OTL logfile created on: 12/17/2011 10:23:27 PM - Run 2 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\David N. Leh\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.25 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 62.80% Memory free 7.00 Gb Paging File | 6.08 Gb Available in Paging File | 86.90% Paging File free Paging file location(s): C:\pagefile.sys 4000 4000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 462.71 Gb Total Space | 350.74 Gb Free Space | 75.80% Space Free | Partition Type: NTFS Drive E: | 149.05 Gb Total Space | 22.07 Gb Free Space | 14.81% Space Free | Partition Type: NTFS Drive G: | 465.65 Gb Total Space | 359.11 Gb Free Space | 77.12% Space Free | Partition Type: FAT32 Computer Name: D51LHP91 | User Name: David N. Leh | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - C:\Documents and Settings\David N. Leh\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\GFI Software\VIPRE\SBAMTray.exe (GFI Software) PRC - C:\Program Files\GFI Software\VIPRE\SBAMSvc.exe (GFI Software) PRC - C:\Program Files\GFI Software\VIPRE\SBPIMSvc.exe (GFI Software) PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com)) PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.) PRC - C:\Program Files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe () PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe () PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe (Motorola) PRC - C:\Program Files\Lexmark Pro200-S500 Series\ezprint.exe () PRC - C:\Program Files\Lexmark Pro200-S500 Series\lxebmon.exe () PRC - C:\WINDOWS\system32\lxebcoms.exe ( ) PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe (Sunbelt Software, Inc.) PRC - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe (Sunbelt Software, Inc.) PRC - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe (Sunbelt Software, Inc.) PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\Runservice.exe () PRC - C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.) PRC - E:\Program Files\SERVINFO\ServInfo.exe (Michael Frantzeskakis) PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe () [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - C:\Program Files\GFI Software\VIPRE\Definitions\libMachoUniv.dll () MOD - C:\Program Files\GFI Software\VIPRE\Definitions\libBase64.dll () MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll () MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll () MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll () MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll () MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll () MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll () MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () MOD - C:\Program Files\Mozilla Firefox\mozjs.dll () MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Program Files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe () MOD - C:\Program Files\Verizon V CAST Media Manager\libexpat.dll () MOD - C:\Program Files\Verizon V CAST Media Manager\sqlite3.dll () MOD - C:\Program Files\Verizon V CAST Media Manager\avutil-50.dll () MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll () MOD - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe () MOD - C:\Program Files\Lexmark Pro200-S500 Series\ezprint.exe () MOD - C:\Program Files\Lexmark Pro200-S500 Series\lxebmon.exe () MOD - C:\Program Files\Lexmark Pro200-S500 Series\epoemdll.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\epstring.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\epwizres.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\epwizard.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\customui.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\epfunct.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\eputil.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\imagutil.dll () MOD - C:\Program Files\Lexmark\Pro200-S500 Series\lxebdrs.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\lxebdrs.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\lxebscw.dll () MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll () MOD - C:\WINDOWS\system32\quartz.dll () MOD - C:\WINDOWS\system32\LXEBPMON.DLL () MOD - C:\Program Files\Lexmark\Pro200-S500 Series\lxebmicro.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\LXEBalm.dll () MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxebdrpp.dll () MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxebdatr.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\iptk.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\4.0.114.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\4.0.114.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.145.4__540d4816ead86321\Intuit.Spc.Esd.Core.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll () MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.56.0__28c9bcd4dddc48a1\System.Data.SQLite.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Portability\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Portability.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.ExceptionHandling\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.ExceptionHandling.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Logging\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.Logging.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Config\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.Config.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll () MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll () MOD - C:\Program Files\Lexmark\Pro200-S500 Series\lxebcaps.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\lxebcaps.dll () MOD - C:\Program Files\Lexmark Pro200-S500 Series\lxebptp.dll () MOD - C:\WINDOWS\system32\LXEBsmr.dll () MOD - C:\WINDOWS\system32\LXEBsm.dll () MOD - C:\WINDOWS\system32\LXEBoem.dll () MOD - C:\Program Files\ffdshow\ffdshow.ax () MOD - C:\WINDOWS\system32\qedit.dll () MOD - C:\WINDOWS\system32\msdmo.dll () MOD - C:\WINDOWS\system32\dxmasf.dll () MOD - C:\WINDOWS\system32\devenum.dll () MOD - C:\WINDOWS\system32\ctmmactl.dll () MOD - C:\Program Files\Sunbelt Software\Personal Firewall\PocoXML.dll () MOD - C:\Program Files\Sunbelt Software\Personal Firewall\PocoFoundation.dll () MOD - C:\Program Files\Sunbelt Software\Personal Firewall\PocoExt.dll () MOD - C:\WINDOWS\mmfs.dll () MOD - C:\WINDOWS\Runservice.exe () MOD - C:\Program Files\WinRAR\RarExt.dll () MOD - C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll () MOD - C:\Program Files\Google\Google Desktop Search\GoogleDesktopDeskbar2.dll () MOD - C:\Program Files\Google\Google Desktop Search\GoogleDesktopHyper.dll () MOD - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll () MOD - C:\Program Files\Sunbelt Software\Personal Firewall\ssleay32.dll () MOD - C:\Program Files\Sunbelt Software\Personal Firewall\libeay32.dll () MOD - C:\Program Files\GFI Software\VIPRE\unrar.dll () MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll () MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe () [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - (AppMgmt) -- File not found SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited) SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.) SRV - (SBAMSvc) -- C:\Program Files\GFI Software\VIPRE\SBAMSvc.exe (GFI Software) SRV - (SBPIMSvc) -- C:\Program Files\GFI Software\VIPRE\SBPIMSvc.exe (GFI Software) SRV - (CarboniteService) -- C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com)) SRV - (MotoConnect Service) -- C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe () SRV - (lxeb_device) -- C:\WINDOWS\System32\lxebcoms.exe ( ) SRV - (lxebCATSCustConnectService) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxebserv.exe () SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (SPF4) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe (Sunbelt Software, Inc.) SRV - (SbPF.Launcher) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe (Sunbelt Software, Inc.) SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.) SRV - (HPM1319RcvFaxSrvc) -- C:\Program Files\HP\HP LaserJet M1319 MFP Series\ReceiveFaxUtility.exe (Marvell) SRV - (Just Flight Limited License Service) -- C:\Program Files\Common Files\Just Flight Limited Shared\Service\JustFlightLimitedLicSvc.exe (Just Flight Limited) SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH) SRV - (DSBrokerService) -- C:\Program Files\DellSupport\brkrsvc.exe () SRV - (Diskeeper) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation) SRV - (LicCtrlService) -- C:\WINDOWS\Runservice.exe () [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB) DRV - (sbtis) -- C:\WINDOWS\system32\drivers\sbtis.sys (GFI Software) DRV - (sbapifs) -- C:\WINDOWS\system32\drivers\sbapifs.sys (GFI Software) DRV - (sbaphd) -- C:\WINDOWS\system32\drivers\sbaphd.sys (GFI Software) DRV - (SBRE) -- C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software) DRV - (NGS) -- c:\VIRUSfighter\Nvc\Bin\ngs.sys (Norman ASA) DRV - (SbFw) -- C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.) DRV - (hap17v2k) -- C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd) DRV - (hap16v2k) -- C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd) DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd) DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd) DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd) DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd) DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.) DRV - (ctdvda2k) -- C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd) DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd) DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd) DRV - (CTERFXFX.SYS) -- C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd) DRV - (CTERFXFX) -- C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd) DRV - (CTSBLFX.SYS) -- C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd) DRV - (CTSBLFX) -- C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd) DRV - (CTAUDFX.SYS) -- C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd) DRV - (CTAUDFX) -- C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd) DRV - (COMMONFX.SYS) -- C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd) DRV - (COMMONFX) -- C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd) DRV - (SBHIPS) -- C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.) DRV - (SBFWIMCL) -- C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.) DRV - (HP1319FAX) -- C:\WINDOWS\system32\drivers\HP1319FAX.sys (Marvell Semiconductor, Inc.) DRV - (HP1319EWS) -- C:\WINDOWS\system32\drivers\HP1319EWS.sys (Marvell Semiconductor, Inc.) DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows (R) 2000 DDK provider) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (elagopro) -- C:\WINDOWS\system32\drivers\elagopro.sys (Gteko Ltd.) DRV - (elaunidr) -- C:\WINDOWS\system32\drivers\elaunidr.sys (Gteko Ltd.) DRV - (dsunidrv) -- C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.) DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation ) DRV - (msloop) -- C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation) DRV - (DSproct) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.) DRV - (SaiNtBus) -- C:\WINDOWS\system32\drivers\SaiBus.sys (Saitek) DRV - (SaiH0461) -- C:\WINDOWS\system32\drivers\SaiH0461.sys (Saitek) DRV - (RivaTuner32) -- C:\Program Files\RivaTuner v2.0 RC 16\RivaTuner32.sys () DRV - (NVStrap) -- C:\WINDOWS\System32\drivers\NVStrap.sys () DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions) DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions) DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions) DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions) DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions) DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions) DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions) DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions) DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions) DRV - (senfilt) -- C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.) DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.) DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.) DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dejazzd.com/my_jazzd IE - HKU\S-1-5-21-2464157562-697926883-618238203-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2464157562-697926883-618238203-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q=" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Bing" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..network.proxy.type: 4 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll () FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/19 05:59:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/12 10:03:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/22 19:03:00 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Documents and Settings\David N. Leh\Application Data\IDM\idmmzcc3 [2010/09/27 20:53:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Extensions [2011/12/14 18:11:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Firefox\Profiles\3uu73kfu.default\extensions [2011/12/14 18:11:06 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Firefox\Profiles\3uu73kfu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2009/06/14 07:31:54 | 000,000,000 | ---D | M] (IE Tab) -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Firefox\Profiles\3uu73kfu.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2011/08/19 13:16:31 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Firefox\Profiles\3uu73kfu.default\extensions\[removed] [2010/09/07 20:41:54 | 000,002,554 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Firefox\Profiles\3uu73kfu.default\searchplugins\askcom.xml [2009/03/08 22:15:34 | 000,001,632 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Application Data\Mozilla\Firefox\Profiles\3uu73kfu.default\searchplugins\live-search.xml [2011/11/12 10:04:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011/11/12 10:03:10 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2008/06/18 02:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll [2010/09/08 21:09:17 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2005/04/27 17:31:10 | 000,225,280 | ---- | M] (Asgard Software Inc.) -- C:\Program Files\mozilla firefox\plugins\NPUploader.dll [2011/10/03 20:00:25 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011/11/12 10:03:10 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Yahoo! () CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEncoding}&fr=crmas&p={searchTerms} CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms} CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\David N. Leh\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.0\ O1 HOSTS File: ([2011/12/13 23:18:58 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll File not found O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll (Dell Inc.) O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll () O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll File not found O3 - HKLM\..\Toolbar: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_1.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll File not found O3 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll File not found O3 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\..\Toolbar\WebBrowser: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_1.dll (Yahoo! Inc.) O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.) O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.) O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark Pro200-S500 Series\ezprint.exe () O4 - HKLM..\Run: [lxebmon.exe] C:\Program Files\Lexmark Pro200-S500 Series\lxebmon.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe () O4 - HKLM..\Run: [SBAMTray] C:\Program Files\GFI Software\VIPRE\SBAMTray.exe (GFI Software) O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKU\S-1-5-21-2464157562-697926883-618238203-1006..\Run: [HLBackupScheduler] C:\Program Files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe () O4 - Startup: C:\Documents and Settings\David N. Leh\Start Menu\Programs\Startup\V CAST Media Monitor.lnk = File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O7 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites) O15 - HKU\S-1-5-21-2464157562-697926883-618238203-1006\..Trusted Domains: localhost ([]* in Local intranet) O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB (Reg Error: Value error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4CC6A2A3-9DA6-4BDE-A594-B5A79C80ED19}: DhcpNameServer = 192.168.254.254 O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\David N. Leh\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\David N. Leh\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2010/08/14 00:17:28 | 000,000,000 | -H-D | M] - G:\autorun -- [ FAT32 ] O32 - AutoRun File - [2008/02/25 10:30:42 | 000,000,054 | RHS- | M] () - G:\autorun.in_2.org -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (OODBS) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011/12/17 22:21:06 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\David N. Leh\Desktop\OTL.exe [2011/12/17 10:37:07 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2011/12/16 23:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David N. Leh\Start Menu\Programs\Latin VFR Cayman Islands Scenery [2011/12/16 06:20:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP [2011/12/15 20:11:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2011/12/15 03:29:41 | 000,077,816 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\sbapifs.sys [2011/12/15 03:28:22 | 000,021,240 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\sbaphd.sys [2011/12/14 20:43:31 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE [2011/12/14 20:26:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David N. Leh\Desktop\Dave 2 [2011/12/14 18:54:25 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys [2011/12/14 18:54:15 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft [2011/12/14 18:54:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft [2011/12/14 18:36:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GFI Software [2011/12/14 18:36:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\VDD [2011/12/14 18:28:45 | 000,217,976 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\sbtis.sys [2011/12/13 23:32:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2011/12/13 23:04:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files [2011/12/13 23:03:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData [2011/12/13 22:58:48 | 000,000,000 | ---D | C] -- C:\0a45f3187bc95bc30bee73 [2011/12/13 22:58:39 | 000,000,000 | ---D | C] -- C:\f2074c84deefd58086f663 [2011/12/09 19:58:54 | 000,000,000 | R--D | C] -- C:\Documents and Settings\David N. Leh\Recent [2011/12/09 19:06:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David N. Leh\Start Menu\Programs\System Fix [2011/11/26 14:17:51 | 000,000,000 | ---D | C] -- C:\users [2011/11/26 14:17:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Aimersoft [2011/11/26 14:17:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David N. Leh\My Documents\Aimersoft DVD Creator [2011/11/26 14:17:21 | 000,000,000 | ---D | C] -- C:\Program Files\Aimersoft [2011/11/21 10:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\David N. Leh\Start Menu\Programs\FSPS [2011/11/20 12:00:51 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_7.dll [2011/11/20 12:00:51 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_5.dll [2011/11/20 12:00:50 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_43.dll [2011/11/20 12:00:50 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_7.dll [2011/11/20 12:00:49 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dcsx_43.dll [2011/11/20 12:00:48 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_43.dll [2011/11/20 12:00:48 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx11_43.dll [2011/11/20 12:00:47 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_43.dll [2011/11/20 12:00:46 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_6.dll [2011/11/20 12:00:46 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_6.dll [2011/11/20 12:00:46 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_4.dll [2011/11/20 12:00:45 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_7.dll [2011/11/20 12:00:44 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_5.dll [2011/11/20 12:00:43 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_5.dll [2011/11/20 12:00:42 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_42.dll [2011/11/20 12:00:41 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dcsx_42.dll [2011/11/20 12:00:41 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx11_42.dll [2011/11/20 12:00:40 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_42.dll [2011/11/20 12:00:39 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_42.dll [2011/11/20 12:00:38 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_41.dll [2011/11/20 12:00:38 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_41.dll [2011/11/20 12:00:38 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_41.dll [2011/11/20 12:00:37 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_4.dll [2011/11/20 12:00:37 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_3.dll [2011/11/20 12:00:36 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_4.dll [2011/11/20 12:00:35 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_6.dll [2011/01/22 15:40:40 | 000,442,368 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebcoin.dll [2011/01/22 15:39:26 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebinpa.dll [2011/01/22 15:39:26 | 000,356,352 | ---- | C] ( ) -- C:\WINDOWS\System32\LXEBhcp.dll [2011/01/22 15:39:26 | 000,344,064 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebiesc.dll [2011/01/22 15:39:25 | 001,048,576 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebserv.dll [2011/01/22 15:39:25 | 000,847,872 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebusb1.dll [2011/01/22 15:39:25 | 000,802,816 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebcomc.dll [2011/01/22 15:39:25 | 000,688,128 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebhbn3.dll [2011/01/22 15:39:25 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebpmui.dll [2011/01/22 15:39:25 | 000,598,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebcoms.exe [2011/01/22 15:39:25 | 000,577,536 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeblmpm.dll [2011/01/22 15:39:25 | 000,373,416 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebcfg.exe [2011/01/22 15:39:25 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebcomm.dll [2011/01/22 15:39:25 | 000,324,264 | ---- | C] ( ) -- C:\WINDOWS\System32\lxebih.exe [2008/06/27 16:59:50 | 000,010,240 | ---- | C] ( ) -- C:\WINDOWS\System32\killapps.exe [2006/12/28 11:26:12 | 000,028,160 | ---- | C] (MicroCrafts) -- C:\Program Files\oldmaml.dbs [2006/12/28 11:26:07 | 000,196,096 | ---- | C] (MySoftware) -- C:\Program Files\MailList.exe [8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [2 C:\*.tmp files -> C:\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011/12/17 22:29:01 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011/12/17 22:27:00 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{C6BF2B74-8D07-41C0-A757-BCF09C6BE98B}.job [2011/12/17 22:20:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David N. Leh\Desktop\OTL.exe [2011/12/17 21:29:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011/12/17 18:54:00 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2011/12/17 17:00:00 | 000,000,452 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job [2011/12/17 12:23:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2011/12/17 11:53:00 | 000,000,820 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job [2011/12/17 00:21:49 | 000,061,440 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/12/16 22:27:00 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2464157562-697926883-618238203-500.job [2011/12/16 21:30:57 | 000,110,860 | ---- | M] () -- C:\ComboFix.zip [2011/12/16 17:15:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job [2011/12/16 06:18:30 | 000,000,811 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to fsx.exe.lnk [2011/12/15 20:03:34 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011/12/15 20:03:17 | 004,958,588 | ---- | M] () -- C:\WINDOWS\{00000002-00000000-00000001-00001102-00000008-10211102}.CDF [2011/12/15 20:02:36 | 000,003,681 | ---- | M] () -- C:\WINDOWS\System32\mmf.sys [2011/12/15 20:02:35 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2464157562-697926883-618238203-1006.job [2011/12/15 20:02:35 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2464157562-697926883-618238203-1007.job [2011/12/15 20:02:29 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2464157562-697926883-618238203-500.job [2011/12/15 20:02:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011/12/15 20:02:19 | 3488,075,776 | -HS- | M] () -- C:\hiberfil.sys [2011/12/15 20:02:18 | 000,137,934 | ---- | M] () -- C:\WINDOWS\System32\OODBS.lor [2011/12/15 08:05:06 | 000,030,600 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000008-10211102}.rfx [2011/12/15 08:05:06 | 000,030,600 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000008-10211102}.rfx [2011/12/15 08:05:06 | 000,029,604 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000008-10211102}.rfx [2011/12/15 08:05:06 | 000,029,604 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000008-10211102}.rfx [2011/12/15 08:05:06 | 000,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000008-10211102}.rfx [2011/12/15 04:53:00 | 000,000,386 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job [2011/12/15 03:27:58 | 000,367,304 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011/12/15 03:07:43 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2011/12/14 19:48:28 | 000,000,588 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to qw.exe.lnk [2011/12/14 18:54:28 | 000,000,806 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk [2011/12/14 18:36:28 | 000,001,761 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VIPRE.lnk [2011/12/14 18:11:31 | 000,000,721 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to msimn.exe.lnk [2011/12/13 23:53:44 | 000,000,733 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to firefox.exe.lnk [2011/12/13 23:52:25 | 000,000,300 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2464157562-697926883-618238203-1006.job [2011/12/13 23:50:44 | 000,442,894 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011/12/13 23:50:44 | 000,072,160 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011/12/13 23:18:58 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2011/12/12 10:07:32 | 000,064,512 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys [2011/12/09 19:12:30 | 000,000,456 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\tNg2UrRUbj7rjw [2011/12/09 19:10:48 | 000,000,858 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk [2011/12/09 19:06:58 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\System Fix.lnk [2011/12/05 23:36:17 | 000,000,080 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Local Settings\Application Data\X-Plane Installer.prf [2011/12/05 11:14:00 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2464157562-697926883-618238203-1007.job [2011/11/27 09:13:03 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2011/11/26 14:17:40 | 000,000,882 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\Aimersoft DVD Creator.lnk [2011/11/23 08:49:41 | 000,004,756 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2011/11/23 08:25:32 | 001,859,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys [2011/11/23 08:25:32 | 001,859,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys [2011/11/21 13:09:52 | 000,663,606 | ---- | M] () -- C:\Documents and Settings\David N. Leh\My Documents\X-1756-03-SITE Plan REV.pdf [2011/11/21 13:06:36 | 001,147,295 | ---- | M] () -- C:\Documents and Settings\David N. Leh\My Documents\X-1756-03-Site Plan.pdf [2011/11/21 13:02:13 | 001,427,095 | ---- | M] () -- C:\Documents and Settings\David N. Leh\My Documents\2212_001.pdf [2011/11/21 10:36:31 | 000,000,804 | ---- | M] () -- C:\Documents and Settings\David N. Leh\Desktop\FSX Booster.lnk [2011/11/20 11:51:13 | 000,001,798 | ---- | M] () -- C:\WINDOWS\winzip.ini [8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [2 C:\*.tmp files -> C:\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011/12/16 21:30:56 | 000,110,860 | ---- | C] () -- C:\ComboFix.zip [2011/12/16 06:18:32 | 000,000,811 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to fsx.exe.lnk [2011/12/14 19:48:28 | 000,000,588 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to qw.exe.lnk [2011/12/14 18:54:35 | 000,000,486 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2011/12/14 18:54:28 | 000,000,806 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk [2011/12/14 18:36:28 | 000,001,761 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VIPRE.lnk [2011/12/14 18:11:31 | 000,000,721 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to msimn.exe.lnk [2011/12/13 23:53:44 | 000,000,733 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\Shortcut to firefox.exe.lnk [2011/12/13 23:36:22 | 3488,075,776 | -HS- | C] () -- C:\hiberfil.sys [2011/12/09 19:10:48 | 000,000,858 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk [2011/12/09 19:06:57 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\System Fix.lnk [2011/12/09 19:06:53 | 000,000,456 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\tNg2UrRUbj7rjw [2011/11/26 14:17:40 | 000,000,882 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\Aimersoft DVD Creator.lnk [2011/11/21 13:09:52 | 000,663,606 | ---- | C] () -- C:\Documents and Settings\David N. Leh\My Documents\X-1756-03-SITE Plan REV.pdf [2011/11/21 13:06:35 | 001,147,295 | ---- | C] () -- C:\Documents and Settings\David N. Leh\My Documents\X-1756-03-Site Plan.pdf [2011/11/21 13:02:11 | 001,427,095 | ---- | C] () -- C:\Documents and Settings\David N. Leh\My Documents\2212_001.pdf [2011/11/21 10:36:29 | 000,000,804 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Desktop\FSX Booster.lnk [2011/03/25 18:24:10 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2011/01/23 16:33:41 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2011/01/23 16:33:39 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2011/01/23 16:33:39 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin [2011/01/22 15:40:41 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxebvs.dll [2011/01/22 15:40:36 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\lxebcui.dll [2011/01/22 15:40:36 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\lxebcuir.dll [2011/01/22 15:40:36 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\lxebgcfg.dll [2011/01/22 15:39:26 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\LXEBinst.dll [2011/01/22 15:39:25 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\lxebins.dll [2011/01/22 15:39:25 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\lxebinsb.dll [2011/01/22 15:39:25 | 000,253,952 | ---- | C] () -- C:\WINDOWS\System32\lxebcu.dll [2011/01/22 15:39:25 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxebgrd.dll [2011/01/22 15:39:25 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\lxebinsr.dll [2011/01/22 15:39:25 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\lxebcub.dll [2011/01/22 15:39:25 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\lxebjswr.dll [2011/01/22 15:39:25 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\lxebcur.dll [2011/01/22 10:24:55 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\LXEBPMON.DLL [2011/01/22 10:24:55 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXEBFXPU.DLL [2011/01/22 10:24:35 | 004,485,120 | ---- | C] () -- C:\WINDOWS\System32\LXEBoem.dll [2011/01/22 10:17:34 | 000,299,008 | ---- | C] () -- C:\WINDOWS\System32\LXEBsm.dll [2011/01/22 10:17:34 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\LXEBsmr.dll [2010/09/18 00:29:29 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [2010/09/07 21:39:08 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2010/09/07 21:39:08 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2010/09/07 21:39:08 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2010/09/07 21:39:08 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2010/09/07 21:39:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2010/04/26 11:46:30 | 000,000,181 | ---- | C] () -- C:\WINDOWS\qawin32.INI [2009/11/19 07:33:11 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old [2009/06/18 21:59:46 | 000,072,832 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat [2009/04/30 21:02:00 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin [2009/02/28 09:37:01 | 000,413,696 | R--- | C] () -- C:\WINDOWS\ZSM1319.EXE [2009/02/28 09:37:01 | 000,413,696 | R--- | C] () -- C:\WINDOWS\System32\ZSM1319.EXE [2009/02/28 09:37:00 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\hpsfs.dll [2009/02/21 13:11:58 | 000,003,681 | ---- | C] () -- C:\WINDOWS\System32\mmf.sys [2008/08/16 08:14:51 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini [2008/06/27 18:05:08 | 000,049,565 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini [2008/06/27 18:05:06 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini [2008/06/27 17:27:54 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll [2008/06/27 17:25:02 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\psconv.exe [2008/06/27 17:09:36 | 000,386,852 | ---- | C] () -- C:\WINDOWS\System32\ctdnlstr.dat [2008/06/27 17:09:36 | 000,051,787 | ---- | C] () -- C:\WINDOWS\System32\ctdlang.dat [2008/06/27 17:03:54 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\regplib.exe [2008/06/27 17:02:56 | 000,149,838 | ---- | C] () -- C:\WINDOWS\System32\ctbas2w.dat [2008/06/27 17:00:36 | 000,274,587 | ---- | C] () -- C:\WINDOWS\System32\ctsbas2w.dat [2008/06/27 17:00:24 | 000,241,084 | ---- | C] () -- C:\WINDOWS\System32\CTSBASW.DAT [2008/06/27 17:00:24 | 000,115,166 | ---- | C] () -- C:\WINDOWS\System32\CTBASICW.DAT [2008/06/27 16:59:56 | 000,313,207 | ---- | C] () -- C:\WINDOWS\System32\ctstatic.dat [2008/06/27 16:59:56 | 000,053,932 | ---- | C] () -- C:\WINDOWS\System32\ctdaught.dat [2008/06/27 16:59:54 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\enlocstr.exe [2008/06/12 22:26:41 | 000,000,080 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Local Settings\Application Data\X-Plane Installer.prf [2008/02/07 10:05:18 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll [2008/02/03 00:27:21 | 000,184,320 | ---- | C] () -- C:\WINDOWS\System32\dbcmdb32.dll [2008/02/03 00:27:21 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\dbcjpg32.dll [2008/02/03 00:27:21 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\DBCMEM32.DLL [2008/02/03 00:27:21 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dbcgeo32.dll [2008/01/12 08:29:32 | 000,000,107 | ---- | C] () -- C:\WINDOWS\RFP.ini [2008/01/04 00:19:51 | 000,355,344 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat [2007/12/23 00:08:50 | 000,000,061 | -HS- | C] () -- C:\WINDOWS\cnerolf.bin [2007/12/15 00:56:45 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2007/12/15 00:14:29 | 000,928,096 | R--- | C] () -- C:\WINDOWS\System32\nvucode.bin [2007/12/12 07:26:05 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2007/12/12 07:24:47 | 000,204,800 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4820.dll [2007/11/22 10:35:32 | 000,000,081 | ---- | C] () -- C:\WINDOWS\PARSONS.INI [2007/11/03 09:09:46 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\flt1chk4.dll [2007/08/19 22:22:04 | 000,000,436 | ---- | C] () -- C:\WINDOWS\jpegcrop.INI [2007/08/13 20:45:02 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll [2007/07/31 22:13:26 | 000,000,082 | ---- | C] () -- C:\WINDOWS\netdet.ini [2007/07/14 01:34:34 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\myodbc3i.exe [2007/07/14 01:34:34 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\myodbc3m.exe [2007/06/19 21:11:26 | 000,000,100 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2007/03/30 13:11:28 | 000,000,025 | ---- | C] () -- C:\WINDOWS\LM.ini [2007/02/23 00:06:34 | 000,010,840 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2007/02/21 23:50:25 | 000,001,798 | ---- | C] () -- C:\WINDOWS\winzip.ini [2007/02/20 22:02:11 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\nY.exe [2007/02/20 22:00:39 | 001,126,400 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461.Dll [2007/02/20 22:00:39 | 000,007,680 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461_10.dll [2007/02/20 22:00:39 | 000,007,680 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461_0C.dll [2007/02/20 22:00:39 | 000,007,680 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461_0A.dll [2007/02/20 22:00:39 | 000,007,680 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461_07.dll [2007/02/20 22:00:39 | 000,006,656 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461_09.dll [2007/02/20 22:00:39 | 000,006,656 | R--- | C] () -- C:\WINDOWS\System32\SaiC0461_0402.dll [2006/12/29 10:47:28 | 000,000,147 | ---- | C] () -- C:\Program Files\RedStat.sts [2006/12/28 11:28:43 | 000,000,000 | ---- | C] () -- C:\Program Files\HPSW.CKI [2006/12/28 11:27:26 | 000,000,041 | ---- | C] () -- C:\Program Files\eregreg.ini [2006/12/28 11:26:12 | 004,039,699 | ---- | C] () -- C:\Program Files\MailList.pdf [2006/12/28 11:26:12 | 000,361,239 | ---- | C] () -- C:\Program Files\maillist.wth [2006/12/28 11:26:12 | 000,264,192 | ---- | C] () -- C:\Program Files\Hotelsmml.bcf [2006/12/28 11:26:12 | 000,264,192 | ---- | C] () -- C:\Program Files\Car Rentalsmml.bcf [2006/12/28 11:26:12 | 000,262,656 | ---- | C] () -- C:\Program Files\Airlinesmml.bcf [2006/12/28 11:26:12 | 000,201,934 | ---- | C] () -- C:\Program Files\Airlines.mml [2006/12/28 11:26:12 | 000,077,824 | ---- | C] () -- C:\Program Files\Textdbs.dbs [2006/12/28 11:26:12 | 000,066,034 | ---- | C] () -- C:\Program Files\Hotels.mml [2006/12/28 11:26:12 | 000,045,196 | ---- | C] () -- C:\Program Files\Car Rentals.mml [2006/12/28 11:26:12 | 000,039,424 | ---- | C] () -- C:\Program Files\Native.dbs [2006/12/28 11:26:12 | 000,017,408 | ---- | C] () -- C:\Program Files\oldmald.dbs [2006/12/28 11:26:12 | 000,006,344 | ---- | C] () -- C:\Program Files\Airlinesmml.fsif [2006/12/28 11:26:12 | 000,004,568 | ---- | C] () -- C:\Program Files\Airlinesmml.msif [2006/12/28 11:26:12 | 000,002,144 | ---- | C] () -- C:\Program Files\Hotelsmml.fsif [2006/12/28 11:26:12 | 000,001,568 | ---- | C] () -- C:\Program Files\Hotelsmml.msif [2006/12/28 11:26:12 | 000,001,500 | ---- | C] () -- C:\Program Files\Car Rentalsmml.fsif [2006/12/28 11:26:12 | 000,001,108 | ---- | C] () -- C:\Program Files\Car Rentalsmml.msif [2006/12/28 11:26:12 | 000,000,385 | ---- | C] () -- C:\Program Files\webmain.url [2006/12/28 11:26:12 | 000,000,061 | ---- | C] () -- C:\Program Files\WebSurf.ini [2006/12/28 11:26:12 | 000,000,000 | ---- | C] () -- C:\Program Files\maillist.sup [2006/12/28 11:26:11 | 000,233,980 | ---- | C] () -- C:\Program Files\FORMDEF.FDL [2006/12/28 11:26:11 | 000,231,248 | ---- | C] () -- C:\Program Files\FORMOPS.FDL [2006/12/28 11:26:11 | 000,181,616 | ---- | C] () -- C:\Program Files\FORMMETA.FDL [2006/12/28 11:26:11 | 000,071,168 | ---- | C] () -- C:\Program Files\jeteng.dbs [2006/12/28 11:26:11 | 000,002,609 | ---- | C] () -- C:\Program Files\ereginfo.ini [2006/12/28 11:26:11 | 000,000,128 | ---- | C] () -- C:\Program Files\EREG.BIN [2006/12/28 11:26:10 | 000,000,018 | ---- | C] () -- C:\Program Files\bmUpd.ddm [2006/12/28 11:26:07 | 000,037,376 | ---- | C] () -- C:\Program Files\AddrCD.rmv [2006/12/28 11:26:06 | 000,267,268 | ---- | C] () -- C:\Program Files\3602pr1.emf [2006/12/28 11:26:06 | 000,252,884 | ---- | C] () -- C:\Program Files\3602r1.emf [2006/12/28 11:26:06 | 000,252,272 | ---- | C] () -- C:\Program Files\3600r1.emf [2006/12/28 11:26:06 | 000,248,460 | ---- | C] () -- C:\Program Files\3601app.emf [2006/12/28 11:26:06 | 000,241,988 | ---- | C] () -- C:\Program Files\3602n1.emf [2006/12/28 11:26:06 | 000,235,248 | ---- | C] () -- C:\Program Files\3602pn1.emf [2006/12/28 11:26:06 | 000,179,312 | ---- | C] () -- C:\Program Files\3602r2.emf [2006/12/28 11:26:06 | 000,170,364 | ---- | C] () -- C:\Program Files\3602pr2.emf [2006/12/28 11:26:06 | 000,155,776 | ---- | C] () -- C:\Program Files\3602n2.emf [2006/12/28 11:26:06 | 000,146,524 | ---- | C] () -- C:\Program Files\3602pn2.emf [2006/12/28 11:26:06 | 000,122,104 | ---- | C] () -- C:\Program Files\3600p2.emf [2006/12/28 11:26:06 | 000,121,092 | ---- | C] () -- C:\Program Files\3620app.emf [2006/12/28 11:26:06 | 000,119,480 | ---- | C] () -- C:\Program Files\3600r2.emf [2006/12/28 11:26:05 | 000,265,408 | ---- | C] () -- C:\Program Files\3600p1.emf [2006/12/28 11:26:05 | 000,000,406 | ---- | C] () -- C:\Program Files\MailList.dmn [2006/12/17 03:00:59 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI [2006/10/29 10:44:00 | 000,004,756 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2006/10/20 19:52:21 | 000,003,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\NVStrap.sys [2006/10/02 17:25:18 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\kill.ini [2006/09/02 13:10:59 | 000,048,640 | ---- | C] () -- C:\WINDOWS\mmfs.dll [2006/09/02 13:10:59 | 000,002,560 | ---- | C] () -- C:\WINDOWS\Runservice.exe [2006/07/07 18:40:49 | 000,002,934 | ---- | C] () -- C:\WINDOWS\mozver.dat [2006/06/17 12:41:31 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.David N. Leh.ini [2006/06/01 17:10:25 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2006/05/18 22:43:21 | 000,000,145 | ---- | C] () -- C:\WINDOWS\Klmamsqo.ini [2006/04/02 19:19:59 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Application Data\dvd.bmk [2006/04/02 13:00:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI [2006/04/02 11:20:14 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Local Settings\Application Data\fusioncache.dat [2006/04/02 00:15:45 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Hposcv07.INI [2006/04/01 16:59:09 | 000,000,152 | ---- | C] () -- C:\WINDOWS\CoolPlay.ini [2006/03/31 21:10:23 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2006/03/31 20:40:12 | 000,000,061 | -HS- | C] () -- C:\WINDOWS\cnerolf.dat [2006/03/31 20:26:49 | 000,001,369 | ---- | C] () -- C:\WINDOWS\GARMINWT.INI [2006/03/27 22:17:18 | 000,000,751 | ---- | C] () -- C:\WINDOWS\eReg.dat [2006/03/25 10:17:04 | 000,000,165 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI [2006/03/25 08:49:27 | 000,000,152 | RHS- | C] () -- C:\WINDOWS\System32\501AA94F16.sys [2006/03/25 01:21:09 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Application Data\PFP120JPR.{PB [2006/03/25 01:21:09 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Application Data\PFP120JCM.{PB [2006/03/25 00:02:55 | 000,061,440 | ---- | C] () -- C:\Documents and Settings\David N. Leh\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/03/20 22:45:24 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006/03/20 22:39:32 | 000,000,285 | ---- | C] () -- C:\WINDOWS\wininit.ini [2006/03/20 22:35:03 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE [2006/03/20 22:28:34 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2006/03/20 22:07:32 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe [2006/03/20 22:07:12 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll [2006/03/20 22:07:12 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2005/11/10 09:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2005/06/18 01:41:32 | 000,046,593 | ---- | C] () -- C:\WINDOWS\System32\e10kxwdm.ini [2005/06/18 01:01:42 | 000,034,304 | ---- | C] () -- C:\WINDOWS\PSCONV.EXE [2004/10/28 09:38:10 | 000,315,728 | ---- | C] () -- C:\WINDOWS\System32\flt1chk3.dll [2004/08/20 01:28:00 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\TSRemote.dll [2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini [2004/08/10 14:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2004/08/10 14:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2004/08/10 14:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2004/08/10 13:57:52 | 000,004,328 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2004/08/10 13:57:15 | 000,367,304 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2004/08/10 13:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2004/08/10 13:51:20 | 000,442,894 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2004/08/10 13:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2004/08/10 13:51:20 | 000,072,160 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2004/08/10 13:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2004/08/10 13:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2004/08/10 13:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2004/08/10 13:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2004/08/10 13:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2004/08/10 13:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2004/08/10 13:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2004/06/06 12:53:42 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2004/06/05 12:56:16 | 000,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2003/07/14 19:57:20 | 000,031,744 | ---- | C] () -- C:\WINDOWS\System32\flt1chk2.dll [2002/12/19 14:04:56 | 003,050,298 | ---- | C] () -- C:\WINDOWS\System32\PDFREPORT_XP.dll [2002/07/23 11:13:58 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\win2000.dll [2002/03/13 18:46:46 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll [1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:74603393 < End of report >