OTL logfile created on: 2/12/2012 11:45:04 AM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Leonard Roe\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.25 Gb Total Physical Memory | 0.68 Gb Available Physical Memory | 54.55% Memory free
1.48 Gb Paging File | 1.08 Gb Available in Paging File | 72.86% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 12.43 Gb Free Space | 36.88% Space Free | Partition Type: NTFS
Computer Name: DG1BWS51 | User Name: Leonard Roe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avutil-51.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avformat-53.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avcodec-53.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\gcswf32.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\ustor.dll ()
MOD - C:\Program Files\Dell\Media Experience\DirWatcher.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\FPXLIB.DLL ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKsl51de008b) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{295D80E9-CFC8-4155-A86F-2FCD9DBD3083}\MpKsl51de008b.sys (Microsoft Corporation)
DRV - (NPF) – C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (PD1030VID) – C:\WINDOWS\SYSTEM32\DRIVERS\p1030vid.sys (Creative Technology Ltd.)
DRV - (C21ndisXP) – C:\WINDOWS\SYSTEM32\DRIVERS\C21ndisXP.sys (Com21, Inc)
DRV - (QV2KUX) – C:\WINDOWS\SYSTEM32\DRIVERS\qv2kux.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:0.6.0.13
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100211.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/17 21:22:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/11 10:37:06 | 000,000,000 | —D | M]
[2008/10/28 10:34:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Extensions
[2011/09/06 11:25:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions
[2009/09/14 11:14:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 12:16:33 | 000,000,000 | —D | M] (Speed Dial) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/02/13 16:33:31 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/13 09:18:27 | 000,000,000 | —D | M] ("AutoPager") – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2010/02/04 12:16:29 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2012/02/11 11:34:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/03 17:33:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/15 17:25:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/02/11 11:34:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/02/11 11:34:24 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/07/11 16:48:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.11_0\
CHR - Extension: YouTube = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Autocomplete = on = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ecpgkdflcnofdbbkiggklcfmgbnbabhh\1.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/05/03 12:52:18 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: auctiva.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: rubylane.com ([www] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157106795703 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} http://www.ipernity.com/E/Applets/Uploader…oader4.cab?v4.7 (Image Uploader Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{060AEA6E-F159-4837-8F62-2717DBE4A491}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{675F733C-F963-4B18-885E-DBA958852641}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/11 11:50:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Solid State Networks
[2012/02/11 11:35:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/02/11 11:34:53 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/11 11:34:53 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/11 11:34:53 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/11 11:34:53 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/10 15:46:02 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/08 14:46:33 | 004,733,440 | —- | C] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:40 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/02/06 17:31:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Leonard Roe\Recent
========== Files - Modified Within 30 Days ==========
[2012/02/12 11:47:12 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/12 11:44:20 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/12 11:39:39 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/02/12 11:39:12 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/12 11:39:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2012/02/12 11:39:03 | 1340,133,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/12 11:23:00 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006UA.job
[2012/02/12 11:01:04 | 000,139,264 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\SystemLook.exe
[2012/02/12 05:23:00 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006Core.job
[2012/02/11 18:30:06 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8DD95D15-9132-4CA1-8998-B4F91695AF3E}.job
[2012/02/11 12:15:39 | 000,879,700 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\SecurityCheck.exe
[2012/02/11 11:55:37 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/02/11 11:34:15 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/11 11:34:15 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/11 11:34:15 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/11 11:34:15 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/11 11:34:13 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/10 16:14:00 | 000,008,628 | -H– | M] () – C:\WINDOWS\System32\ZSHP1020.GID
[2012/02/10 16:07:00 | 000,336,319 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\FSS.exe
[2012/02/10 02:29:33 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 20:45:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/08 14:47:19 | 004,733,440 | —- | M] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
========== Files Created - No Company Name ==========
[2012/02/12 11:01:10 | 000,139,264 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\SystemLook.exe
[2012/02/11 12:15:30 | 000,879,700 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\SecurityCheck.exe
[2012/02/11 11:55:37 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/02/11 11:55:36 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/02/10 16:06:52 | 000,336,319 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\FSS.exe
[2012/01/27 20:53:46 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2010/03/09 13:54:08 | 000,150,240 | —- | C] () – C:\WINDOWS\System32\drivers\MLTCAP.sys
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/03/01 09:01:16 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2009/01/09 11:49:53 | 000,054,088 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/04/16 02:56:28 | 000,000,135 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\fusioncache.dat
[2008/04/04 13:35:41 | 000,000,086 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/06 15:19:24 | 000,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2006/12/11 11:46:20 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/12/11 11:46:20 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2006/11/10 03:24:30 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2006/10/05 11:45:27 | 000,000,325 | —- | C] () – C:\WINDOWS\PSTUDIO.INI
[2006/09/25 12:57:55 | 000,002,301 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/01 05:43:25 | 000,000,064 | —- | C] () – C:\WINDOWS\sysdat.dll
[2005/02/03 03:36:23 | 000,000,347 | —- | C] () – C:\WINDOWS\ulead32.ini
[2005/02/02 01:07:36 | 000,014,211 | R— | C] () – C:\WINDOWS\twacker.ini
[2005/01/21 18:24:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/08 18:14:22 | 000,373,760 | —- | C] () – C:\WINDOWS\System32\xnmba450.dll
[2004/11/08 18:14:22 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\xnmhb450.dll
[2004/11/08 18:14:22 | 000,066,048 | —- | C] () – C:\WINDOWS\System32\xnmte450.dll
[2004/11/08 18:14:22 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\xnmhn450.dll
[2004/11/08 18:14:16 | 000,004,036 | —- | C] () – C:\WINDOWS\System32\apcctr.ini
[2004/10/22 17:10:52 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\mcrtl32(2)(2).dll
[2004/10/22 17:10:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/10/22 12:29:54 | 000,000,329 | —- | C] () – C:\WINDOWS\dellstat.ini
[2004/10/17 20:54:01 | 000,006,656 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/10/17 20:50:15 | 000,061,678 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JPR.{PB
[2004/10/17 20:50:15 | 000,012,358 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JCM.{PB
[2004/10/17 17:32:09 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/10/17 13:56:37 | 000,000,738 | —- | C] () – C:\WINDOWS\ahd3.ini
[2004/10/16 15:43:04 | 000,000,154 | —- | C] () – C:\WINDOWS\PCStudy.ini
[2004/10/16 12:39:38 | 000,000,012 | —- | C] () – C:\WINDOWS\XBIBLEST.INI
[2004/10/10 16:08:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/10 16:03:24 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/10/10 15:58:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/10/10 15:58:37 | 000,000,304 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/10/10 15:49:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/10/10 15:48:28 | 000,445,762 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/10/10 15:48:28 | 000,072,556 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/10/10 15:36:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 13:08:08 | 000,262,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 10:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 16:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 15:09:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/02/10 14:08:00 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 14:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\BOOT.PCP:SummaryInformation
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >