - (Tmntsrv) – C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security 14\TmPfw.exe (Trend Micro Inc.)
========== Driver Services (SafeList) ==========
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman251) Acronis Try&Decide; and Restore Points filter (build 251) – C:\WINDOWS\system32\DRIVERS\tdrpm251.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (epmntdrv) – C:\WINDOWS\system32\epmntdrv.sys ()
DRV - (EuGdiDrv) – C:\WINDOWS\system32\EuGdiDrv.sys ()
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (FXUSBFilter) – C:\WINDOWS\system32\drivers\FXUSBFILTER.sys (Enova Technology Corp.)
DRV - (SANDRA) – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP2\WNt500x86\sandra.sys (SiSoftware)
DRV - (PLTurbo) – C:\WINDOWS\system32\drivers\plturbo.sys (Prolific Technology Inc.)
DRV - (PLTurbh) – C:\WINDOWS\system32\drivers\plturbh.sys (Prolific Technology Inc.)
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (NetBT) – C:\WINDOWS\system32\drivers\netbt.sys ()
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (TPkd) – C:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (ASPI32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-861567501-813497703-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.conduit.com/?SearchSource=10…;ctid=CT2475029
IE - HKU\S-1-5-21-861567501-813497703-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-861567501-813497703-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://search.yahoo.com/search?ei=UTF-8&fr;=yff35awe&p;="
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {524B8EF8-C312-11DB-8039-536F56D89593}:3.7.0.0
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.8
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100127023632
FF - prefs.js..extensions.enabledItems: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.17: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.17: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/27 16:49:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/14 09:02:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Ex\\UnicodeExtensionMap: 0000000EE5E83BF90C0A811EE0EFB83479A7009B
[2009/01/31 14:41:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Chris\Application Data\Mozilla\Extensions
[2011/12/17 07:42:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions
[2009/09/06 14:09:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/27 16:56:20 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/12/12 17:19:35 | 000,000,000 | —D | M] (MyAshampoo Community Toolbar) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2009/02/07 16:00:53 | 000,000,000 | —D | M] (Craigslist Image Preview Ext) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions\craigslistimagepreviewext@craigstoolbox
[2011/05/01 22:23:26 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions\[removed]
[2009/12/07 19:54:23 | 000,000,000 | —D | M] (Pterodactl) – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\extensions\[removed]
[2010/01/20 11:19:10 | 000,000,923 | —- | M] () – C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\z0ujyay8.default\searchplugins\conduit.xml
[2011/04/29 15:50:21 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/04 17:45:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHRIS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z0UJYAY8.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHRIS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z0UJYAY8.DEFAULT\EXTENSIONS\{524B8EF8-C312-11DB-8039-536F56D89593}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHRIS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z0UJYAY8.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
[2011/03/04 17:44:47 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/11/27 16:49:37 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/04 17:44:46 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/08 23:14:35 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/27 16:49:38 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
O1 HOSTS File: ([2011/12/18 11:27:24 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [IDTSysTrayApp] C:\WINDOWS\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [pccguide.exe] C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QT Lite\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKU\S-1-5-21-861567501-813497703-839522115-1004..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Chris\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKU\S-1-5-21-861567501-813497703-839522115-1004..\Run: [OE_OEM] C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKU\S-1-5-21-861567501-813497703-839522115-1004..\Run: [SansaDispatch] C:\Documents and Settings\Chris\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-813497703-839522115-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-861567501-813497703-839522115-1004\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-861567501-813497703-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-861567501-813497703-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-861567501-813497703-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: En&queue; current page with BID - C:\Program Files\Bulk Image Downloader\iemenu\iebidqueue.htm ()
O8 - Extra context menu item: Enqueue link tar&get; with BID - C:\Program Files\Bulk Image Downloader\iemenu\iebidlinkqueue.htm ()
O8 - Extra context menu item: Open &link; target with BID - C:\Program Files\Bulk Image Downloader\iemenu\iebidlink.htm ()
O8 - Extra context menu item: Open current page with BI&D; - C:\Program Files\Bulk Image Downloader\iemenu\iebid.htm ()
O8 - Extra context menu item: Open current page with BID Link E&xplorer; - C:\Program Files\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{156FC6F9-73D5-4134-885E-098DA546B2C6}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Chris\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chris\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/31 12:33:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/18 16:06:57 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Chris\Desktop\OTL.exe
[2011/12/18 15:20:50 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/18 15:19:31 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Chris\Desktop\aswMBR.exe
[2011/12/18 14:36:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\visit to st. paul
[2011/12/18 14:36:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\St. Paul weekend
[2011/12/18 14:36:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\mom's retirement
[2011/12/18 14:35:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\memorial weekend
[2011/12/18 14:35:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\christmas
[2011/12/18 10:38:37 | 000,000,000 | —D | C] – C:\ComboFix
[2011/12/18 09:50:56 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/18 09:44:07 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/12/18 09:44:07 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/12/18 09:44:07 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/12/18 09:44:07 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/12/18 09:42:42 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/12/18 09:41:29 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/18 09:34:10 | 004,342,882 | R— | C] (Swearware) – C:\Documents and Settings\Chris\Desktop\ComboFix.exe
[2011/12/15 21:44:45 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/15 21:33:54 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/15 21:33:50 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/15 21:33:01 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/14 19:54:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\New Folder
[2011/12/12 14:15:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PeerBlock
[2011/12/01 22:56:40 | 000,000,000 | R–D | C] – C:\Documents and Settings\Chris\Start Menu\Programs\Administrative Tools
[2011/11/27 16:52:57 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Chris\Recent
[2011/11/02 22:20:34 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Chris\Application Data\pcouffin.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/18 16:06:54 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Chris\Desktop\OTL.exe
[2011/12/18 16:04:01 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/12/18 16:02:13 | 001,008,141 | —- | M] () – C:\Documents and Settings\Chris\Desktop\rkill.com
[2011/12/18 15:59:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/18 15:59:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/18 15:43:33 | 001,008,141 | —- | M] () – C:\Documents and Settings\Chris\Desktop\rkill.exe
[2011/12/18 15:40:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/18 15:24:47 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Chris\Desktop\aswMBR.exe
[2011/12/18 14:46:34 | 000,014,460 | -HS- | M] () – C:\Documents and Settings\Chris\Local Settings\Application Data\iwsoqu7j4mhu4tjc5mlf2b630q1y
[2011/12/18 14:46:34 | 000,014,460 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\iwsoqu7j4mhu4tjc5mlf2b630q1y
[2011/12/18 11:27:24 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/18 10:28:30 | 000,545,946 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/18 10:28:30 | 000,116,024 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/18 09:51:13 | 000,000,437 | RHS- | M] () – C:\boot.ini
[2011/12/18 09:47:30 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/18 09:34:14 | 004,342,882 | R— | M] (Swearware) – C:\Documents and Settings\Chris\Desktop\ComboFix.exe
[2011/12/17 19:25:48 | 000,022,016 | —- | M] () – C:\Documents and Settings\Chris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/17 19:25:48 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/12/17 18:27:10 | 000,625,664 | —- | M] () – C:\Documents and Settings\Chris\Desktop\dds.scr
[2011/12/16 16:20:42 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\5ann6p.dat
[2011/12/15 21:28:30 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/15 19:41:57 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/15 19:34:02 | 000,016,352 | -HS- | M] () – C:\Documents and Settings\Chris\Local Settings\Application Data\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/15 19:34:02 | 000,016,352 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/14 06:42:49 | 002,164,592 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/14 03:19:20 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/23 07:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 07:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[2011/11/21 17:50:58 | 219,948,503 | —- | M] () – C:\Documents and Settings\Chris\Desktop\numero_group_wxdu_11_18_11.mp3
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/18 16:02:15 | 001,008,141 | —- | C] () – C:\Documents and Settings\Chris\Desktop\rkill.com
[2011/12/18 15:43:36 | 001,008,141 | —- | C] () – C:\Documents and Settings\Chris\Desktop\rkill.exe
[2011/12/18 14:41:52 | 000,014,460 | -HS- | C] () – C:\Documents and Settings\Chris\Local Settings\Application Data\iwsoqu7j4mhu4tjc5mlf2b630q1y
[2011/12/18 14:41:52 | 000,014,460 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\iwsoqu7j4mhu4tjc5mlf2b630q1y
[2011/12/18 09:51:11 | 000,000,321 | —- | C] () – C:\Boot.bak
[2011/12/18 09:50:59 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/12/18 09:44:07 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/12/18 09:44:07 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/12/18 09:44:07 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/12/18 09:44:07 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/12/18 09:44:07 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/12/17 18:27:11 | 000,625,664 | —- | C] () – C:\Documents and Settings\Chris\Desktop\dds.scr
[2011/12/16 16:20:42 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\5ann6p.dat
[2011/12/15 21:33:50 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/15 19:46:23 | 000,000,328 | —- | C] () – C:\Documents and Settings\Chris\Desktop\fix.reg
[2011/12/15 19:28:11 | 000,016,352 | -HS- | C] () – C:\Documents and Settings\Chris\Local Settings\Application Data\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/15 19:28:11 | 000,016,352 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/11/21 17:00:07 | 219,948,503 | —- | C] () – C:\Documents and Settings\Chris\Desktop\numero_group_wxdu_11_18_11.mp3
[2011/11/02 22:20:34 | 000,007,887 | —- | C] () – C:\Documents and Settings\Chris\Application Data\pcouffin.cat
[2011/11/02 22:20:34 | 000,001,144 | —- | C] () – C:\Documents and Settings\Chris\Application Data\pcouffin.inf
[2011/08/31 17:59:35 | 000,001,552 | —- | C] () – C:\WINDOWS\_ISENV31.INI
[2011/06/25 12:17:50 | 000,008,216 | -HS- | C] () – C:\Documents and Settings\Chris\Local Settings\Application Data\13gpr2hj11f04eu87q3qw51t4w67sao78p15gh8lk6e
[2011/06/25 12:17:50 | 000,008,216 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\13gpr2hj11f04eu87q3qw51t4w67sao78p15gh8lk6e
[2011/06/22 15:47:23 | 000,019,524 | -HS- | C] () – C:\Documents and Settings\Chris\Local Settings\Application Data\pjg4v1ibu1ntflw0v
[2011/06/22 15:47:23 | 000,019,524 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\pjg4v1ibu1ntflw0v
[2010/12/03 20:46:31 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2010/12/03 20:46:17 | 000,006,211 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2010/10/04 08:44:09 | 000,000,124 | —- | C] () – C:\Documents and Settings\Chris\Application Data\default.rss
[2010/09/25 14:31:23 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/09/18 02:07:24 | 001,774,720 | —- | C] () – C:\WINDOWS\System32\BootMan.exe
[2010/09/18 02:07:24 | 000,086,408 | —- | C] () – C:\WINDOWS\System32\setupempdrv03.exe
[2010/09/18 02:07:24 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2010/09/18 02:07:24 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2010/09/18 02:07:24 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2010/09/05 16:55:10 | 001,900,132 | —- | C] () – C:\WINDOWS\System32\ExpansionHD_Firmware.bin
[2010/09/05 16:55:10 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\DigiPlatformSupport.dll
[2010/09/02 21:16:29 | 000,000,128 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sandra.ldb
[2010/09/02 21:15:54 | 012,824,576 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sandra.mda
[2010/08/31 22:34:24 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2009/09/11 22:19:29 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2009/07/05 18:44:55 | 000,000,140 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/05/08 21:00:58 | 000,007,337 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/02/10 20:42:39 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/02/01 14:18:31 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\bwmedia.dll
[2009/01/31 20:49:53 | 000,000,307 | —- | C] () – C:\WINDOWS\olx98NT.sys
[2009/01/31 18:08:11 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2009/01/31 17:43:40 | 000,022,016 | —- | C] () – C:\Documents and Settings\Chris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/31 14:41:12 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/01/31 12:35:15 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/31 12:31:05 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/01/31 06:14:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/31 06:13:01 | 002,164,592 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/09/29 02:36:06 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2007/09/29 02:36:06 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2007/09/29 02:36:06 | 000,972,072 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2007/08/14 21:11:54 | 000,114,630 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/02/28 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 06:00:00 | 000,545,946 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 06:00:00 | 000,162,816 | —- | C] () – C:\WINDOWS\System32\drivers\netbt.sys
[2006/02/28 06:00:00 | 000,116,024 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 06:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/09/12 00:14:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2009/12/19 19:17:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2010/09/23 19:03:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/09/11 19:26:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/06/19 18:58:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonEPP
[2011/04/01 21:42:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/06/19 18:58:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2011/06/19 18:58:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX2
[2010/09/11 19:29:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMSetup
[2011/12/05 19:34:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/04/01 21:34:57 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/06/10 11:04:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\cO06511DaKgK06511
[2010/05/22 21:03:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/03/19 02:12:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easy CD-DA Extractor
[2009/09/11 22:19:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2009/05/08 20:18:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeRIP
[2010/10/01 02:40:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/12/03 20:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MAGIX
[2009/10/03 11:15:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2009/08/27 21:51:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2010/08/31 22:35:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2010/12/03 22:00:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RonyaSoft
[2010/04/04 10:17:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/09/11 22:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/09/12 06:47:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/03/03 23:53:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Acronis
[2009/12/19 19:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Ashampoo
[2011/09/22 22:23:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Ashampoo Cover Studio 2
[2009/06/18 16:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\BID
[2010/09/23 19:03:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Canneverbe Limited
[2011/04/01 21:34:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Canon
[2010/05/22 21:10:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\DAEMON Tools Lite
[2010/02/14 09:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Desktopicon
[2010/06/04 19:56:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\JAM Software
[2010/12/03 20:46:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\MAGIX
[2009/08/27 21:52:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Nikon
[2010/08/31 22:35:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\PACE Anti-Piracy
[2011/12/18 15:13:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\PriceGong
[2011/07/20 18:13:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Qywom
[2009/01/31 21:58:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\SanDisk
[2011/12/18 15:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\uTorrent
[2011/11/02 22:20:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Vso
[2009/08/13 22:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\wootalyzer
[2011/07/20 21:12:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Woylbi
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 1286 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:9z6M3PmdhrD3r2fSADKLYTu1JNl
@Alternate Data Stream - 1202 bytes -> C:\Documents and Settings\Chris\Cookies:h7IlfSfdalnv849QMNz
@Alternate Data Stream - 1190 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:HPHT8Fe7oKk1vJjiy2UZr
@Alternate Data Stream - 1161 bytes -> C:\Program Files\Outlook Express:Scs3hz5KO7Tf5kHrbRBwOioF5S
< End of report >