OTL logfile created on: 9/6/2012 11:54:46 PM - Run 1
OTL by OldTimer - Version 3.2.61.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.16 Gb Available Physical Memory | 58.19% Memory free
3.33 Gb Paging File | 2.70 Gb Available in Paging File | 80.90% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 100.47 Gb Free Space | 53.93% Space Free | Partition Type: NTFS
Computer Name: YOUR-96FC0AA548 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Documents and Settings\Owner\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\UMStor\Res.exe (ali)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Apple Computer\Adobe\bwnbipbao.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\PhoTags Express\PWSSearchHandler.dll ()
MOD - C:\WINDOWS\system32\wnaspi32.dll ()
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (Retrospect Helper) – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (Sunkfiltp) – C:\WINDOWS\System32\Drivers\sunkfiltp.sys File not found
DRV - (SANDRA) – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009\WNt500x86\Sandra.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCLEPCI) – C:\WINDOWS\system32\drivers\pclepci.sys File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\Owner\LOCALS~1\Temp\catchme.sys File not found
DRV - (MpKslfc0cacc6) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{76E3CDA0-78E3-4B0F-AD74-156CDE6A6471}\MpKslfc0cacc6.sys (Microsoft Corporation)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (Amusbprt) – C:\WINDOWS\system32\drivers\Amusbprt.sys (A4Tech Co.,Ltd.)
DRV - (Amfilter) – C:\WINDOWS\system32\drivers\Amfilter.sys (A4Tech Co.,Ltd.)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (BVRP Software)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (W55U01) – C:\WINDOWS\system32\drivers\W55U01.sys (Windows ® 2000 DDK provider)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (SQTECH905C) – C:\WINDOWS\system32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (STVqx5) – C:\WINDOWS\system32\drivers\STVqx5.sys (Digital Blue )
DRV - (STVqx5m) – C:\WINDOWS\system32\drivers\STVqx5m.sys (Digital Blue )
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (genmcmnUSB) – C:\WINDOWS\system32\drivers\gflmouhid.sys ()
DRV - (sonypvf2) – C:\WINDOWS\System32\drivers\sonypvf2.sys (Sony Corporation)
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (SunkFilt39) – C:\WINDOWS\system32\drivers\Sunkfilt39.sys (Alcor Micro Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (SoC PC-Camera Service) – C:\WINDOWS\system32\drivers\PFC027.sys ()
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (sonypvt2) – C:\WINDOWS\System32\drivers\sonypvt2.sys (Sony Corporation)
DRV - (sonypvl2) – C:\WINDOWS\System32\drivers\sonypvl2.sys (Sony Corporation)
DRV - (MXOFX) – C:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (NUVision) – C:\WINDOWS\system32\drivers\nuvvid2.sys (Zoran Ltd.)
DRV - (nuvaud2) – C:\WINDOWS\system32\drivers\nuvaud2.sys (Zoran Ltd.)
DRV - (MASPINT) – C:\WINDOWS\System32\drivers\MASPINT.SYS (MicroStaff Co.,Ltd.)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.bing.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{2E0F48F7-1ADC-465E-BB92-F743EC2E8A94}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" =
http://search.yahoo.com/search?p={searchTe…mp;fr=chr-i3752
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "
http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.selectedEngine: "Creative Commons"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:2.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.0.0.11
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=ffds1&p;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.2: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/21 13:06:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/21 13:06:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/06 18:43:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/06 18:42:12 | 000,000,000 | —D | M]
[2008/08/28 08:53:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/09/02 09:19:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bjontjbx.default\extensions
[2004/08/04 08:00:00 | 000,004,804 | —- | M] () (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bjontjbx.default\extensions\[removed]
[2012/09/06 18:42:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 18:43:52 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2006/09/21 16:25:40 | 000,049,152 | —- | M] (BitTorrent, Inc.) – C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2010/06/29 18:13:23 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/03/09 14:23:10 | 000,532,480 | —- | M] (Move Networks) – C:\Program Files\mozilla firefox\plugins\npmnqmp07030901.dll
[2006/11/18 21:45:10 | 001,245,184 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npRACtrl.dll
[2012/05/21 13:05:36 | 000,129,144 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2006/11/18 21:45:10 | 000,003,072 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
[2006/11/18 21:45:10 | 000,245,408 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\unicows.dll
[2012/08/29 10:58:58 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/08/29 10:58:58 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\google\chrome\application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: QuickTime Plug-in 7.5 (861) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\google\chrome\application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\google\chrome\application\21.0.1180.83\pdf.dll
CHR - plugin: BitTorrent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: MoveNetworks Quantum Media Player (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npmnqmp07030901.dll
CHR - plugin: LogMeIn Inc. Remote Access Components 1.0.0.250 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npRACtrl.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Entanglement = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Panda Poet = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\daicmhhkdcccfobnkidlhnieapcikadf\6_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Poppit = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2010/06/08 22:12:08 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Reg Error: Value error.) - {e7547097-66c9-440d-a4e6-400567105898} - Reg Error: Value error. File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [USB Storage Toolbox] C:\WINDOWS\UMStor\Res.exe (ali)
O4 - HKCU..\Run: [Adobe] C:\Documents and Settings\Owner\Local Settings\Application Data\Apple Computer\Adobe\bwnbipbao.dll ()
O4 - HKCU..\Run: [Internet Security] C:\Documents and Settings\All Users\Application Data\isecurity.exe File not found
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\Owner\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4B4513E2-4E57-43DF-9496-FCD37E9DFA64}
http://67.15.101.3/g_bin/eng/navy_2_0_0_28.cab (GameDesire Sea Battle)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1223434252000 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7}
http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://download.games.yahoo.com/games/web_…aploader_v6.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: YExplorer1_8US.CAB http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B197BC76-4F75-4CBB-A636-2697801E1B2D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 () -
http://us.f1.yahoofs.com/groups/g_1925614/…cD7uoCBm6LQHuv1
O24 - Desktop Components:1 () -
http://us.f315.mail.yahoo.com/ym/us/ShowLe…pos=0&Idx;=4
O24 - Desktop Components:2 () - file:///C:/DOCUME~1/Owner/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:3 (My Current Home Page) - About:Home
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/19 21:14:03 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{2cbda127-7fbb-11e1-b2c8-0011116b8630}\Shell - "" = AutoRun
O33 - MountPoints2\{2cbda127-7fbb-11e1-b2c8-0011116b8630}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2cbda127-7fbb-11e1-b2c8-0011116b8630}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/09/06 23:49:29 | 000,599,552 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/09/06 23:39:23 | 002,211,928 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\tdsskiller.exe
[2012/09/06 18:42:04 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/09/06 12:17:41 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2012/09/06 12:01:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2012/09/05 12:26:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\photos jennifers robert moses Sept 1 2012
[2012/08/25 23:58:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Western_Digital
[2012/08/25 15:27:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2012/08/25 15:25:54 | 000,000,000 | —D | C] – C:\Program Files\Western Digital
[2012/08/25 15:25:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WD SmartWare
[2012/08/25 15:25:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Western Digital
[2012/08/23 17:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\New Folder (3)
[2012/08/23 17:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Photos from Phones
[2004/12/04 09:58:41 | 000,487,424 | —- | C] (Citrix Online) – C:\Documents and Settings\Owner\chatlnk.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/06 23:49:05 | 000,599,552 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/09/06 23:47:01 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{3ACFEDC2-BB99-4E91-A287-FC07563D196B}.job
[2012/09/06 23:39:10 | 002,211,928 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\tdsskiller.exe
[2012/09/06 23:38:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/06 12:25:29 | 000,070,628 | —- | M] () – C:\Documents and Settings\Owner\Desktop\What the tech.htm
[2012/09/06 12:17:35 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2012/09/06 12:01:43 | 000,000,951 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/09/06 12:01:43 | 000,000,933 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2012/09/06 10:38:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/06 07:33:27 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/09/06 07:26:25 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1234179448-1215034524-384412549-1003.job
[2012/09/06 07:26:22 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/09/06 07:26:21 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2012/09/06 07:26:20 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1234179448-1215034524-384412549-1008.job
[2012/09/06 07:26:20 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1234179448-1215034524-384412549-1007.job
[2012/09/06 07:23:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/09/06 07:23:20 | 2137,833,472 | -HS- | M] () – C:\hiberfil.sys
[2012/09/05 21:42:37 | 000,493,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/09/04 22:19:26 | 000,034,568 | —- | M] () – C:\Documents and Settings\Owner\Desktop\LP conversion kit Invoice.htm
[2012/09/03 14:35:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1234179448-1215034524-384412549-1007.job
[2012/09/03 13:07:01 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1234179448-1215034524-384412549-1003.job
[2012/09/03 07:20:00 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1234179448-1215034524-384412549-1008.job
[2012/08/31 09:58:36 | 000,638,851 | —- | M] () – C:\Documents and Settings\Owner\Desktop\acro dance kings park Fall 2013.pdf
[2012/08/27 23:45:24 | 000,876,607 | —- | M] () – C:\Documents and Settings\Owner\Desktop\class request.pdf
[2012/08/27 18:34:39 | 000,189,386 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ny-circus-arts.htm
[2012/08/27 18:31:47 | 000,033,008 | —- | M] () – C:\Documents and Settings\Owner\Desktop\circus arts camp.htm
[2012/08/27 17:07:46 | 000,058,528 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gymnastics artistic.htm
[2012/08/26 00:04:34 | 002,352,580 | —- | M] () – C:\Documents and Settings\Owner\Desktop\My Book back-up.pdf
[2012/08/25 17:12:17 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/08/25 15:27:11 | 000,001,057 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk
[2012/08/22 11:12:18 | 000,014,641 | —- | M] () – C:\Documents and Settings\Owner\Desktop\tutoring_jobs.htm
[2012/08/16 22:35:16 | 000,008,459 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Purple Gables Bed & Breakfast, Amherst, MA.htm
[2012/08/16 22:07:57 | 000,013,852 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Massachusetts Gourmet Bed & Breakfast _ B&B; Hot Tub _ MA Tourism.htm
[2012/08/16 10:50:11 | 000,000,792 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2012/08/16 00:07:44 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/08/15 22:13:26 | 000,190,369 | —- | M] () – C:\Documents and Settings\Owner\Desktop\contacts for phome.CSV
[2012/08/15 22:13:24 | 000,038,470 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Comma Separated Values (DOS).ADR
[2012/08/15 15:27:33 | 000,222,263 | -H– | M] () – C:\Documents and Settings\Owner\Desktop\ZbThumbnail.info
[2012/08/14 20:02:20 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/06 12:25:29 | 000,070,628 | —- | C] () – C:\Documents and Settings\Owner\Desktop\What the tech.htm
[2012/09/06 12:01:02 | 000,000,951 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/09/06 12:01:02 | 000,000,933 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2012/09/04 22:19:24 | 000,034,568 | —- | C] () – C:\Documents and Settings\Owner\Desktop\LP conversion kit Invoice.htm
[2012/08/31 09:58:32 | 000,638,851 | —- | C] () – C:\Documents and Settings\Owner\Desktop\acro dance kings park Fall 2013.pdf
[2012/08/27 23:45:24 | 000,876,607 | —- | C] () – C:\Documents and Settings\Owner\Desktop\class request.pdf
[2012/08/27 18:34:38 | 000,189,386 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ny-circus-arts.htm
[2012/08/27 18:31:46 | 000,033,008 | —- | C] () – C:\Documents and Settings\Owner\Desktop\circus arts camp.htm
[2012/08/27 17:07:44 | 000,058,528 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gymnastics artistic.htm
[2012/08/26 00:37:23 | 000,532,448 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/08/26 00:04:34 | 002,352,580 | —- | C] () – C:\Documents and Settings\Owner\Desktop\My Book back-up.pdf
[2012/08/25 15:27:11 | 000,001,057 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk
[2012/08/22 11:12:17 | 000,014,641 | —- | C] () – C:\Documents and Settings\Owner\Desktop\tutoring_jobs.htm
[2012/08/16 22:35:15 | 000,008,459 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Purple Gables Bed & Breakfast, Amherst, MA.htm
[2012/08/16 22:07:55 | 000,013,852 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Massachusetts Gourmet Bed & Breakfast _ B&B; Hot Tub _ MA Tourism.htm
[2012/08/15 22:13:25 | 000,190,369 | —- | C] () – C:\Documents and Settings\Owner\Desktop\contacts for phome.CSV
[2012/08/15 17:16:38 | 000,038,470 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Comma Separated Values (DOS).ADR
[2012/02/23 13:36:15 | 000,000,106 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2012/02/15 23:58:19 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/08/20 18:58:02 | 000,214,952 | —- | C] () – C:\WINDOWS\hpoins35.dat.temp
[2011/08/20 15:42:41 | 000,001,069 | —- | C] () – C:\WINDOWS\hpomdl35.dat.temp
[2011/01/30 11:57:39 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/24 09:42:21 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\GUITOOLS.DLL
[2010/05/21 20:53:50 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\housecall.guid.cache
[2008/10/07 20:00:14 | 000,077,824 | —- | C] () – C:\Program Files\Startup.exe
[2006/07/03 22:56:02 | 000,063,730 | —- | C] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2004/12/14 10:14:25 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2004/11/29 23:39:33 | 000,000,238 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2004/11/28 22:09:08 | 000,068,608 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ==========
[2011/09/04 10:27:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BarbieFashionShow2008
[2005/05/04 21:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DataViz
[2005/04/15 19:04:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2010/03/29 22:22:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Photodex
[2004/12/29 18:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2005/04/24 16:22:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/02/18 12:50:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2007/05/23 01:17:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/25 14:24:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/06/29 19:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2008/01/29 21:02:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivendi Universal Games
[2012/08/25 15:27:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2011/09/05 11:22:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2010/11/11 10:58:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2008/10/07 21:59:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2007/10/22 01:11:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2010/03/19 10:30:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ChessBase
[2011/09/28 07:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2005/07/12 15:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Common Files
[2005/04/30 04:29:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Enigma Browser
[2010/11/11 21:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EuroTalk
[2011/07/09 10:21:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2005/04/15 19:02:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HotSync
[2005/04/15 19:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2007/09/22 22:13:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2010/06/29 18:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2009/03/15 11:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2009/01/01 15:53:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PhotoParade
[2012/04/12 12:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SanDisk
[2010/06/29 19:20:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SoftGrid Client
[2005/01/17 16:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2010/06/29 18:00:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TP
[2010/03/10 17:12:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuxPaint
[2011/02/20 18:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Unity
[2007/02/14 23:02:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2009/01/05 17:22:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Search
[2012/09/06 23:47:01 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{3ACFEDC2-BB99-4E91-A287-FC07563D196B}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/01/30 20:30:00 | 000,135,168 | —- | M] (Netsurfer, Inc.) – C:\DHCPD.exe
[2007/01/30 20:30:00 | 000,790,528 | —- | M] (Netsurfer, Inc.) – C:\setup32.exe
[2007/01/30 20:30:00 | 000,344,064 | —- | M] (Netsurfer, Inc.) – C:\Yampa.exe
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< C:\Windows\assembly\tmp\U\*.* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ECF5194F
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E758E1CB
< End of report >