Lewg
Topic Starter
OTL logfile created on: 5/21/2012 4:12:50 PM - Run 2
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Lew\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.85% Memory free
4.21 Gb Paging File | 2.92 Gb Available in Paging File | 69.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.74 Gb Total Space | 69.56 Gb Free Space | 50.87% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 0.27 Gb Free Space | 2.72% Space Free | Partition Type: NTFS
Computer Name: CAROL-PC | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found –
PRC - [2012/05/21 16:10:17 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Lew\Downloads\OTL (1).com
PRC - [2012/04/26 09:12:10 | 000,113,592 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Adobe\Director\SWDNLD.EXE
PRC - [2012/03/26 17:08:12 | 000,931,200 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
PRC - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe
PRC - [2008/05/04 05:25:32 | 000,040,960 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/05/04 05:25:26 | 000,167,936 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/05/04 05:25:26 | 000,050,736 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/04 05:25:26 | 000,049,152 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) – C:\Windows\System32\stacsv.exe
========== Modules (No Company Name) ==========
MOD - [2012/05/16 20:46:34 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\ef684a2ee2f7276eec3973a0654d2bd4\System.Web.ni.dll
MOD - [2012/05/16 20:46:24 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 17:11:07 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/11 17:10:49 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/12/20 16:04:08 | 001,671,840 | —- | M] () – C:\Program Files\WOT\WOT.dll
MOD - [2008/05/19 02:25:24 | 000,054,784 | —- | M] () – C:\Windows\System32\bcmwlrmt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2012/05/04 21:26:35 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/26 17:03:40 | 000,214,952 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) [Auto | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE – (BBSvc)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) [Auto | Running] – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe – (WXRSS)
SRV - [2008/07/24 01:20:23 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/04/28 17:56:28 | 000,161,048 | —- | M] (Stardock Corporation) [Disabled | Stopped] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\stacsv.exe – (STacSV)
SRV - [2007/11/12 07:07:16 | 000,073,728 | —- | M] (Andrea Electronics Corporation) [Disabled | Stopped] – C:\Windows\System32\AEstSrv.exe – (AESTFilters)
SRV - [2007/03/21 14:00:04 | 000,355,096 | —- | M] (Intel Corporation) [Disabled | Stopped] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\RT-USB.sys – (RT-USB)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Running] – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys – (esgiguard)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\BCM42RLY.sys – (BCM42RLY)
DRV - [2012/05/21 16:04:41 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C6B3BC2C-2879-44EC-BCD7-C094B0616D1F}\MpKslef200719.sys – (MpKslef200719)
DRV - [2012/03/20 20:44:12 | 000,074,112 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2010/05/10 14:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/05/25 17:01:00 | 000,069,098 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\jl2005c.sys – (JL2005C)
DRV - [2008/05/04 05:25:24 | 000,164,400 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV - [2008/01/20 22:23:25 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2008/01/20 22:23:21 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV - [2007/11/12 07:07:28 | 000,330,240 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2007/09/06 12:35:16 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/08/04 20:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\.DEFAULT\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\S-1-5-18\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\S-1-5-18\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GPEA_en
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2011/10/03 11:37:36 | 000,434,545 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14956 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.9.1.0/…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54616514-34E7-4A11-A4D6-37C98C4F228A}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC1269BC-025B-49DB-8A8F-716A88F2C75A}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/05/11 09:56:17 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/05/11 09:56:17 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/05/11 09:56:16 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/05/11 09:56:16 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/05/11 09:56:16 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/05/11 09:55:56 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/05/11 09:55:56 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/05/11 09:55:56 | 002,044,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/05/09 00:04:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/05/04 23:17:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/05/04 23:17:17 | 000,476,960 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:17:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/21 16:02:17 | 000,606,552 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/05/21 16:02:17 | 000,106,376 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/05/21 15:56:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 15:56:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 15:56:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/16 20:36:43 | 000,002,519 | —- | M] () – C:\Users\Lew\Desktop\HiJackThis.lnk
[2012/05/13 20:59:47 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | M] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/11 17:09:03 | 000,271,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/07 22:22:13 | 000,002,263 | —- | M] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | M] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 23:16:57 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/05/04 23:16:56 | 000,476,960 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:16:56 | 000,472,864 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2012/05/04 21:38:57 | 000,000,253 | —- | M] () – C:\Users\Lew\Desktop\Compare Hotel Prices - Best Hotel Deals Guaranteed.url
[2012/05/04 21:26:32 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/05/04 21:26:32 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/04 21:14:56 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:43 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:59 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:42 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:12 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/04/23 00:40:36 | 000,000,403 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 1. - YouTube.url
[2012/04/23 00:29:08 | 000,005,191 | —- | M] () – C:\Users\Lew\Desktop\Watch Red Shoe Diaries Online, Full Episodes of Season 1 to 5 Yidio.url
[2012/04/22 21:55:32 | 000,000,638 | —- | M] () – C:\Users\Lew\Desktop\VCDS Release 11.11.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/13 20:59:47 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | C] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/07 22:22:13 | 000,002,263 | —- | C] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | C] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 21:14:56 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:58 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:41 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:11 | 000,001,828 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/23 00:40:36 | 000,000,403 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 1. - YouTube.url
[2012/04/23 00:29:08 | 000,005,191 | —- | C] () – C:\Users\Lew\Desktop\Watch Red Shoe Diaries Online, Full Episodes of Season 1 to 5 Yidio.url
[2011/11/13 18:15:45 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/10/02 14:01:03 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/10/02 13:51:12 | 000,038,868 | —- | C] () – C:\Windows\hpomdl03.dat.temp
[2011/10/02 13:51:12 | 000,029,359 | —- | C] () – C:\Windows\hpoins03.dat.temp
[2011/10/02 13:48:28 | 000,000,091 | —- | C] () – C:\Users\Lew\AppData\Local\fusioncache.dat
[2011/07/07 00:03:30 | 000,017,408 | —- | C] () – C:\Users\Lew\AppData\Local\WebpageIcons.db
< End of report >
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Lew\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.85% Memory free
4.21 Gb Paging File | 2.92 Gb Available in Paging File | 69.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.74 Gb Total Space | 69.56 Gb Free Space | 50.87% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 0.27 Gb Free Space | 2.72% Space Free | Partition Type: NTFS
Computer Name: CAROL-PC | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found –
PRC - [2012/05/21 16:10:17 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Lew\Downloads\OTL (1).com
PRC - [2012/04/26 09:12:10 | 000,113,592 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Adobe\Director\SWDNLD.EXE
PRC - [2012/03/26 17:08:12 | 000,931,200 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
PRC - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe
PRC - [2008/05/04 05:25:32 | 000,040,960 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/05/04 05:25:26 | 000,167,936 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/05/04 05:25:26 | 000,050,736 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/04 05:25:26 | 000,049,152 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) – C:\Windows\System32\stacsv.exe
========== Modules (No Company Name) ==========
MOD - [2012/05/16 20:46:34 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\ef684a2ee2f7276eec3973a0654d2bd4\System.Web.ni.dll
MOD - [2012/05/16 20:46:24 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 17:11:07 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/11 17:10:49 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/12/20 16:04:08 | 001,671,840 | —- | M] () – C:\Program Files\WOT\WOT.dll
MOD - [2008/05/19 02:25:24 | 000,054,784 | —- | M] () – C:\Windows\System32\bcmwlrmt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2012/05/04 21:26:35 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/26 17:03:40 | 000,214,952 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) [Auto | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE – (BBSvc)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) [Auto | Running] – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe – (WXRSS)
SRV - [2008/07/24 01:20:23 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/04/28 17:56:28 | 000,161,048 | —- | M] (Stardock Corporation) [Disabled | Stopped] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\stacsv.exe – (STacSV)
SRV - [2007/11/12 07:07:16 | 000,073,728 | —- | M] (Andrea Electronics Corporation) [Disabled | Stopped] – C:\Windows\System32\AEstSrv.exe – (AESTFilters)
SRV - [2007/03/21 14:00:04 | 000,355,096 | —- | M] (Intel Corporation) [Disabled | Stopped] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\RT-USB.sys – (RT-USB)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Running] – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys – (esgiguard)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\BCM42RLY.sys – (BCM42RLY)
DRV - [2012/05/21 16:04:41 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C6B3BC2C-2879-44EC-BCD7-C094B0616D1F}\MpKslef200719.sys – (MpKslef200719)
DRV - [2012/03/20 20:44:12 | 000,074,112 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2010/05/10 14:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/05/25 17:01:00 | 000,069,098 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\jl2005c.sys – (JL2005C)
DRV - [2008/05/04 05:25:24 | 000,164,400 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV - [2008/01/20 22:23:25 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2008/01/20 22:23:21 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV - [2007/11/12 07:07:28 | 000,330,240 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2007/09/06 12:35:16 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/08/04 20:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\.DEFAULT\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\S-1-5-18\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\S-1-5-18\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GPEA_en
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2011/10/03 11:37:36 | 000,434,545 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14956 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.9.1.0/…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54616514-34E7-4A11-A4D6-37C98C4F228A}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC1269BC-025B-49DB-8A8F-716A88F2C75A}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/05/11 09:56:17 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/05/11 09:56:17 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/05/11 09:56:16 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/05/11 09:56:16 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/05/11 09:56:16 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/05/11 09:55:56 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/05/11 09:55:56 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/05/11 09:55:56 | 002,044,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/05/09 00:04:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/05/04 23:17:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/05/04 23:17:17 | 000,476,960 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:17:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/21 16:02:17 | 000,606,552 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/05/21 16:02:17 | 000,106,376 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/05/21 15:56:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 15:56:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 15:56:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/16 20:36:43 | 000,002,519 | —- | M] () – C:\Users\Lew\Desktop\HiJackThis.lnk
[2012/05/13 20:59:47 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | M] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/11 17:09:03 | 000,271,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/07 22:22:13 | 000,002,263 | —- | M] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | M] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 23:16:57 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/05/04 23:16:56 | 000,476,960 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:16:56 | 000,472,864 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2012/05/04 21:38:57 | 000,000,253 | —- | M] () – C:\Users\Lew\Desktop\Compare Hotel Prices - Best Hotel Deals Guaranteed.url
[2012/05/04 21:26:32 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/05/04 21:26:32 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/04 21:14:56 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:43 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:59 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:42 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:12 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/04/23 00:40:36 | 000,000,403 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 1. - YouTube.url
[2012/04/23 00:29:08 | 000,005,191 | —- | M] () – C:\Users\Lew\Desktop\Watch Red Shoe Diaries Online, Full Episodes of Season 1 to 5 Yidio.url
[2012/04/22 21:55:32 | 000,000,638 | —- | M] () – C:\Users\Lew\Desktop\VCDS Release 11.11.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/13 20:59:47 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | C] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/07 22:22:13 | 000,002,263 | —- | C] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | C] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 21:14:56 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:58 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:41 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:11 | 000,001,828 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/23 00:40:36 | 000,000,403 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 1. - YouTube.url
[2012/04/23 00:29:08 | 000,005,191 | —- | C] () – C:\Users\Lew\Desktop\Watch Red Shoe Diaries Online, Full Episodes of Season 1 to 5 Yidio.url
[2011/11/13 18:15:45 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/10/02 14:01:03 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/10/02 13:51:12 | 000,038,868 | —- | C] () – C:\Windows\hpomdl03.dat.temp
[2011/10/02 13:51:12 | 000,029,359 | —- | C] () – C:\Windows\hpoins03.dat.temp
[2011/10/02 13:48:28 | 000,000,091 | —- | C] () – C:\Users\Lew\AppData\Local\fusioncache.dat
[2011/07/07 00:03:30 | 000,017,408 | —- | C] () – C:\Users\Lew\AppData\Local\WebpageIcons.db
< End of report >